Berlin’s state government has formally acknowledged an extortion attempt linked to the August compromise of its administrative network, confirming that it will not comply with the attackers' demands. Officials stated that the decision to refuse payment aligns with their stance that yielding to cybercriminal pressure would set a dangerous precedent for public institutions.
The initial breach was detected in August, prompting an emergency response and forensic investigation. As part of that ongoing analysis, authorities have since uncovered additional data exfiltration tied to the Senate Department for Mobility, Transport, Climate Protection and Environment. This marks a second, distinct data loss event connected to the broader intrusion, expanding the scope of the incident beyond what was previously disclosed.
While the full extent of the stolen data remains under review, the confirmation of further outflows suggests that the attackers had deeper access than initially understood. The state government has not indicated any willingness to open negotiations, reinforcing its public position against ransom payments.
Affected entity: Berlin state administrative network
Additional compromised data: Senate Department for Mobility, Transport, Climate Protection and Environment
Incident timeline: Initial compromise in August; extortion attempt confirmed subsequently
Source: The Hacker News
Given Berlin’s refusal to pay, how is your organization balancing the risk of data leakage against the reputational and operational costs of holding the line on ransom demands?