Berlin’s state government has confirmed it is being extorted following a breach of the city’s state administrative network discovered in August, and has stated publicly that it will not pay the attackers’ ransom demand.
In the same statement, officials disclosed that ongoing forensic analysis has uncovered further data exfiltration affecting systems within the portfolio of the Senate Department for Mobility, Transport, Climate Protection and Environment. This suggests the intrusion extended beyond the initial point of compromise and that the scope of data taken from Berlin’s networks is still being assessed.
What We Know
- The compromise of Berlin’s state administrative network was identified in August.
- Attackers exfiltrated data and are now demanding payment, which the city has refused.
- Forensic investigators have since found additional data outflows connected to the Senate Department for Mobility, Transport, Climate Protection and Environment.
Government bodies remain frequent targets for extortion actors precisely because refusal to pay carries political and operational risk, from potential public disclosure of sensitive data to disruption of administrative services. Berlin’s decision not to negotiate follows guidance commonly issued by national cybersecurity agencies, which generally discourage ransom payments on the grounds that they do not guarantee data deletion and can encourage further attacks.
Why It Matters
Municipal and state government networks often manage a wide range of citizen data across departments, including transport, environmental, and administrative records. A breach that spreads across multiple departmental systems, as appears to be the case here, complicates both the forensic response and the eventual public accounting of what data was exposed.
Security teams supporting public sector environments should treat this incident as a reminder to review segmentation between departmental systems and centralized administrative networks, ensure logging is sufficient to trace lateral movement across agency boundaries, and maintain incident response plans that anticipate prolonged forensic investigations following an initial breach disclosure.
No further technical details, including the initial access vector or the threat actor responsible, have been disclosed at this time.
