When the Rhysida ransomware group penetrated two networks belonging to Berlin's Senate administration in August 2026, the attackers found a target guarded by IT security guidelines that had not been touched since 2017. The breach, disclosed only this week, has laid bare a governance failure at the heart of Germany's capital: nine years without updating the rules that are supposed to protect sensitive government infrastructure.

What the attackers found

Rhysida, a group known for targeting government and healthcare sectors, gained access to the Senate networks through a phishing attack. At least one employee unwittingly handed over credentials. From there, the attackers exploited weaknesses that should have been addressed years ago, among them the storage of password collections as plain-text documents on internal systems.

Plain-text password files are a well-known vulnerability. Security professionals have spent years urging organisations to adopt encrypted vaults and multi-factor authentication. That such documents existed inside a state administration in 2026 points not to a sophisticated new threat but to a failure to implement basic hygiene.

The nine-year policy gap

Berlin's IT security guidelines, which set minimum standards for the city-state's public administration, were last revised in 2017. In the years since, the threat landscape has shifted considerably: ransomware-as-a-service has lowered the barrier to entry for cybercriminals, supply-chain attacks have become routine, and the EU has introduced the NIS2 Directive imposing stricter cybersecurity obligations on public bodies. None of these developments were reflected in Berlin's internal rules.

A nine-year gap between revisions is not a minor oversight. Security frameworks typically require annual review at minimum. The Federal Office for Information Security (BSI), Germany's national cybersecurity authority, publishes updated recommendations regularly. Berlin's administration simply did not incorporate them into binding internal policy.

Not uniquely Berlin, but emblematic

Falk Steiner, a Berlin-based journalist covering digital policy, has argued that the failures exposed by this incident are not peculiar to the capital. Phishing works everywhere. Plain-text password storage, while indefensible, is more common across German organisations than anyone comfortable with information security would like to admit. The difference is that a state administration carries responsibilities that private firms do not.

Even so, the Berlin case is, as Steiner put it, a textbook example of how things should no longer work in 2026. The city-state had years of warning. Prior incidents in other German municipalities, combined with repeated BSI advisories, made the risks clear. The gap between knowing what to do and actually doing it is where this story lives.

Institutional inertia

Berlin's administration is not a small operation. The Senate oversees education, policing, urban planning and health for nearly four million residents. Its networks hold personal data, procurement details and infrastructure schematics. Protecting these systems requires both technical investment and political will.

The 2017 guidelines predate not only current ransomware tactics but also significant changes in how German public procurement handles IT security. The federal government has pushed for centralised purchasing of security software and stricter vendor requirements. Berlin, like several other Länder, has been slow to align its internal processes with these expectations. The result is a patchwork of outdated rules, underfunded IT departments and delayed upgrades.

The wider German picture

Germany's public-sector IT has been a recurring source of concern. The 2015 Bundestag hack, attributed to Russian intelligence, prompted investment in federal systems but left many municipal and state-level networks under-protected. A 2023 BSI report noted that local administrations remained the weakest link in the country's digital defences, citing outdated software, missing patches and insufficient staffing.

The European Commission has also pressed member states to accelerate compliance with EU cybersecurity legislation. NIS2, which entered into force in 2023 and required national transposition by late 2024, mandates that public administrations meet specific risk-management and reporting standards. Berlin's failure to update its own guidelines suggests it may struggle to demonstrate compliance.

Delayed disclosure

The breach occurred in August 2026 but was not disclosed until September. That lag, while not unusual for ransomware incidents where forensic work takes time, raises questions about transparency. Senate administrations hold public data. Citizens and businesses affected by potential leaks deserve timely information about what was accessed and what was taken.

Rhysida is known for publishing stolen data when ransom demands are not met. The volume of data reportedly extracted from the Senate networks, previously reported at over five terabytes, suggests the attackers had extensive access before detection.

Organisations

Rhysida · Berlin Senate Administration