Bottom line: Berlin's refusal to pay hackers may escalate the situation.
What's happening: The attack occurred on August 25, 2022, when a threat actor breached the BLV's network using an unpatched vulnerability in an unknown third-party application, exploiting CVE-2022-21243 (CVSS score: 9.8). The attackers then demanded 100,000 euros in Bitcoin.
What to do: CISOs should monitor the situation closely and prepare for potential lateral movement attacks, as the attackers may attempt to use the compromised data to access other systems within the city's network. Security teams should also review and update third-party application patching policies to prevent similar breaches in the future.