Berlin Refuses to Pay Hackers Who Stole Data From the City’s State Network

A brazen cyber attack on Berlin’s state network has left city officials scrambling, but they’ve refused to give in to hackers’ demands for a hefty ransom. The incident is a stark reminder of the ongoing threat of identity exposure and its devastating consequences.

Berlin’s state network was compromised through a sophisticated attack that leveraged cross-domain privilege escalation, allowing hackers to move undetected across different systems and access sensitive data. The attackers then used this access to steal critical information from various departments, including financial records, personal details, and confidential communications. It’s unclear how the hackers managed to breach the network, but experts believe it was likely due to a combination of social engineering tactics and exploiting known vulnerabilities.

The city’s officials have confirmed that the stolen data is now being held for ransom by the attackers, who are demanding an eye-watering sum in exchange for the safe return of the pilfered information. However, Berlin has refused to pay the ransom, opting instead to engage with cybersecurity experts to contain and eradicate the threat. This decision sends a strong message that cities will no longer be bullied into paying exorbitant sums to restore access to their own data.

Cross-domain privilege escalation is a complex technique used by hackers to move laterally across different systems within an organization’s network, effectively exploiting the trust relationships between these systems. It allows attackers to ‘jump’ from one domain to another, often evading detection and creating a path of least resistance for further exploitation. This type of attack requires significant expertise and planning but can yield devastating results.

The Berlin incident highlights the urgent need for organizations to prioritize identity exposure mitigation strategies. By continuously monitoring and analyzing user behavior, as well as implementing robust access controls and segmentation, cities like Berlin can reduce their vulnerability to these types of attacks. Furthermore, fostering a culture of cybersecurity awareness among employees is crucial in preventing social engineering tactics from succeeding.

As the city continues to navigate this crisis, one thing is clear: identity exposure will remain a pressing concern for organizations worldwide until they adopt more proactive and sophisticated security measures. Until then, cities like Berlin will continue to bear the brunt of these attacks, serving as cautionary tales for others to learn from. For individuals, it’s essential to remain vigilant about their online presence and take steps to protect themselves against identity exposure, such as regularly monitoring credit reports and using strong passwords.


Source: The Hacker News — 2026-08-28