Berlin Refuses to Pay Hackers Who Stole Data From the City’s State Network

A daring cyber attack on Berlin’s state network has left city officials scrambling to contain the fallout, but one thing is clear: they won’t be paying hackers to delete the stolen data. The brazen heist exposed sensitive information about thousands of citizens, sparking an investigation into how the attackers managed to breach the system.

At the heart of this high-stakes cyber game lies a common tactic employed by malicious actors: cross-domain privilege escalation (CDPE). By exploiting vulnerabilities in one part of the network, attackers can leapfrog from one domain to another, gaining unauthorized access to sensitive data. In Berlin’s case, it appears that hackers used CDPE to infiltrate the city’s state network and siphon off valuable information.

The consequences are dire: thousands of citizens’ personal details have been compromised, including sensitive data such as addresses, phone numbers, and social security numbers. This type of information is a goldmine for malicious actors, who can use it to launch targeted phishing campaigns or even commit identity theft. As the city struggles to contain the fallout, officials are facing intense pressure to explain how this breach occurred in the first place.

One thing that’s not clear, however, is why hackers would bother deleting the stolen data – at least, not for free. In a bizarre twist, Berlin officials have announced that they will not be paying any ransom demands or negotiating with the attackers. This stance raises more questions than answers: are the hackers simply trying to create chaos, or do they genuinely expect payment in exchange for deleting the compromised data? Whatever their motives, it’s clear that CDPE has proven once again to be a potent tool in an attacker’s arsenal.

Berlin’s decision not to pay off the hackers is a bold move, but one that also highlights the city’s limited understanding of how these breaches occur. As we’ve seen time and time again, malicious actors will stop at nothing to exploit vulnerabilities – and it’s only by shedding light on these tactics that we can hope to prevent similar attacks in the future.

So what does this mean for average citizens? For one thing, it underscores the importance of staying vigilant online. With sensitive data increasingly being stolen and sold on the dark web, it’s more crucial than ever to keep your information secure – and that means using strong passwords, keeping software up-to-date, and being wary of suspicious emails or messages.


Source: The Hacker News — 2026-08-28