Ransomware in Berlin: managing the crisis once data has been exfiltrated
A ransomware attack involving data theft in Berlin demonstrates once again that extortion no longer relies solely on encryption. When information leaves the organisation, the ransomware response becomes as much legal and communicative as it is technical.

News summary
The Berlin case reported by Reuters fits the dominant pattern of recent years: attackers encrypt systems, but first they exfiltrate the information. Extortion is no longer just about restoring access to data, but about not publishing it. This completely changes the nature of the response.
A company with impeccable backups can restore its servers in hours and still face a serious problem: contracts, payroll, histories, or customer data in the hands of third parties. Backups solve availability; they do not solve confidentiality.
At Seintec, we insist on a point that is often discovered too late: the most costly phase of modern ransomware is not restoration, but determining exactly what was taken. Without sufficient logs —of access, outbound traffic, or file server activity— that question remains unanswered, and without an answer, it is impossible to notify correctly or negotiate with sound judgment.
Within the European framework, moreover, the clock is ticking. Notification to the supervisory authority and, where appropriate, to the affected individuals, has demanding deadlines. An organisation that discovers the incident on Friday afternoon and has not decided who leads, who speaks to the regulator, and who speaks to the customers, loses its first useful hours.
The practical recommendation is to prepare for the crisis in advance: a technical response contact available out of hours, an identified legal advisor, a single spokesperson, and baseline messaging for customers and employees. It does not eliminate the damage, but it prevents improvisation from multiplying it.
In terms of prevention, three controls continue to account for most of the value: multi-factor authentication for all remote access, segmentation to prevent lateral movement across the network, and immutable copies outside the domain, verified through actual restoration tests.
Source: Reuters — 5 September 2026
What happened
Reuters reported a ransomware case in Berlin that follows the pattern that has dominated for years: attackers encrypt systems, but first steal the data. Extortion no longer means only restoring access to data, but threatening to publish it.
A company with sound backups can restore its servers within hours and still face a serious problem: contracts, payroll or customer data in outsiders' hands. Backups solve availability, not confidentiality.
What it teaches a mid-sized business
The costliest phase of modern ransomware isn't restoration, but determining exactly what the attackers took. Without sufficient logs of access, outbound traffic and file-server activity, that question has no answer, and without an answer you can't notify correctly or negotiate with judgement.
Under the European framework, the clock is ticking: notifying the supervisory authority and, where applicable, affected individuals carries tight deadlines. Discovering the incident on a Friday afternoon without a clear crisis lead wastes the first useful hours.
What to review
Preparation that makes the difference in this kind of crisis:
- A technical response contact available outside business hours.
- A legal adviser identified in advance and a single designated spokesperson.
- Sufficient access and outbound-traffic logs to scope the theft.
- MFA on remote access, network segmentation and immutable off-domain backups, verified with real restores.
Frequently Asked Questions
- Should you pay the ransom in a ransomware attack?
- Paying doesn't guarantee the data won't be published or that decryption tools will work, and it funds future attacks. The priority should be recovering from verified backups and meeting notification obligations.
- How do we know what data the attackers took?
- Only through logs. Without retained traces of access, outbound traffic and file-server activity, the investigation can't scope the breach.
- Are backups alone enough to be protected?
- No. Backups solve system availability but don't prevent stolen data from being published if the attacker extracted it before encrypting.
Concepts mentioned in this article: Backup · Ransomware
The response to ransomware is prepared before the incident. At Seintec we review your exposure level, your backups, and your detection capacity, and we document the crisis procedure in writing. Request a cybersecurity review.
Contact SeintecRelated service
Cybersecurity
We shield your business so it never stops.