Category: Security News

  • 5 Lessons from the Berlin Ransomware Attack — What the Rhysida Breach Means for Public Institutions

    Berlin Ransomware

    Key Summary

    • The Berlin city government officially confirmed that the Rhysida ransomware gang posted a confession on a dark web leak site and is now attempting financial extortion against the city
    • Attackers gained initial access weeks before being detected and performed lateral movement across parts of Berlin’s administrative network, according to the investigation
    • Exposed data is believed to include personnel records, citizen service information, and internal financial records; the full scope of the breach remains under forensic investigation

    Analysis

    The Berlin ransomware incident is not just a simple hacking case. The Berlin city government officially confirmed that the Rhysida gang posted a confession on a dark web leak site and is now attempting financial extortion. Weeks before detection, the attackers had already completed lateral movement across sections of Berlin’s administrative network.

    This is the most painful point from a practitioner’s perspective. The fact that a city-scale administrative network failed to detect external intruders for weeks means that internal visibility and anomaly detection systems were not properly in place.

    Berlin Ransomware Breach Timeline — From Initial Access to Data Exfiltration

    According to the Berlin city government’s announcement, the attack followed a typical ransomware intrusion pattern. Initial entry is believed to have come through phishing emails, exposed VPN/RDP endpoints, or external Initial Access Brokers (IABs). This was followed by a double-extortion tactic: abusing legitimate cloud services (remote management tools, file sharing) to exfiltrate data, and then deploying bulk encryption at the end.

    According to BleepingComputer’s report, the leak site is believed to include personnel records, citizen service information, and internal financial records. The exact scope of the breach will be confirmed by the forensic investigation at Berlin’s IT Coordination Office (ITDZ Berlin).

    The Rhysida Gang’s RaaS Structure and Tactics

    Rhysida is a Ransomware-as-a-Service (RaaS) operation that first appeared in 2023. Core operators provide the ransomware builder and leak site infrastructure, while affiliate attackers use these tools to perform their own intrusions. The profit split between attackers and operators is typically known to be around 7:3 to 8:2.

    Rhysida’s weapon is its consistent target selection across healthcare, government, education, and manufacturing sectors. Ransoms are typically set in the seven-figure dollar range, and if unpaid, the leaked data is released in stages to apply pressure. The fact that the Berlin ransomware incident followed the same pattern confirms that the gang’s operational playbook works just as well against public institutions.

    Primary and Secondary Damage Scenarios

    Exposed personnel and financial data immediately becomes phishing fodder. An attacker who knows employee names and internal report titles can craft a convincing email disguised as a “security check notice.” Under GDPR, the city of Berlin has notified the relevant supervisory authority of the breach, but the real danger concentrates in the days immediately following notification. This is because secondary phishing attacks, crafted from the externally exposed information, will target both city employees and citizens at the same time.

    What I consider the most serious aspect of this incident is the length of the compromise period. The fact that lateral movement was possible for weeks strongly suggests that the attacker obtained domain controller privileges.

    Incident Response — ITDZ Berlin’s 7-Day Sprint

    The city of Berlin is simultaneously working with external incident response teams on the following tasks: blocking intrusion paths, bulk revoking compromised credentials, auditing access paths, and collecting forensic evidence. The city’s data protection authority is gradually disclosing the scope of the exposed information to citizens.

    The GDPR notification obligation is 72 hours, but full response completion can take several months. Looking at similar European public institution cases, some have taken 4 to 6 months just to recover their administrative networks.

    5 Lessons from the Berlin Ransomware Incident for Public Institutions

    The Berlin ransomware case vividly demonstrates what risks city-scale infrastructure faces. Compared to U.S. city government breach cases, the initial intrusion vectors are strikingly identical: unpatched VPN/RDP gateways, reused service account passwords, and SIEMs with anomaly alerts turned off.

    In a similar context, as seen in the article China Hacking Correction: Words Reversed in Just 3 Days, cyberattack incidents often see the truth shift during the post-incident reporting process. The final damage scale of the Berlin ransomware case could also vary significantly based on forensic investigation results.

    Key Issues

    The Berlin ransomware incident raises three core issues.

    First, weeks of detection failure exposes the limitations of public institution SIEMs. Second, VPN/RDP patching cycles are slower than attackers’. Third, double extortion must now be assumed as the baseline scenario for public institutions.

    What to Do Right Now

    • Extract the list of externally exposed VPN/RDP gateways today and compare them against patched versions
    • Audit whether administrator account passwords are being reused and immediately rotate domain controller credentials
    • Verify that SIEM anomaly detection rules are enabled and add Indicators of Compromise (IoC) feed sources
    • Verify that backup data is stored separately in offline, immutable storage
    • Run at least one secondary phishing simulation drill for employees within this week

    Frequently Asked Questions

    What is Rhysida ransomware?

    It is a RaaS-type ransomware gang that appeared in 2023, primarily active in healthcare, government, and education sectors. It mainly uses double-extortion tactics, and ransoms are typically set in the seven-figure dollar range.

    Did the Berlin city government pay the ransom?

    The Berlin city government’s official position is refusal to negotiate. In general, public institutions have a strong tendency to decide not to pay ransoms.

    How is the leaked citizen information being protected?

    Berlin’s data protection authority is currently analyzing the scope of the leak, and citizens will be notified in stages. Under GDPR, the supervisory authority was notified within 72 hours.

    Could the same thing happen to Korean public institutions?

    Yes, the same initial intrusion vectors exist in Korea. VPN patch delays and credential reuse are common issues across global public institutions.

    The Berlin ransomware case ultimately demonstrates the structural vulnerabilities of public sector cybersecurity. The scarier fact isn’t the intrusion itself, but that it went undetected for weeks. Even after the external incident response team completes intrusion blocking and credential revocation, the secondary phishing risk will persist for at least a quarter. Operations teams must keep this in mind.

    Expert Comments (AI)

    Cybersecurity Expert

    Rhysida’s weeks of unauthorized lateral movement is a textbook double-extortion case showing how far public administrative networks lag behind in identity-centric controls and breach visibility

    Since emerging in 2023, Rhysida has targeted healthcare, government, and education as a RaaS operation, faithfully executing a proven playbook: entry through exposed VPN/RDP endpoints and Initial Access Brokers, abuse of cloud services for exfiltration, followed by bulk encryption. The most serious signal in this incident is the weeks of lateral movement before detection, which is interpreted as the result of overlapping gaps in endpoint detection coverage, lack of privileged account segmentation, and insufficient domain controller access controls. The response flow — external incident response team deployment, bulk revocation of compromised credentials, parallel forensic investigation — itself aligns with standard best practices. However, given that domain administrator-level credential exposure is strongly suggested, the re-intrusion risk remains without a full Active Directory reconstruction-level remediation and a complete VPN gateway audit. Exposed personnel and financial data will be used as raw material for sophisticated spear phishing over the coming quarters, so defense against the human attack surface remains a long-term challenge separate from technical response. Looking ahead, public institutions, with their low incentive to pay ransoms but vulnerable security budgets and staffing structures, will inevitably remain persistent targets for RaaS operations.

    Rating: 5/10 – Response procedures follow standards, but the pre-incident control level revealed by weeks of detection failure and privileged credential exposure clearly falls short in an era where double extortion is the baseline scenario

    Data Protection & Crisis Management Expert

    Refusing to pay the ransom and fulfilling the 72-hour notification obligation is standard doctrine, but the real test lies in blocking secondary damage to citizens and recovery governance spanning months

    The public institution’s choice to refuse ransom payment aligns with international guidance: payment does not guarantee decryption or data deletion, and it creates targeting incentives. Fulfillment of the GDPR 72-hour supervisory authority notification and staged disclosure of leak scope is appropriate from a transparency standpoint, but since secondary phishing targeting citizens and employees is most dangerous in the days immediately following notification, official channel warning campaigns must run concurrently with the notification to be effective. Exposed personnel records and financial information become direct material for financial fraud and identity theft, so trust cannot be restored through notification alone without follow-up measures such as operating a consultation window or support system for affected citizens. The disappointing point is that chronic shortages in local government IT budgets and staffing are the structural backdrop of this breach, and meeting the public sector resilience requirements of the NIS2 era requires a shift from one-time recovery to permanent investment frameworks. Considering similar European cases where administrative network recovery took 4 to 6 months, service continuity plans and offline backup verification should be elevated to policy priorities.

    Rating: 7/10 – Refusal to pay and regulatory compliance are exemplary in direction, but execution power in preventing secondary damage to citizens and resolving structural issues in local government security investment remain as challenges