When a ransomware crew posts your name, most teams treat that listing as the inventory. You assume they have the files, the dump is real, and the only remaining cybersecurity decision is whether to pay. That assumption is getting people hurt this week, in opposite directions.

Berlin’s state government confirmed an extortion attempt after the August compromise of its administrative network, and said it will not meet the attackers’ demands. Forensic work then found further data outflows in the Senate Department for Mobility, Transport, Climate Protection and Environment. The public note was incomplete. The city’s own investigation is still mapping what left.

Carhartt’s situation ran the other way. Reporting this week indicated that data tied to that breach was partly fake. U.S. Bank is in the familiar position of responding to a gang’s claims rather than a verified, internally reconstructed exfil list. Manchester Airports Group is dealing with its own incident in the same news cycle. The common thread is operational and ugly: the adversary’s story is a pressure tactic. Your incident response lives or dies on whether you already instrumented the truth.

Refuse the Ransom. Then Prove What Left.

Berlin’s refusal is the part that will get the headlines, and it is the correct public posture for a government network. Paying funds the next campaign. It also trains every other crew to treat your city as a customer. You already know that speech. Give it internally in ten minutes and move on.

The part that actually determines your exposure is slower. After the August compromise of Berlin’s state administrative network, investigators kept finding data leaving another portfolio: mobility, transport, climate, environment. That is a classic post-intrusion pattern. The first confirmed store is rarely the only one. Lateral movement is quiet. Collection is quieter. If your threat-protection stack only alerts on ransomware notes and encrypted shares, you will learn about the second department the same way Berlin did: late, from forensics, after the extortion clock is already running.

Berlin government buildings, site of a state administrative network compromise and subsequent extortion attempt
Berlin confirmed an extortion attempt against the city’s state network and said it will not pay. Forensics kept finding more outflows anyway.

You should run the same hunt even if you never see a leak site. Especially if you never see one. Plenty of crews steal, pause, and only later decide the data is worth a posting. Your cyber security program needs a standing answer to a blunt question: which identities moved which data to which destinations in the last 90 days, and which of those destinations you do not own.

The Leak Site Is a Marketing Funnel

Extortion sites exist to create a deadline and an audience. Sample files, victim names, countdown timers: that is conversion copy. Some of it is real. Some of it is stitched together from public records, old breaches, and files the operators never took from you. Carhartt’s partly fake dump is a gift to every defender who has been told to treat the screenshot as evidence. U.S. Bank’s need to respond to claims is the other half of the same problem. Once the gang speaks, your legal and comms teams are in motion. Your technical team may still be missing NetFlow.

Believe the incentive model. A crew that can post something that looks like your data gets paid more often than a crew that stays quiet. Fabrication is cheaper than a second trip through your file servers. Mixing a few authentic records with a pile of junk still photographs well. If your executives make scoping decisions from the leak page, they will over-notify in one incident and under-scope in the next.

Security news desk illustration representing a week of ransomware claims, fake dumps, and incomplete victim statements
This week’s roundup put a fake-padded dump, a bank answering gang claims, and a major airport incident in the same pile. The claims are the noisy part.

Manchester Airports Group is a reminder that operational disruption and data theft can travel together, and that the public timeline will be written by whoever talks first. If that is the attacker, you are already behind. Security hardening after the press call is theater. The work that matters is the telemetry you collected while the transfer was boring.

Your Cybersecurity Inventory Has to Exist Before the Note Arrives

You cannot reconstruct a clean exfil map from a PDF on a leak site. You reconstruct it from logs you kept, egress paths you actually control, and identity events you can time-correlate. If those sources are missing, the gang’s narrative becomes the working theory by default. That is how you get a board briefing built on a screenshot.

Immediate actions are unglamorous. Do them anyway, this week, on a quiet Tuesday, before anyone is paging you.

Questions your team should answer from logs, not from a dump

  1. Pull 90 days of egress from the firewall and any explicit proxies: top talkers by bytes, new destinations, and transfers that ran outside business hours. Flag destinations you do not recognize, especially object storage, VPS ranges, and consumer file-share domains.
  2. Correlate those flows with identity. Which service accounts, VPN users, and admin principals touched file shares or databases in the same windows? A brute-force spray against VPN followed by a large outbound copy is a story. A trusted printer or backup account doing the copy is a worse story, because it looks like yours.
  3. Inventory collection staging. Temp directories, compressed archives, and unexpected use of admin shares or cloud sync clients are the boring middle of almost every double-extortion case. If you cannot search for those artifacts across endpoints, you will learn about staging from the attacker.
  4. Lock the remaining doors while you hunt. Disable unused remote access, rotate credentials for any account that touched the suspected shares, and ban the destination IPs you already see in logs. On Windows edges, dynamic blocks of the sort people run with ipban (or IPBan Pro if that is already on the box) are a reasonable way to stop the follow-on brute-force noise while you work the actual incident.
  5. Write the scoping memo from telemetry first: systems, data classes, time bounds, destinations. Only then compare the leak-site samples. Matching hashes or unique row values can confirm authenticity. Mismatches are evidence of padding. Either result belongs in the record.

Ongoing work is where most programs quietly fail. Keep DNS, proxy, and firewall logs longer than your legal hold fantasies. Ninety days is a minimum if you want to answer Berlin-shaped questions. Instrument large outbound transfers as a first-class threat detection signal, with thresholds that match how your business actually moves files. Backup traffic, software distribution, and known SaaS sync should be allowlisted by destination and volume so the leftover spikes mean something.

Segment the departments that hold the data you would hate to see on a leak site. Berlin’s extra findings in a second Senate portfolio are the argument for that control. Shared admin planes and flat file access turn one foothold into a city-wide problem. Least privilege on file shares, separate backup credentials, and monitored service accounts are security hardening you can finish without buying a new platform.

Rehearse the decision tree with legal and comms using two scenarios: the dump is real, and the dump is junk. You will look reckless if you dismiss authentic records. You will look captured if you treat a padded archive as gospel. The only way those conversations stay sane is if engineering can produce an independent inventory in hours, not days.

Frequently Asked Questions

Should we still refuse to pay if forensics confirm real theft?
Yes, as policy, unless you have a legally forced exception you have already documented. Payment does not give you a complete inventory, a deletion guarantee, or a quieter second extortion. Use the confirmation to drive notification, containment, and monitoring of the destinations you actually observed.
How do we tell a fake dump from a real one under time pressure?
Compare unique artifacts you control: internal IDs, unpublished filenames, row-level values, and metadata that would be hard to invent. If samples match systems you can prove were reachable, treat those classes as stolen. If the archive is full of public PDFs and recycled data, say that plainly in the record and keep hunting.
What if we have no egress history worth using?
Say so internally, then start collecting it today. You will not retroactively log last month’s copy job. Prioritize firewall and proxy retention, identity correlation, and alerts on unusual outbound volume so the next incident has a map. That gap is a board-level risk, not a tooling footnote.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.