Executive Summary
In August 2026, the Rhysida ransomware group successfully infiltrated Berlin's state administrative network, exfiltrating 5.79 terabytes of data including personal information on over 12,000 individuals between August 7-12. The attackers gained initial access through compromised VPN credentials and deployed double extortion tactics, demanding ransom payment while threatening to leak stolen government data. Berlin's leadership, including Governing Mayor Kai Wegner, publicly refused to pay the ransom despite ongoing extortion attempts, maintaining operations while conducting forensic investigation with federal authorities.
This incident highlights the continued evolution of ransomware groups targeting critical government infrastructure, particularly as threat actors like Rhysida increasingly focus on high-profile public sector victims to maximize pressure and potential payouts through leaked sensitive citizen data.
Why This Matters Now
Government ransomware attacks are escalating globally, with threat actors specifically targeting public sector entities to exploit their responsibility to protect citizen data and maintain critical services, making robust zero trust architectures and egress controls essential for municipal cybersecurity.
Attack Path Analysis
Rhysida ransomware group compromised Berlin's state administrative network through valid credentials on external-facing VPN services lacking MFA, escalated privileges using known vulnerabilities, moved laterally within the network for several days, maintained persistent command and control channels, exfiltrated 5.79 terabytes of sensitive government data between August 7-12, and deployed ransomware demanding payment while threatening public data disclosure.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers gained initial access through compromised valid credentials on external-facing VPN services, exploiting the absence of multi-factor authentication on critical remote access points
Related CVEs
CVE-2020-1472
CVSS 5.5A privilege escalation vulnerability in Microsoft Netlogon Remote Protocol that allows an unauthenticated attacker to gain domain administrator privileges by exploiting the Netlogon authentication process.
Affected Products:
Microsoft Windows Server – 2008 R2, 2012, 2012 R2, 2016, 2019
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Valid Accounts
Phishing
Exploitation of Remote Services
Exploitation for Privilege Escalation
Data Encrypted for Impact
Exfiltration Over Web Service
Inhibit System Recovery
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
CISA Zero Trust Maturity Model 2.0 – Multi-Factor Authentication
Control ID: IM.AM.1
GDPR – Security of Processing
Control ID: Article 32
ISO 27001:2022 – Information Backup
Control ID: A.8.9
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
DORA – ICT Risk Management Framework
Control ID: Article 11
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Berlin ransomware attack demonstrates critical exposure to lateral movement and data exfiltration vulnerabilities in government networks lacking proper segmentation and encryption controls.
Airlines/Aviation
Manchester Airports Group breach exposes aviation sector's vulnerability to customer data theft through inadequate egress security and policy enforcement on booking systems.
Transportation
Transportation infrastructure faces ransomware threats targeting mobility departments with insufficient east-west traffic security and zero trust segmentation enabling lateral movement attacks.
Information Technology/IT
IT sectors must address Rhysida ransomware exploiting VPN access without MFA and CVE-2020-1472 vulnerabilities requiring enhanced threat detection and anomaly response capabilities.
Sources
- Berlin Refuses to Pay Hackers Who Stole Data From the City's State Networkhttps://thehackernews.com/2026/08/berlin-refuses-to-pay-hackers-who-stole.htmlVerified
- CISA FBI MS-ISAC Advisory on Rhysida Ransomwarehttps://www.cisa.gov/news-events/cybersecurity-advisories/aa23-319aVerified
- Berlin Senate Chancellery Statement on Cyberattackhttps://www.berlin.de/rbmskzl/aktuelles/pressemitteilungen/2026/pressemitteilung.1708208.phpVerified
- Manchester Airports Group Statement on Cyber Security Incidenthttps://mediacentre.magairports.com/mag-statement-on-cyber-security-incident/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have significantly constrained the Rhysida ransomware group's ability to move laterally across Berlin's government network and reduced the scale of data exfiltration through workload segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Cloud native security fabric would likely have limited the initial compromise scope by providing identity-aware access controls and reducing the attack surface of external-facing services through secure cloud connectivity patterns.
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation would likely have constrained privilege escalation by limiting cross-workload access and reducing the blast radius of domain controller compromise through microsegmentation of critical infrastructure components.
Control: East-West Traffic Security
Mitigation: East-west traffic enforcement would likely have significantly reduced lateral movement capabilities by constraining inter-departmental network access and limiting reachability between government workloads through granular segmentation policies.
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility and control mechanisms would likely have detected and constrained persistent command channels through anomalous traffic pattern recognition and reduced the scope of coordinated operations across distributed network segments.
Control: Egress Security & Policy Enforcement
Mitigation: Egress security policies would likely have significantly constrained the massive data exfiltration by limiting outbound data flows and reducing the volume of sensitive government information accessible for external transfer through controlled egress points.
While ransomware deployment may still have occurred within compromised segments, the overall impact would likely have been constrained to isolated workloads rather than affecting the entire government network infrastructure.
Impact at a Glance
Affected Business Functions
- Digital Government Services
- Administrative Operations
- Transportation Management
- Environmental Compliance
Estimated downtime: 14 days
Estimated loss: N/A
5.79 terabytes of government data including personal information of 12,076 individuals, maps and geodata files, and administrative documents from Berlin's state network
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust segmentation with identity-based policies to prevent lateral movement across government departments and limit blast radius of compromised credentials
- • Deploy egress security controls with FQDN filtering and data loss prevention to detect and block unauthorized data exfiltration attempts in real-time
- • Enable multicloud visibility and anomaly detection to identify suspicious east-west traffic patterns and repeated malformed requests during the reconnaissance phase
- • Enforce encrypted traffic controls (HPE) with MACsec/IPsec for all data in transit to protect sensitive government communications from interception
- • Establish threat detection and anomaly response capabilities with baselining to identify covert tools like remote access software and unusual data access patterns



