Berlin State Government Refuses to Pay Extortionists After State Network Breach

Berlin’s state government confirmed on August 28, 2026 that it is the target of an extortion attempt following the compromise of the city-state’s administrative network earlier in August, and said it will not meet the attackers’ demands, according to a Senate Chancellery statement and reporting by The Hacker News. The same statement disclosed that forensic investigators had found further data outflows tied to the Senate Department for Mobility, Transport, Climate Protection and Environment, with exfiltration dated between August 7 and August 12, 2026.

The Senate Chancellery said the affected department first reported an outflow on August 7 and was cut off from the network on August 14, seven days later. Berlin has not published a figure for how much data left the network; the only itemized account in circulation is from the attackers’ own leak-site post, indexed on August 28. The Chancellery said personal or other non-public data cannot be excluded from what was taken, and that the scope and content of the breach are still being examined.

Refusing extortion demands after a confirmed government network breach carries operational risk if attackers publish or sell stolen data, but security officials increasingly favor the approach to avoid funding further attacks and to preserve credibility with other public bodies watching how governments respond. The case adds Berlin to a growing list of European state and municipal governments that have had to publicly navigate ransomware extortion decisions on live, unresolved incidents this year.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *