IT-Sicherheit: Berliner Hacker-Ultimatum abgelaufen – Kein Lösegeld
Die Berliner Verwaltung bleibt beim Nein zu Lösegeld. Was bedeutet das für die erbeuteten Daten nach dem Ablauf des Ultimatums der kriminellen Hackergruppe Rhysida?
The deadline for the criminal hacker group Rhysida's ransom demand in the massive data theft from Berlin's municipal network has passed. It remains unclear immediately after the deadline expired on Friday afternoon whether the perpetrators had already published the nearly 5.8 terabytes of data on the Darknet. The extortionists had displayed a countdown on their leak site, which expired around 3:35 pm on Friday.
They demanded a ransom of 30 Bitcoin, equivalent to about two million euros. The Berlin Senate had previously stated that it would not engage in such extortion and would not pay a ransom. Upon the expiration of the deadline, the website of the extortionists on the Darknet announced the "auction" had ended. "All files have been uploaded to the publicly accessible area - have fun browsing, data hunters!" said the message there.
However, a link led to an error message instead of the data. Experts praised the Senate's decision to refuse ransom payments. Bianca Kastl from the Chaos Computer Club said the decision was correct, explaining, "If we continued to support these groups with money or other things, they would only continue to do so. We must starve them financially."
Renowned IT security expert Christof Fischer noted that the state cannot make payments in extortion cases according to law. The situation in cases like Berlin is very difficult, as he said, "The data is in the hands of criminals, and a publication often has very harmful effects in many cases. To date, I have not come across a case where money was paid and a publication still occurred."
However, it is assumed that the perpetrators, who mostly lived in Eastern European countries, would provide these data to the authorities in those countries to protect themselves from prosecution. According to Fischer, this typically takes several hours or days after comparable attacks before stolen datasets are actually made available for download via archive files or peer-to-peer networks.
IT security experts and Berlin's investigative authorities continue to monitor relevant forums and leak sites.
Written by urgent.news from Handelsblatt's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
Also reported by 1 other outlet
- IT-Sicherheit: Berliner Hacker-Ultimatum abgelaufen – Kein Lösegeld handelsblatt.com