Berlin Won’t Pay Extortion Group Claiming Data Theft
The Rhysida ransomware group has claimed responsibility for stealing over 5TB of data from Berlin, including personal information and credentials. Berlin has decided against paying the extortion demands made by the threat actors.
The Rhysida ransomware group has targeted Berlin's government infrastructure, claiming to have stolen 5.79 TB of data ahead of the city-state's upcoming elections. Berlin officials have confirmed the August cyberattack on their administrative network and refused to meet the extortion demands, despite the threat of data release.
The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed that a cyberattack compromised a system containing information on its investigation targets, with the prolific ransomware group Qilin claiming responsibility for the incident. The ATF stated that the attack was isolated to a standalone system and had not affected critical operations. The incident highlights ongoing threats to federal law enforcement infrastructure and the continued targeting of government agencies by sophisticated ransomware operators.
The Bureau of Alcohol, Tobacco, Firearms and Explosives has confirmed a cyber incident classified as major, with the Department of Justice assisting in the ongoing investigation. A ransomware group has claimed responsibility for the attack against the federal agency.
Aurora ransomware operators are leveraging SpaceX's Cursor Agent AI tool to automate reconnaissance and exploitation tasks as part of their ransomware campaigns. This represents a notable shift in adversary tradecraft, with threat actors weaponizing legitimate AI development tools to enhance their operational capabilities.