Rhysida Strikes Berlin In Ongoing Global Extortion Spree
Berlin's city administration has confirmed that cybercriminals stole sensitive data from its network and are now attempting to extort the German capital. The Rhysida ransomware gang listed Berlin on its dark web leak site on August 28, claiming credit for an intrusion first discovered in mid-August. Kai Wegner, the Mayor of Berlin, stated publicly that the city will not pay the attackers under any circumstances. The State Criminal Police Office, the public prosecutor's office, and federal security agencies are now jointly investigating the incident.

Rhysida claims to have exfiltrated 5.79 TB of data, comprising roughly 1.44 million files, from Berlin's administrative systems. According to the gang's own leak site listing, the stolen material reportedly includes several categories of sensitive government and personal records:
- Government, legal, financial, contractual, HR, infrastructure, health, and mapping records tied to city operations.
- Thousands of names, email addresses, phone numbers, and 148 international bank account numbers.
- Plaintext credentials, database accounts, payment-system data, and password vaults belonging to senior officials.
- Personnel files, payroll data, disciplinary records, email archives, SQL database dumps, and identity documents.
Forensic investigators also found evidence that attackers accessed data from Berlin's Senate Department for Mobility, Transport, Climate Protection, and the Environment. That intrusion likely occurred between August 7 and 12, and the affected department was disconnected from the state network on August 14. Senator Iris Spranger said officials found no evidence that election data was compromised, adding that systems supporting the upcoming Berlin House of Representatives election remain secure.
Rhysida has not disclosed how it initially breached Berlin's network. However, the group has a documented history of using fraudulent Microsoft Teams installers to gain a foothold inside corporate and government environments. This tactic connects the Berlin incident to a much broader pattern of activity the gang has pursued since surfacing in mid-2023.
Rhysida first drew widespread attention in February 2024 after claiming a cyberattack against Lurie Children's Hospital in Chicago, a leading pediatric care institution serving over 200,000 children annually. The attack forced the hospital to take its email, phone systems, and MyChart portal offline for weeks. Doctors were forced to switch to handwritten prescriptions after ultrasound and CT scan systems became unavailable. Rhysida later offered to sell 600 GB of allegedly stolen hospital data to a single buyer for 60 BTC, worth roughly $3.7 million at the time.
Later that year, the City of Columbus, Ohio, became another high-profile target after a ransomware attack struck on July 18, 2024. Rhysida claimed to have stolen 6.5 TB of data, including employee credentials and city surveillance camera footage. When the city refused to pay, the gang published 45 percent of the stolen files on its leak portal. Columbus Mayor Andrew Ginther initially told local media that the leaked data was "encrypted or corrupted" and posed no risk to residents.
That claim was later disputed by independent security researcher David Leroy Ross, who shared unencrypted samples with reporters to demonstrate that the data was readable. Columbus subsequently notified 500,000 individuals that their personal and financial information, including Social Security numbers and bank account details, had been exposed. The city now offers affected residents 24 months of free credit monitoring through Experian.
The Pennsylvania State Education Association, the state's largest public-sector union, suffered a similar fate after a July 2024 network intrusion. Rhysida claimed the breach in September 2024 and demanded a 20 BTC ransom to prevent a data leak. By March 2025, the union confirmed it was notifying more than 517,000 individuals that attackers had accessed personal, financial, and health information, including Social Security numbers and medical records.
Port of Seattle, which oversees Seattle's seaport and Seattle-Tacoma International Airport, was hit by a Rhysida attack in August 2024 that disrupted flight displays and reservation systems. The Port refused to pay a ransom despite threats to publish stolen files, and it later confirmed that roughly 90,000 individuals were affected. Stolen records included names, dates of birth, Social Security numbers, and driver's license information belonging to employees, contractors, and parking customers. The agency emphasized that payment processing systems and passenger travel operations remained unaffected throughout the incident.
Microsoft Moves to Disrupt Teams-Based Distribution Method
In October 2025, Microsoft took direct action against one of Rhysida's primary infection vectors by revoking more than 200 digital certificates used to sign malicious software. The certificates had been used to sign fraudulent Microsoft Teams installers distributed through lookalike domains such as teams-install[.]top and teams-download[.]buzz. These installers delivered the Oyster backdoor, granting attackers remote access before the Rhysida ransomware was deployed onto compromised networks.
Microsoft attributed the campaign to a group it tracks as Vanilla Tempest, also known by other vendors as Vice Society. "The threat actor has used various ransomware payloads, including BlackCat, Quantum Locker, and Zeppelin, but more recently has been primarily deploying Rhysida ransomware," Microsoft said in a statement announcing the disruption. The group has been active since at least June 2021 and has repeatedly targeted the education, healthcare, and manufacturing sectors.
The malvertising campaign relied on search engine advertisements and search engine optimization poisoning to push victims toward convincing fake download pages. Clicking the prominent download button delivered a file named MSTeamsSetup.exe, mimicking the filename used by Microsoft's legitimate installer. Security researchers noted that this same Oyster backdoor and delivery method had previously been linked to earlier Rhysida ransomware campaigns.
Rhysida operates as a ransomware-as-a-service group, meaning affiliates carry out intrusions while the core developers maintain the malware and leak infrastructure. The operation first gained notoriety in 2023 after breaching the British Library and stealing sensitive records from the Chilean Army. It later claimed responsibility for hacking Sony subsidiary Insomniac Games and leaking 1.67 TB of internal documents after the studio refused to pay a $2 million ransom.
The gang's affiliates also breached Singing River Health System in Mississippi, exposing personal and medical information belonging to nearly 900,000 patients. The U.S. Department of Health and Human Services has separately linked Rhysida to a broader wave of attacks against American healthcare providers. Researchers in South Korea previously published details of a flaw in Rhysida's encryption process, though the group appears to have since corrected the weakness in newer versions of its malware.
"PSEA experienced a security incident on or about July 6, 2024, that impacted our network environment," the Pennsylvania State Education Association said in breach notification letters sent to affected members. Statements like this have become common across Rhysida's victim list, as organizations balance transparency obligations against the risk of further provoking the attackers. Few victims publicly confirm whether they paid a ransom, leaving the true scale of Rhysida's earnings difficult to verify.
Security researchers continue to advise organizations to verify software downloads only through official vendor websites rather than search engine advertisements. IT administrators should also maintain offline, tested backups and apply timely patches, since Rhysida affiliates frequently exploit weak remote access controls and outdated software to gain entry.
Multi-factor authentication, network segmentation, and employee training against phishing and malvertising remain central defenses against this style of attack. Individuals affected by any of the breaches described above should monitor their financial accounts and credit reports for unusual activity. Enrolling in any complimentary credit monitoring service offered by an affected organization is also strongly recommended.
Share:
Karolis Liucveikis
Experienced software engineer, passionate about behavioral analysis of malicious apps
Author and general operator of PCrisk's News and Removal Guides section. Co-researcher working alongside Tomas to discover the latest threats and global trends in the cyber security world. Karolis has experience of over 8 years working in this branch. He attended Kaunas University of Technology and graduated with a degree in Software Development in 2017. Extremely passionate about technical aspects and behavior of various malicious applications.
PCrisk security portal is brought by a company RCS LT.
Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.
Our malware removal guides are free. However, if you want to support us you can send us a donation.
DonatePCrisk security portal is brought by a company RCS LT.
Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.
Our malware removal guides are free. However, if you want to support us you can send us a donation.
Donate
▼ Show Discussion