Berlin's Senate network was hit by a ransomware attack carried out by the Rhysida group, one of several government targets struck in a compressed period. A national tax authority and a national justice ministry were also attacked within the same two weeks.

The clustering is notable. Whether it reflects coordination, a shared initial access broker supplying government-sector footholds, or simply a common unpatched product across public sector estates, three national-level government targets in fourteen days is not background noise.

Rhysida's pattern

Rhysida operates as ransomware-as-a-service and has a documented preference for public sector and public-interest targets: government bodies, healthcare providers, educational institutions. The group uses double extortion — encrypting systems and stealing data, then threatening publication if payment is refused.

The targeting logic is straightforward, if grim. These organisations combine three properties attackers like: extreme sensitivity to service disruption, custodianship of data that cannot be replaced, and security budgets set by processes that do not respond quickly to threat conditions.

Why government breaches are different

When a retailer loses card data, the harm is real and largely bounded. Cards get reissued, monitoring gets offered, the exposure decays.

Government data does not work that way. A Senate or ministry network can hold:

  • Citizen identity records, including national identifiers that cannot be changed on request.
  • Tax and financial records covering years of individual history.
  • Judicial and law enforcement material, potentially including witness or victim information.
  • Social services records covering vulnerable people.
  • Employee data for public officials, which has obvious targeting value.

A leaked national identity number is a lifetime exposure. There is no reissue process, and the harm compounds every time it is combined with another leaked dataset.

The structural problem

Public sector security suffers from constraints that are political and budgetary rather than technical:

Procurement cycles outlast threats. Buying a security capability can take twelve to eighteen months from identified need to deployed control. Attacker tooling iterates in weeks.

Legacy systems cannot be retired. A statutory obligation to maintain a records system built in 2004 is not negotiable because the vendor stopped issuing patches.

Salary ceilings limit hiring. Public pay scales cannot match private sector security salaries, and the gap is widest exactly at the senior levels where experience matters most.

Federated authority fragments accountability. A city-state administration like Berlin's spans many agencies, each with its own IT decisions, connected by networks that were built for convenience.

What actually helps

For public sector organisations working within those constraints, the interventions with the best return are the ones that do not require a large procurement:

  • Offline, immutable backups, tested by restore. The single control that most reliably determines whether an incident is a bad week or an existential event.
  • Network segmentation between agencies. If a compromise at one department reaches all of them, you have one large target rather than many small ones.
  • Phishing-resistant MFA on administrative accounts. Hardware keys cost less than a single day of incident response.
  • An assumption of exfiltration. Plan the notification, legal and communications workstreams before an incident, because double extortion means data theft is the default, not the exception.
  • Shared services where politically possible. A single well-staffed regional SOC serving many small agencies beats each of them running an under-resourced one.

The Berlin incident will run its course, and recovery will be measured in weeks. The more useful question for every other public administration is whether they could answer, today, how long it would take them to restore from backups they have actually tested.