The German Federal Office for Information Security (BSI) has confirmed that the cybercrime group Rhysida breached the Berlin Senate's building and transport administrations using a specific technical exploit known as TerminalFix. This verification comes days after the incident was first reported, providing official attribution for an attack that compromised sensitive government networks and led to a substantial ransom demand.
Officials stated that the intrusion resulted in the exfiltration of large volumes of data, including critical information regarding state infrastructure. The attackers subsequently demanded 2 million euro in Bitcoin to restore access and prevent the publication of stolen files. The confirmation closes a gap in public knowledge regarding the specific vector used to penetrate the state's defences.
How TerminalFix bypasses standard defences
The TerminalFix method relies on social engineering rather than a software vulnerability in the traditional sense. Users visiting a compromised website are presented with a fake Cloudflare captcha page that claims their browser needs verification. Instead of clicking a button, the user is instructed to press the Windows key combined with X, followed by the I key. This sequence opens the Windows Terminal with administrator privileges.
Once the terminal window is open, the user is guided to paste a command that appears harmless but executes a PowerShell script. This script downloads the initial malware payload from the attackers' servers in the background. While the manipulated webpage continues to display the fake captcha in the foreground to keep the user occupied, the malware establishes a SOCKS proxy. This creates a tunnel giving the criminals direct access to the organisation's internal network.
Security failures inside the Senate
Technical exploitation was only half the problem. The BSI analysis indicated that Rhysida found relatively easy passage through the network because password lists were stored in plaintext within the Berlin authorities' systems. This basic failure of security hygiene allowed the attackers to move laterally across the network once the initial foothold was established via TerminalFix.
Storing credentials without encryption violates fundamental security protocols expected of public administrations. It suggests that internal IT governance was insufficient to protect sensitive state data against even moderately sophisticated actors. The presence of plaintext passwords effectively negated many of the peripheral defences that might otherwise have slowed the intrusion or limited the scope of data exfiltration.
The economics of Rhysida operations
Rhysida has established a reputation for targeting public sector and educational institutions across Europe and North America. The group operates on a ransomware-as-a-service model, where affiliates carry out attacks in exchange for a share of the profits. A 2 million euro demand is consistent with their previous campaigns, calculated to be high enough to generate revenue but low enough that some victims might consider payment feasible.
For the attackers, the effort required to deploy TerminalFix is minimal compared to the potential return. The method bypasses many email filters because it relies on user interaction with a website rather than a malicious attachment. This shift in tactics reflects a broader trend where criminals exploit human error rather than searching for zero-day software vulnerabilities.
European regulatory pressure mounting
Incidents like this occur as the European Union tightens cybersecurity requirements for public bodies. The NIS2 Directive, which member states are integrating into national law, mandates stricter incident reporting and security measures for essential entities. Public administrations fall squarely within the scope of these regulations, meaning future breaches could trigger significant regulatory scrutiny beyond local political embarrassment.
The European Commission has emphasised that cybersecurity is a core component of the Digital Decade strategy, aiming to secure critical infrastructure across the bloc. EU digital policy priorities now expect member states to demonstrate resilience against precisely this type of coordinated ransomware campaign. Failure to comply with these standards may eventually carry financial penalties for national governments.
Organisations
German Federal Office for Information Security · Microsoft · Berlin Senate