← BACK TO FEED
ransomwareRhysidadata breachBerlinManchester Airports Group

Berlin Won't Pay Up After Hackers Swipe 5.79TB From City Network

Berlin's state government has confirmed it is the victim of an extortion attempt following a cyberattack in August 2026 that compromised its administrative network and resulted in the exfiltration of data, reportedly 5.79 terabytes according to the attackers. The city has refused to pay the ransom, with Governing Mayor Kai Wegner stating plainly that "the state of Berlin is being blackmailed," while law enforcement and federal security authorities investigate the incident. The ransomware group Rhysida has been named as the likely perpetrator, with officials stating that election infrastructure and sensitive data appear not to have been compromised.

Berlin's city government has confirmed it's being extorted following a ransomware attack on its administrative network in August, and has made clear it has no intention of paying. Governing Mayor Kai Wegner said as much after a special Senate session at the Rotes Rathaus: 'The state of Berlin is being blackmailed.' Short, blunt, accurate.

The breach was first disclosed on August 17. Forensic work established that the state network had been compromised, with two affected departments isolated the previous Friday. New findings have since widened the picture. The Senate Department for Mobility, Transport, Climate Protection and Environment saw data leaving its systems between August 7 and August 12, a full week before it was cut off on August 14. Whether personal or otherwise sensitive data was caught in that outflow is still being determined.

Berlin hasn't put a number on what was taken. That figure, such as it is, comes from the attackers themselves. A post on Rhysida's darknet leak site, indexed on August 28 and verified independently by leak-site monitoring services, claims 5.79 terabytes and around 1.44 million files, with personal data on just over 12,000 individuals. Der Spiegel was first to name Rhysida as the group responsible, citing both the leak-site entry and security sources close to the investigation.

The post lists eleven file categories, with maps and geodata making up the largest chunk at nearly 125,000 files. Roughly a quarter of the claimed total file count is accounted for. No ransom figure was stated publicly.

Rhysida isn't new. CISA, the FBI and MS-ISAC published a joint advisory on the group back in November 2023, documenting their methods. The usual routes in: compromised credentials used against external VPN access points, frequently at organisations without multi-factor authentication; the Zerologon vulnerability (CVE-2020-1472), a privilege escalation flaw in Microsoft's Netlogon protocol that was patched back in August 2020; and plain old phishing. The advisory also notes overlaps between Rhysida and Vice Society, tracked by Microsoft as Storm-0832.

As of August 29, monitoring services had logged 280 Rhysida victims globally, nine of them in Germany. Stuttgart's city administration was hit in May 2026, and humanitarian aid organisation Welthungerhilfe fell victim in June 2025. The Port of Seattle, which runs Seattle-Tacoma International Airport, appeared on the list in September 2024.

The state criminal police, public prosecutor and federal security authorities are all investigating. Berlin's data protection commissioner and the Federal Office for Information Security are being kept in the loop. The Berlin Commissioner for Data Protection had made no public statement as of August 29.

On the practical front, housing benefit applications and payments were offline while the affected departments were isolated. All Senate departments were reconnected on August 23. Interior Senator Iris Spranger said there's currently no indication that data relating to the September 20 regional election was taken, describing the election environment as secure.

The official advice to the roughly 12,000 potentially affected individuals? So far, none. Berlin's two public statements on the incident contained no guidance for people whose records may have been exfiltrated.

---

Manchester Airports Group Confirms Customer Data Stolen

Manchester Airports Group, which runs Manchester, London Stansted and East Midlands airports, has confirmed that an unauthorised third party got into a system holding customer data tied to car park bookings, lounge and Fast Track reservations, and in-airport WiFi registrations.

The data accessed includes email addresses, phone numbers, vehicle registration plates and postcodes. MAG says the compromised system holds no payment or banking details. The company has described it only as a system separate from MAG's own infrastructure, which is not exactly illuminating.

Around 8.7 million customers are thought to be affected, a figure attributed to a company spokesperson speaking to the press rather than anything in MAG's official materials. The company's own statements leave the number unspecified.

Passenger safety and aviation security were not affected, MAG says, and airport operations are continuing normally. The online Manage My Booking service has been suspended as a precaution. Anyone with a booking due within 72 hours can reach customer services on 0208 163 8001, weekdays 9am to 5pm.

Affected customers are being contacted directly and pointed toward the NCSC's data breach guidance, with the standard advice to watch out for phishing attempts across email, SMS and phone calls.

READ NEXT
Qilin Ransomware Gang Claims ATF Scalp as Feds Confirm 'Major' BreachLockBit Claims US Bank Scalp With September Leak DeadlineShinyHunters Turns Up the Heat on Ernst & Young After Tax Data Breach