# Major Cyber Incidents Shake European Public Sector and Aviation Industry
## German State Government Refuses to Pay After Network Breach
Berlin’s government administration has fallen victim to a significant cyber extortion campaign, confirming that its state administrative network was compromised in August and that threat actors are now attempting to leverage stolen data for financial gain.
According to official statements, forensic investigators have identified additional unauthorized data transfers from the Senate Department for Mobility, Transport, Climate Protection and Environment. The exfiltration occurred over a five-day window between August 7 and August 12 of this year, though the full scope of information taken is still under active examination. Officials have cautioned that the stolen material may include personal data and other non-public records belonging to citizens and employees.
The department became aware of the initial data outflow on August 7, a full seven days before emergency network isolation procedures were enacted on August 14. Authorities have declined to disclose the volume of information that left the network during the breach window.
The only available accounting of the stolen material comes directly from the attackers themselves, who posted a claim on a dark web leak platform on August 28. That posting alleges the exfiltration of 5.79 terabytes of data, encompassing approximately 1.44 million files and sensitive records belonging to more than 12,000 individuals. The listing identifies the victim simply as Berlin, Germany, and organizes the stolen material into eleven categories. The single largest category consists of over 124,000 maps and geospatial data files. Notably, no specific ransom amount was stated in the posting.
As of the latest update, government authorities have issued no advisory or guidance to individuals whose personal information may be among the compromised records.
## Attribution Points to Rhysida Ransomware Group
German media outlet Der Spiegel first reported the attribution to Rhysida, a cybercriminal organization that operates a dark web leak site and employs double extortion tactics — simultaneously encrypting systems and threatening to publish stolen data unless a ransom is paid. Monitoring services confirmed that an entry titled “Berlin, Germany” appeared on the group’s leak site on August 28.
The United States Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) released a joint advisory detailing Rhysida’s known attack methodologies. The group is known to exploit several initial access vectors, including:
– **Compromised credentials on external-facing services**, particularly virtual private network gateways at organizations that do not enforce multi-factor authentication by default.
– **Zerologon (CVE-2020-1472)**, a critical privilege escalation vulnerability in Microsoft’s Netlogon Remote Protocol that has been patched since August 2020.
– **Phishing campaigns**, which have proven effective at granting initial footholds inside target networks.
Federal cybersecurity agencies have consistently advised against paying ransom demands, noting that payments do not guarantee data recovery and may encourage further targeting of other organizations. Recommended defenses include timely patching of known vulnerabilities, mandatory multi-factor authentication, and robust network segmentation to contain lateral movement.
Rhysida’s activities bear notable similarities to those of Vice Society (tracked by Microsoft as Storm-0832), with security researchers documenting overlapping tactics and infrastructure between the two groups as far back as 2023.
As of late August, the monitoring service recorded 280 confirmed Rhysida victims worldwide. Nine of those are based in Germany, with prior incidents affecting the Stuttgart city administration in May 2026 and the humanitarian organization Welthungerhilfe in June 2025. The group’s victim list also includes the Port of Seattle, which oversees Seattle-Tacoma International Airport.
## Election Security Remains Intact, Officials Say
Berlin’s Interior Senator Iris Spranger addressed concerns about the integrity of upcoming elections, stating that no data has been exfiltrated from systems relevant to the September 20 parliamentary vote. Her office has assessed the election infrastructure as secure and unaffected by the ongoing incident.
## Government Response and Recovery Timeline
Berlin first publicly acknowledged the breach on August 17, disclosing that forensic teams had confirmed the compromise and that affected departments had been isolated the previous Friday. At an August 19 press conference, Governing Mayor Kai Wegner described the situation as serious while emphasizing that, based on available information at the time, no sensitive data had been confirmed to have left the network.
The disruption caused significant practical challenges for residents. Housing benefit applications and related payment processes were unavailable during the period when the two departments remained disconnected from the broader network. All Senate departments were restored and reconnected on August 23, and forensic analysis of the state network continues.
The Senate Chancellery confirmed that Berlin’s data protection commissioner and the Federal Office for Information Security are being kept regularly updated. However, as of August 29, no formal public statement had been released by Berlin’s Commissioner for Data Protection and Freedom of Information.
—
## Manchester Airports Group Discloses Mass Customer Data Breach
In a separate but related cybersecurity development, Manchester Airports Group (MAG) announced on August 27 that an unauthorized third party gained access to customer data across three major airports it operates. The affected facilities include Manchester Airport, London Stansted Airport, and East Midlands Airport.
The breach exposed information tied to several customer-facing services, including car park reservations, airport lounge bookings, Fast Track security queue passes, and in-airport WiFi registration sign-ups. A company spokesperson confirmed that neither MAG’s core payment systems nor any banking or financial details were stored on the compromised platform.
Officials emphasized that airport operations, passenger safety protocols, and aviation security measures were never put at risk and continue to function normally. The compromised system was described as a standalone platform separate from MAG’s primary operational infrastructure.
In the wake of the disclosure, MAG suspended access to its online “Manage My Booking” portal as a precautionary step. Customers with bookings requiring changes within the next 72 hours are directed to contact customer services by phone during weekday business hours.
Reports indicate that approximately 8.7 million customers may have been affected, though MAG’s official communications have not included a confirmed number. The company has begun direct outreach to impacted individuals and directed them to the U.K. National Cyber Security Center’s official guidance on data breach response, urging vigilance against suspicious emails, text messages, and unsolicited phone calls.
—
## Frequently Asked Questions (FAQ)
**What is double extortion in the context of ransomware attacks?**
Double extortion refers to a tactic where threat actors not only encrypt a victim’s data to disrupt operations but also exfiltrate sensitive information beforehand, threatening to publish it publicly if the ransom is not paid. This puts victims in a double bind, as they face both operational paralysis and the risk of reputational and legal damage from leaked data.
**How does Rhysida gain access to victim networks?**
According to U.S. federal cybersecurity advisories, Rhysida commonly exploits three main access vectors: compromised credentials on external-facing remote services (especially VPN gateways without multi-factor authentication), the Zerologon vulnerability in Microsoft’s Netlogon protocol, and successful phishing campaigns.
**Why do federal agencies advise against paying ransomware demands?**
Agencies such as CISA and FBI warn that paying ransoms does not guarantee the safe return of data, does not prevent future attacks, and may incentivize threat actors to target additional organizations. Payment also potentially funds further criminal activity.
**Should travelers who used Manchester airports be concerned about financial fraud?**
MAG has confirmed that no bank account or payment card details were stored on the compromised system. However, passengers are advised to remain vigilant for phishing attempts and social engineering scams that may use exposed email addresses and phone numbers as a starting point for fraudulent contact.
**Are Berlin’s September elections at risk due to the cyber incident?**
Berlin’s Interior Senator has stated that no data from systems relevant to the September 20 parliamentary election was compromised, and security assessments of the election environment have deemed it secure.
**What should individuals whose data may have been exposed do?**
Affected individuals should monitor for unusual communications, exercise caution with unsolicited emails and messages, enable multi-factor authentication on personal accounts, and report any suspicious activity to the appropriate national cybersecurity authority.
—
## Conclusion
These two incidents highlight the growing sophistication and reach of cybercriminal organizations targeting both public institutions and private-sector service providers. Berlin’s government facing extortion underscores the vulnerability of municipal and state-level administrative networks, while the Manchester Airports Group breach demonstrates how large-scale data theft can affect millions of ordinary citizens across multiple service touchpoints. Both cases reinforce the critical importance of robust cybersecurity hygiene — including timely vulnerability patching, mandatory multi-factor authentication, network segmentation, and proactive incident response planning. As cyber threats continue to evolve, organizations and individuals alike must remain vigilant and prioritize resilient security practices to safeguard sensitive data and critical infrastructure.
Thank you for reading



