Berlin's ransomware attack, in five points
- Rhysida breached Berlin's state government network on August 7, 2026. The compromised department stayed connected to the shared state backbone for another seven days before anyone disconnected it
- Rhysida claimed 5.79 terabytes across 1.44 million files on August 28, including personal data on 12,076 people and nearly 6,000 files containing login credentials. Berlin refused the 30-bitcoin demand
- On September 6, Rhysida published a second leak. Not more records this time. Access credentials
- Berlin runs the security controls that most large networks use: network segmentation, VPN access, and standard authentication. None of them answer the one question that decided how far this breach spread: what can a specific compromised account reach across the rest of the network
- That question is still open a month later, worked through department by department by a crisis unit that had to build the answer after the fact
Three questions a CISO should be able to answer for their board
If one account were compromised today, could you name its blast radius, the full set of systems it can reach, not just the segment it happens to sit in? Berlin's crisis unit is still reconstructing that access map one department at a time, a month after the breach.
Could you contain lateral movement from one compromised identity without taking down everything connected to it? Segmentation gave Berlin a way to cut the cable. It never told them which standing privileges, inherited permissions, or shared credentials extended past that cut.
If credentials leaked tomorrow, how long would it take you to confirm every system they're scoped to reach and revoke access before they're used? Berlin's answer to that question is still being assembled by hand, credential by credential, weeks after the fact.
The controls Berlin had in place were not the wrong controls. VPN gateways, MFA, and network segmentation govern authentication and the perimeter, how someone gets in and where a segment's boundary sits. None of them govern authorization at runtime, what an already-authenticated identity is entitled to touch once it's inside. That gap between authentication and authorization is the exact question this breach raised.
The timeline: from the first alert to the second leak
Berlin's Senate Department for Mobility, Transport, Climate Protection and Environment flagged unusual data movement on August 7, 2026. The department stayed connected to the Landesnetz, the state's shared backbone network, until August 14. Berlin disclosed the breach publicly on August 17, reconnected the affected systems on August 23, and then confirmed further exfiltration on August 26.
Rhysida claimed responsibility for its leak site on August 28, which contained 5.79 terabytes across roughly 1.44 million files. The claimed haul spans personal data tied to 12,076 individuals, nearly 78,000 legal and complaint files, more than 46,500 contracts, close to 6,000 files containing login credentials, judicial documents, and material tied to critical infrastructure, including Berlin's water supply.
The group demanded 30 bitcoin, worth roughly $2.3 million at the time, with a one-week deadline.
Governing Mayor Kai Wegner and Interior Senator Iris Spranger said Berlin would not pay. Rhysida published its first data package on September 4.
The Senate Chancellery established a central crisis-response unit on September 5, led by Chief Digital Officer Florian Hauer, working alongside the State Criminal Police Office, the Berlin Public Prosecutor's Office, data protection officials, and the federal Office for Information Security (BSI). Both affected Senate departments set up their own internal task forces in addition to that unit.
On September 6, Rhysida released a second package described in Berlin's own statement as containing access credentials. The affected Senate department said it had reviewed and tightened precautionary measures following the new disclosure. Berlin holds a state election on September 20, and officials have said no data left the areas relevant to the election, with security officers regarding the election environment as secure.
Rhysida itself is not a new actor. The group has been active since 2023 and has claimed roughly 280 victims, about half of them in the United States. Federal advisories from CISA, the FBI, and MS-ISAC have tracked its methods for over two years. None of that history made this attack novel. What made it damaging was what happened after the initial access, not the access itself.
Why did standard controls not stop this from spreading
Federal advisories describe Rhysida's usual paths as: valid credentials for external-facing remote services, particularly VPN access without multi-factor authentication; the Zerologon flaw in Windows domain authentication; and phishing. None of these require a sophisticated exploit. They require one gap in one system that a large, decades-old network never fully closed.
A network the size of Berlin's runs the controls this scale demands: segmentation across departments, VPN gateways, standard domain authentication. Those controls are built to stop or slow someone from getting in, or to contain which network segments can talk to which.
None of them are built to answer a narrower question: once a specific account is compromised, what does that account itself have permission to reach, across every system it touches, not just the segment it happened to enter through.
That gap is what turned a single compromised department into a ten-day, city-wide dilemma. Segmentation told Berlin's team which parts of the network could physically reach which other parts. It said nothing about whether the transport department's compromised accounts had access, inherited permissions, or shared credentials that extended to systems outside transport entirely. Berlin's crisis unit is still reconstructing that picture by hand, department by department, a month after the breach.
This is the pattern behind most large-network ransomware incidents, not a fact specific to Berlin's own architecture. Authentication and segmentation are necessary. They are not the same question as what an authenticated identity can actually do once it is inside, and large networks accumulate that second gap for years without anyone noticing, because nothing forces it into view until an attacker finds it first.
What does this mean for other large networks?
Berlin's crisis unit is doing, by hand and under public pressure, what a standing identity map would already answer. Before this happens to another large network:
- Inventory every account with access to more than one department, system, or segment, not just the systems each department administers directly.
- Correlate service accounts and shared credentials back to the individual or team that owns them, so a compromised login maps to a known blast radius instead of an open question.
- Flag and remediate partially offboarded accounts and shadow admin access before an incident forces the audit.
- Build the cross-system access map before a breach, not during one.
How Unosecur answers the question that those controls can't
Unosecur does not replace VPN security, MFA, or network segmentation. It answers the question those controls do not: what can this specific identity reach across every connected system, right now?
Unosecur's Unified Identity Fabric builds one correlated view of every account across every connected system and flags the conditions that turn access into risk: partially offboarded, inactive, no MFA, shadow admin. That view joins every account one person holds across every system, so "what does this department's access touch elsewhere?" has a standing answer instead of a ten-day investigation.
Once that map exists, least-privilege policies apply based on observed usage, closing off every system an account has never touched. A leaked credential stops being an open question and becomes a known, already-narrowed set of doors. Reaching a network like Berlin's would not require opening it further. Integration is agentless and read-only, and on-prem systems connect via Unochariot, which initiates only outbound connections and requires no inbound access.











.webp)

.avif)