Tag: Ransomware

  • Berlin State Government Refuses to Pay Extortionists After State Network Breach

    Berlin State Government Refuses to Pay Extortionists After State Network Breach

    Berlin’s state government confirmed on August 28, 2026 that it is the target of an extortion attempt following the compromise of the city-state’s administrative network earlier in August, and said it will not meet the attackers’ demands, according to a Senate Chancellery statement and reporting by The Hacker News. The same statement disclosed that forensic investigators had found further data outflows tied to the Senate Department for Mobility, Transport, Climate Protection and Environment, with exfiltration dated between August 7 and August 12, 2026.

    The Senate Chancellery said the affected department first reported an outflow on August 7 and was cut off from the network on August 14, seven days later. Berlin has not published a figure for how much data left the network; the only itemized account in circulation is from the attackers’ own leak-site post, indexed on August 28. The Chancellery said personal or other non-public data cannot be excluded from what was taken, and that the scope and content of the breach are still being examined.

    Refusing extortion demands after a confirmed government network breach carries operational risk if attackers publish or sell stolen data, but security officials increasingly favor the approach to avoid funding further attacks and to preserve credibility with other public bodies watching how governments respond. The case adds Berlin to a growing list of European state and municipal governments that have had to publicly navigate ransomware extortion decisions on live, unresolved incidents this year.

  • ATF Confirms Cyberattack on Standalone System Containing Investigation Targets, Calls It a Major Incident

    ATF Confirms Cyberattack on Standalone System Containing Investigation Targets, Calls It a Major Incident

    The Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed on August 27, 2026 that a standalone computer system containing information about targets of ATF investigations was breached, designating the incident a “major incident” under federal guidelines, according to an agency statement and reporting by Recorded Future News. The Justice Department component had appeared on the leak site of the Qilin ransomware gang earlier in the week, though the group did not publish samples of stolen data.

    An ATF spokesperson said the affected system “was not connected to any other ATF systems, including any case management systems, laboratory systems, or eForms systems,” and that it was shut down as soon as the breach was discovered. The agency said its investigative and operational missions were not disrupted, and that the Justice Department is investigating the incident. Qilin has been among the most active ransomware operations of the past two years, with previously claimed attacks on Kuala Lumpur International Airport, beverage maker Asahi, a Texas municipal government and several U.S. power cooperatives.

    The incident adds to a run of cyberattacks affecting Justice Department components in recent years, including earlier breaches involving the U.S. Marshals Service and the federal courts’ docketing system. For law enforcement and government facilities, the case underscores a recurring theme in ransomware incidents: segmenting sensitive investigative systems from broader case-management and operational networks can limit the blast radius of an attack even when a breach cannot be entirely prevented.

  • UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

    UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

    A cybercrime group tracked as UAT-10147 is using artificial intelligence tools to help scale attacks against internet-facing servers, and is deploying a malware toolset called SPECTRE that includes endpoint detection and response (EDR) evasion capabilities and a Linux rootkit component, according to a report published by The Hacker News on August 24, 2026.

    What the campaign involves

    Reporting describes UAT-10147 as using AI-assisted techniques to accelerate reconnaissance and exploitation against server infrastructure, rather than relying solely on manual attack chains. Once inside a target environment, the group is reported to deploy SPECTRE, which combines capabilities to bypass or blind EDR tooling with a Linux-focused rootkit intended to maintain stealthy, persistent access.

    Why it matters

    The use of AI-assisted tooling to scale attacks against server infrastructure reflects a trend that both offensive and defensive researchers have flagged repeatedly through 2026: attackers are using automation and AI assistance to compress the time between reconnaissance and exploitation, while defenders increasingly rely on AI-assisted detection to keep pace. A rootkit paired with EDR-bypass capability is also a reminder that Linux server estates — often assumed to be lower-risk than Windows endpoints — remain a high-value target, particularly where detection tooling coverage is weaker than on the desktop fleet.

    Sources

    More coverage like this is available on Technology News.