Berlin Refuses Ransom After Hackers Breach City's Administrative Network

Berlin's state government says it will not pay the criminals behind an August intrusion, as forensic work uncovers fresh data theft from the city's transport and environment department.

ThreatVectr Newsdesk· 3 min read
Full-frame photoreal editorial shot of a dimly lit corporate server room with rows of glowing blue and amber rack lights, a slightly out-of-focus enterprise dat
Share

Key points

  • Berlin's state government has confirmed an extortion attempt tied to the August 2024 break-in of its state administrative network.
  • Officials have publicly refused to pay the criminals anything.
  • Investigators found extra data was stolen from the Senate Department for Mobility, Transport, Climate Protection and Environment.
  • The city has not named the group behind the attack or said how the intruders first got in.
  • Berliners whose records sit in transport or environment files may see their information surface online.

Berlin's state government has confirmed it is being blackmailed by the criminals who broke into the city's administrative computer network in August. The city says it will not pay.

The attack hit the network that carries traffic between Berlin's state offices, the shared plumbing behind everything from permits to internal email. Officials disclosed the extortion demand this week, alongside fresh findings from the forensic team still picking through the damage.

Those findings are not comforting. Investigators now say more data left the building than first thought, specifically from the Senate Department for Mobility, Transport, Climate Protection and Environment. In plain terms: files from the department that runs Berlin's transport and environmental policy were copied out by the intruders.

The city has not said what is in the stolen files, how many people are affected, or how much money the criminals asked for. It also has not named the group behind the intrusion, as first reported by The Hacker News.

What actually happened?

Criminals broke into the network that connects Berlin's state government offices back in August, quietly copied data, and later returned with a ransom demand. Berlin has now said no to that demand in public.

This is the standard shape of a modern extortion attack. The intruders do not always scramble the victim's files with ransomware, which is malicious software that locks up systems until a payment is made. Increasingly they simply steal the data and threaten to publish it. That is called double extortion when both happen, or pure data extortion when only the theft is used as leverage. Berlin has not confirmed which flavour this is.

Refusing to pay is the position most European governments now take publicly. It is also the position law enforcement agencies push, because paying funds the next attack and does not guarantee the data stays private.

Should Berlin residents be worried?

Possibly, but there is nothing to panic about yet. The city has not published a list of what was taken. If files from the transport and environment department are dumped online later, they could include names, addresses, vehicle records or correspondence with residents.

Anyone who has dealt with that department, applied for a residents' parking permit, filed an environmental complaint, corresponded about a construction project, should watch for unusual emails referencing real details of past dealings. That is the classic sign of phishing, where criminals send fake messages using stolen context to trick people into handing over passwords or clicking bad links.

Banking details are unlikely to be in these files. Contact details and case history are the more realistic worry.

Would MFA have helped?

Honestly, we do not know yet, because Berlin has not said how the intruders got in. If the entry point was a stolen employee password reused from somewhere else, then yes: multi-factor authentication, the second check like a code from a phone app, would very likely have stopped the login cold. That is the single highest-value control for administrative networks and remains the honest answer in most public-sector breaches of this shape.

If the entry point was a software flaw in an internet-facing system, MFA would not have mattered, and the fix is patching plus network segmentation so a single foothold cannot reach the transport department's file shares.

Berlin's forensic report, when it lands, should tell us which it was. Until then, the refusal to pay is the clearest signal the city has sent.

© 2026 Threat Vectr