Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > Berlin District Refuses CrowdStrike Security Scan After Rhysida Ransomware Attack

Berlin District Refuses CrowdStrike Security Scan After Rhysida Ransomware Attack

By: Jordan Vector Cybersecurity Expert

Last updated: September 7, 2026

Human Written
Berlin District Refuses CrowdStrike Security Scan After Rhysida Ransomware Attack
  • Berlin’s Senate Chancellery hired CrowdStrike to search for signs of a recent ransomware hack.

  • The Lichtenberg district refuses to let CrowdStrike’s Falcon tool onto its network, citing US ties.

  • Hackers leaked 1.4 million files after Berlin refused to pay a 30 Bitcoin ransom.

A ransomware attack hit Berlin’s city administration back in August. The Senate Chancellery brought in CrowdStrike, a US cybersecurity company, to check the damage. But one district won’t go along with the plan. Lichtenberg says the firm’s American ties raise too many concerns.

The Rhysida Ransomware Hack on Berlin

A hacking group called Rhysida broke into Berlin’s network in August. According to a post from International Cyber Digest on X, the attackers stayed hidden inside the system from August 7 to August 12. Nobody noticed the break-in until August 14.

Rhysida then demanded a ransom of 30 Bitcoin, worth close to €2 million (approximately $2.3 million USD). Berlin’s administration refused to pay it. In response, Rhysida published around 1.4 million files online. The leaked data adds up to roughly 5.8 terabytes in size.

On its leak page, Rhysida claims the files include more than 46,500 contracts. The group also says it stole over 5,000 personnel files. One single file reportedly held close to 6,000 login credentials.

Some of those documents allegedly stored passwords in plain text. Plain text means the passwords were not scrambled or hidden in any way. Anyone who opens those files could read the passwords directly.

Because of how serious the breach looked, the Senate Chancellery hired CrowdStrike. The firm’s job is to scan district systems for signs of the hack. CrowdStrike planned to use a tool called Falcon for this work. Falcon usually sits on a device and watches for unusual activity in real time.

Lichtenberg District Blocks CrowdStrike’s Access

Not every district agrees with the plan to bring in CrowdStrike. Lichtenberg, one of Berlin’s twelve districts, refuses to install the Falcon tool. District officials gave several reasons for saying no.

First, Falcon could let CrowdStrike see staff devices and personal data. Second, US law may force the company to share that data with American authorities. Third, officials pointed to CrowdStrike’s ties with Palantir, a firm known for handling government data. Lichtenberg says it will only allow access under one condition. The Senate must take full responsibility for the outcome. The Senate must also cover every cost tied to the process.

Cybersecurity Experts and the Public React

Reactions to the standoff online quickly split into different camps. According to Oliver Contney, Berlin waited far too long before calling in an emergency incident response team. He said the delay cost valuable time that could have limited the damage.

Contney added that he hopes for a clear, detailed report so other security teams can learn from the mistakes made. He also advised every IT department to set up a managed security response system now, rather than waiting for a crisis to hit.

Anand Sharma raised a different point entirely. He argued the bigger issue isn’t which country the vendor comes from. Sharma noted that the stolen passwords sat unprotected for about a week before anyone caught the problem. He said this kind of failure can happen in any tightly regulated organization, no matter the vendor’s home country.

A user posting as Onyx_Digital admitted early doubts about the cleartext password claim. The doubts eased once a German outlet found the file and the Senate confirmed it. Still, the user pushed back on earlier reporting that claimed direct confirmation, arguing the credit belonged to the reporters who first found the file.

Other users focused more on politics than technical details. Michael Keenan referenced older testimony connected to CrowdStrike and a separate US election controversy, suggesting this history should make Berlin reconsider its choice of vendor. That claim relates to a different, older matter and remains outside the scope of this report.

Several commenters mocked Lichtenberg’s decision altogether. Antonio Calderón questioned why officials would rather leave stolen data with hackers than accept help from a US company. Brian Gehrke made a similar argument, pointing out that the data may already be for sale on the dark web regardless of who investigates it. Vincent Yiu called the district’s position confusing, since it tolerates the ransomware exposure but rejects a vendor trying to help.

Some responses leaned toward humor rather than criticism. A user posting as Mark – NerdSpeak joked that Lichtenberg might as well hire a Russian firm instead. AVB called the situation ironic, since hackers already accessed the systems while officials worry about a security vendor doing the same. M Kumar summed it up as hiring a US firm to investigate a breach, then blocking its tool over access concerns.

Not everyone criticized Lichtenberg’s move. Raphael Spannocchi supported the district’s stance, arguing that European governments should rely on cybersecurity vendors based in Europe, and ideally in Germany, rather than American firms.

The disagreement points to a bigger question facing governments everywhere. Officials must balance urgent security needs against concerns over who controls sensitive data. As Berlin works to recover from the Rhysida hack, the standoff with Lichtenberg shows how messy that balance can get, especially when a breach has already put millions of records at risk.

In July 2026, threat actor Monkeydance claimed to have breached Thailand’s Thepha District Public Health Office and offered a full data dump containing multiple databases, PDF invoices, and about 2GB of government documents.

Share this article

You might also like

Shipup Cyberattack Exposes Customer Data From Micromania and Easypara

Shipup Cyberattack Exposes Retail Customer Data in Supply Chain Security Breach

Cyberattack on delivery tracking service Shipup has revealed the names, emails, and phone numbers of the customers of Micromania and…

September 4, 2026
French Ministry Hit by Cyberattack as Hacker Claims Thousands of Records Stolen

France Confirms Cyberattack on Environment Ministry as Hacker Claims Data Theft

A hacker claims to have stolen two databases tied to France’s Ministry of Ecological Transition. The alleged files contain data…

September 3, 2026
ZeroBytes Claims 4 2 Million Géofoncier Records Stolen in French Cyberattack

French Land Data Platform Géofoncier Faces 4.2M-Record Breach Claim

ZeroBytes claims it accessed Géofoncier through an authenticated account with API access and extracted 4,226,008 lines. The alleged data includes…

September 3, 2026

About the Author

Jordan Vector

Jordan Vector

Cybersecurity Expert

Jordan is a security researcher and advocate who focuses on making privacy practical. Whether he's explaining how to harden a browser or reporting on the latest surveillance disclosures, his goal is to equip readers with knowledge they can use immediately. Jordan believes that true security begins with understanding the digital landscape.

Comments (0)

No comments.