Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Berlin Commissioner. Show all posts

Berlin Confirms Extortion Attempt After Network Compromise as Manchester Airports Group Reports Customer Data Theft

 

The state of Berlin confirms that it is the victim of an extortion attempt after allegedly having its network hacked back in August. Authorities say they will not give in to the hackers’ demands. 

Forensic analyses of the network of the Senate Department of Mobility, Transport, Climate Protection and the Environment have revealed additional data thefts outside the network in the period between August 7 and 12. The department had first noticed data loss on August 7 and had been cut off on August 14. Berlin is currently still investigating the extent and scope of the data loss, saying that it is possible that personal data or other confidential information had been accessed. 

The amount of data stolen in the cyber-attack on Berlin has not been disclosed officially; however, one entry on the dark web by the hackers’ group Rhysida, published on August 28, claims that 5,79 TB of data containing personal information of 12,076 people were stolen. The entry also stated that approximately 1,44 million files had been scanned. 

According to the post, the target of the attack was Berlin, Germany, without specifying any ransom value. Der Spiegel revealed that the ransom note was published by the hacker collective Rhysida, citing the group’s dark web blog and security sources. According to the report, a monitoring service confirmed on Friday that a post titled “Berlin, Germany” appeared on the leak site of Rhysida on August 28. Berlin has not officially attributed the attack to any hacker group. 

A joint security advisory released by the U.S. Cybersecurity and Infrastructure Security Agency, the FBI and the Multi-State Information Sharing and Analysis Center highlights that Rhysida has been abusing compromised legitimate usernames and passwords from remote access services and has been using phishing and the Zerologon vulnerability (CVE-2020-1472). The advisory recommends prioritizing the response to known exploited vulnerabilities, implementing multi-factor authentication and network segmentation. 

Berlin’s data protection commissioner and the Federal Office for Information Security have been informed of the attack. Interior Minister Iris Spranger stated that, according to preliminary information, no data from the election-relevant IT systems were removed from the network. Thus far, no election functions have been interrupted. Meanwhile, Manchester Airports Group (MAG) has announced that a cyber-security incident involving the unauthorized collection of customer data occurred at its UK airports. 

The personal data of passengers who booked car parking, lounges, or Fast Track services or who subscribed to in-airport WiFi were affected. The data compromised in the breach include customers’ email addresses, phone numbers, vehicle registration numbers, and postcode details. According to MAG, the data do not include customers’ payment or bank details, and no impact has been made on passengers’ safety or aviation safety or airport operations.

As of August 29, the online booking system, called Manage My Booking, has been temporarily offline for security reasons. It has been reported that affected customers have been contacted directly and have been warned to be vigilant of further communication attempts from unauthorized third parties.

DeepSeek Faces Ban From App Stores in Germany

 

DeepSeek, a competitor of ChatGPT, may face legal ramifications in the European Union after the Berlin Commissioner for Data Protection ordered that Google and Apple remove the AI app from their stores. 

After discovering that the DeepSeek app violates the EU's General Data Protection Regulation (GDPR), Berlin Commissioner for Data Protection and Freedom of Information Meike Kamp issued a press release on June 27 urging Google and Apple to take the app down. The action follows Kamp's earlier request that DeepSeek either voluntarily remove its app from Germany or alter its procedures to safeguard the data of German users, neither of which DeepSeek did. 

"The transfer of user data by DeepSeek to China is unlawful. DeepSeek has not been able to provide my office with convincing evidence that data of German users is protected in China at a level equivalent to that of the European Union. Chinese authorities have extensive access rights to personal data held by Chinese companies,” Kamp stated. 

"In addition, DeepSeek users in China do not have enforceable rights and effective legal remedies as guaranteed in the European Union. I have therefore informed Google and Apple, as operators of the largest app platforms, of the violations and expect a prompt review of a blocking.” 

This does not imply that DeepSeek will be removed from the Google Play Store or App Store right away. Apple and Google must consider Kamp's request and choose their course of action. If the app is eventually taken down, it probably won't affect users in other countries; it might only be blocked in Germany or the EU broadly. Despite this, millions of users may be looking for a new favourite AI software, given that DeepSeek had over 50 million downloads on the Google Play Store as of July 2025.

In any case, given this news, some users might wish to get rid of the app altogether. As Kamp's news statement states, "According to its own website, [DeepSeek] processes extensive personal data of users, including all text entries, chat histories, and uploaded files, as well as information about location, devices used, and networks.” 

Users who care about their data privacy, regardless of where they live, should likely be concerned about Kamp's office's increased efforts to have DeepSeek banned in Germany or to have it provide data protection that complies with EU regulations. However, the same could be said for the majority of social media and AI apps.