Berlin’s state government confirmed on August 29 that it is facing an extortion attempt following a cyberattack on the city administration’s data network, and that it will not pay. “The state of Berlin is being blackmailed,” Governing Mayor Kai Wegner said after a special Senate session at the Rotes Rathaus, according to the city’s official portal, adding that the Senate would not give in to the demands. Forensic work has since found a further data outflow from the Senate Department for Mobility, Transport, Climate Protection and Environment, dated between August 7 and 12, with the affected department disconnected from the state network on August 14.

The city has not published a figure for how much data left its network. The only itemized claim in circulation belongs to the attackers themselves, a leak site entry that surfaced August 28 asserting 5.79 terabytes and personal information on more than a million files, without naming which department the data came from. Berlin’s own two public statements on the incident carry no guidance for people whose records might be among what was taken, even as the state acknowledges it cannot rule out personal or other non-public data being involved.

The gap between an attacker’s leak site claim and a victim’s own disclosure is the real story for defenders tracking this incident, not the ransom demand itself. Berlin has confirmed the intrusion, confirmed a second data outflow beyond the original one, and confirmed it will not pay, but has not confirmed scope, and state criminal police, prosecutors, and federal security authorities are still investigating who is behind it. Security teams at any organization handling a live extortion attempt should treat that sequencing as normal, not as a sign the victim is withholding information: verified scope takes longer than either the ransom note or the news cycle around it. CyberTech has tracked the same disclosure lag pattern before, including a case where a benefits platform breach took nine months to surface, and separate research on why ransomware increasingly targets the mid-market rather than large enterprises.

Source: Berlin.de