Skip to main content
Don't Pay Ransoms? Berlin Shows Why That's Harder Than It SoundsSecurity & Breach Notification
4 min readFor IT & Security Teams

Don't Pay Ransoms? Berlin Shows Why That's Harder Than It Sounds

The Conventional Wisdom

When ransomware operators demand payment, the standard advice is clear: don't pay. The FBI, CISA warns against it, and your cyber insurance policy likely advises refusal. The reasoning is straightforward: paying encourages attackers, funds criminal activities, and doesn't guarantee data recovery.

Berlin's state government adhered to this advice after hackers exfiltrated data between August 7 and August 12. They refused the extortion demand, even as attackers claimed to hold personal information on 12,076 individuals. On paper, Berlin did everything right.

The Reality Check

The "never pay" stance treats ransomware response as a simple ethical choice, but it's actually an operational crisis that many organizations aren't ready to handle. Berlin's experience highlights the gap between policy and reality.

After Berlin refused to pay, the Senate Chancellery issued two statements by August 29. Neither provided guidance for the 12,076 individuals whose personal data was compromised. There was no notification timeline, no advice on protective measures, and no clarity on what data was taken beyond "personal or other non-public data cannot be excluded."

Article 34 requires you to communicate a personal data breach to affected individuals "without undue delay" when there's a high risk to their rights and freedoms. The communication must describe the breach, its likely consequences, and measures taken or proposed to address it. Berlin's silence suggests they either couldn't determine what was taken or weren't prepared to respond at scale.

If you're not ready to refuse ransom payment, the refusal itself becomes a liability. You're choosing to operate in a compromised state without the unreliable data recovery shortcut that payment might provide. Your incident response plan, data inventory, backup architecture, and communication protocols need to work flawlessly under pressure. For most organizations, they don't.

The Evidence

The suspected group, Rhysida, follows a documented playbook. A joint advisory from CISA, the FBI, and MS-ISAC identifies their initial access methods: valid accounts on external-facing services, Zerologon exploitation, and phishing. Berlin's network was compromised, with the mobility and environment department reporting an outflow on August 7. Yet, it took until August 14 to isolate the affected systems. That's seven days of continued access after detection.

The attackers claimed 5.79 terabytes across approximately 1.44 million files. Berlin published no competing figure, indicating issues with their data classification and monitoring capabilities. Without quickly quantifying what left the network, you can't assess breach severity, satisfy Article 33's 72-hour notification requirement, or determine which data subjects face high risk under Article 34.

The Berlin Commissioner for Data Protection and Freedom of Information had issued no public statement as of August 29, twelve days after the city's initial disclosure. The Federal Office for Information Security was being "kept informed on a continuing basis," but the absence of supervisory authority guidance suggests Berlin was still establishing the scope while managing public pressure about election security and housing benefit disruptions.

This is what "don't pay" looks like when your security posture has gaps. You're simultaneously investigating, remediating, restoring services, and trying to determine notification obligations while the clock runs on regulatory deadlines.

What to Do Instead

If you're going to refuse ransom demands, you need infrastructure that makes refusal operationally viable:

Build a Data Inventory That Works Under Pressure. Know within hours, not weeks, what categories of personal data were on compromised systems. Maintain current records of processing activities under Article 30, with enough detail to support breach assessment. If you process special categories of data under Article 9, confirm or rule out their compromise immediately.

Segment Your Network. Network segmentation prevents ransomware from spreading. Berlin isolated two departments on August 14, but the exfiltration window ran through August 12. Segmentation limits lateral movement and your notification obligations when a breach occurs.

Prepare Article 34 Communication Templates Now. You won't draft clear, legally compliant data subject notifications during an active incident. Prepare templates for different breach scenarios: compromised credentials, exfiltrated files, encrypted systems. Include the Article 34 required elements, your DPO contact information, and specific protective steps data subjects should take. Test whether you can deliver these communications at scale.

Deploy Multi-Factor Authentication Everywhere. Rhysida gains initial access through compromised credentials at organizations lacking MFA. This isn't sophisticated tradecraft. It's exploiting the authentication gap between your critical systems and secondary services. Attackers don't need to compromise your most sensitive system first; they need a foothold.

Know Your Backup Recovery Time. If you refuse to pay, you're betting on your ability to restore operations from clean backups. Berlin reconnected all Senate departments on August 23, six days after public disclosure. Housing benefit applications were unavailable during that window. What's your organization's tolerance for service disruption across different processing activities?

When the Conventional Wisdom Is Right

The "don't pay" guidance is correct that payment offers no guarantee of data recovery and funds criminal operations. Agencies are also right that paying may mark your organization as a willing payer for future attacks.

If you've implemented the appropriate technical and organizational measures under Article 32, maintained offline backups, and can restore operations without the attackers' cooperation, refusing payment is both the ethical choice and the operationally sound one. Berlin's refusal demonstrates institutional resolve.

But resolve without preparation creates a different problem: you're managing a prolonged crisis without the tools to assess its scope, notify affected individuals promptly, or restore services quickly. That's not a security posture. That's hope.

The conventional wisdom assumes you've done the work that makes refusal possible. Most organizations haven't.

You Might Also Like