By NHI Mgmt Group Editorial TeamDomain: Breaches & IncidentsSource: UnosecurPublished August 7, 2026

TL;DR: Rhysida’s breach of Berlin’s state network spread for ten days because segmentation and VPN controls did not answer what a compromised account could reach across departments, leaving 5.79 terabytes across 1.44 million files and nearly 6,000 credential files exposed, according to Unosecur. The case shows that authorization mapping, not perimeter control, determines blast radius in large NHI-heavy environments.


At a glance

What this is: This is an analysis of how Berlin’s ransomware incident spread across a 600-site government network and what the breach revealed about account-level blast radius.

Why it matters: It matters because IAM and NHI teams need to know not just how identities authenticate, but what standing access, inherited permissions, and shared credentials they can actually reach once inside.

By the numbers:

👉 Read Unosecur's analysis of the Berlin ransomware breach and identity blast radius


Context

Berlin’s ransomware case is a textbook reminder that authentication controls and network segmentation are not the same as authorization control. A compromised identity can still move far beyond the segment it entered if access is inherited, shared, or poorly mapped across departments, which is the primary identity governance problem exposed here.

For IAM and NHI programmes, the real question is blast radius: what a specific account, service credential, or shared login can reach across the environment before anyone notices. This incident shows why organisations need a standing cross-system access map, not an after-the-fact reconstruction during crisis response.

The breach is typical of large, long-lived government networks where segmentation exists but runtime authorization visibility does not. That makes it especially relevant to teams responsible for human accounts, service accounts, and shared administrative access in complex estates.


Key questions

Q: What breaks when a compromised account has more reach than the network segment it sits in?

A: Segmentation may still stop some traffic, but it does not stop an identity from reaching systems it was already authorised to touch elsewhere. The failure is effective access visibility. Teams need a live understanding of blast radius, because containment depends on what the account can do, not just where it logs in.

Q: Why do network controls fail to contain ransomware when shared credentials and inherited access exist?

A: Because those controls govern connectivity, not the permissions already attached to the identity. If a stolen login can reach multiple systems through inherited access or reused secrets, the attacker can keep moving even when the initial segment is isolated. Authorization scope is the missing control plane.

Q: How can security teams know whether identity blast radius is actually shrinking?

A: Look for fewer cross-system entitlements, fewer accounts with standing privilege, and faster revocation across connected systems after a change or incident. If you still need a manual department-by-department investigation to understand reach, the blast radius is not under control.

Q: Should organisations prioritise identity mapping before another segmentation project?

A: Yes, when the main risk is compromised accounts moving across systems you cannot currently trace. Segmentation remains useful, but it will not tell you who can reach what. A current identity-to-resource map gives responders the information they need to contain lateral movement without guessing.


Technical breakdown

Why segmentation did not answer authorization at runtime

Network segmentation limits where traffic can flow, but it does not tell you what an authenticated identity is allowed to do after it gets in. In a large enterprise or government network, that distinction matters because a user, admin, or service account may inherit permissions that cross department boundaries even when the network itself is split. The Berlin case shows the common failure mode: perimeter and transport controls exist, but no single control answers the scope question for the identity itself. That leaves responders reconstructing access after compromise instead of constraining it beforehand.

Practical implication: map identity permissions separately from network segments so compromised accounts have a known blast radius before incident response begins.

Standing privilege, shared credentials, and inherited access

Standing privilege is access that remains available until someone manually revokes it. Shared credentials and inherited permissions make that worse because compromise of one account can expose access paths that were never meant to be obvious from the department boundary alone. In a heterogeneous environment, these entitlements often accumulate over years through delegation, vendor access, and temporary exceptions that never get cleaned up. Berlin’s difficulty was not the initial breach alone, but the need to discover which systems the compromised identity could still touch across the rest of the state backbone.

Practical implication: identify all standing and shared access paths and eliminate the ones that do not have an explicit business owner.

Why runtime access maps matter more than static admin lists

A static list of who administers what is not the same as a live map of what an identity can reach right now. Runtime access changes through inherited entitlements, service account reuse, and partial offboarding, so the effective blast radius can be much wider than any directory record suggests. That is why Berlin’s crisis unit had to build the answer manually, department by department. For identity security, the mechanism that fails is visibility into effective access, not the existence of authentication or segmentation itself.

Practical implication: maintain a current effective-access inventory that correlates identities, service accounts, and cross-system permissions.


Threat narrative

Attacker objective: The attackers aimed to maximise extortion leverage by stealing sensitive records, credentials, and government data that could be used for pressure and resale.

  1. Entry occurred when Rhysida gained access to Berlin’s environment through a compromised identity path that standard authentication controls did not prevent.
  2. Escalation followed as the attackers used the compromised account’s reachable permissions to move beyond the initial department into connected systems and shared resources.
  3. Impact came from prolonged access and exfiltration, including 5.79 terabytes of files and nearly 6,000 files containing login credentials.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Account-level blast radius is the control gap Berlin exposed. Segmentation and MFA answered how someone got in, but they did not answer what the compromised account could reach once authenticated. That is the failure mode: identity scope was not mapped tightly enough to stop cross-department spread. For large estates, the practitioner conclusion is that blast radius must be a governed attribute, not a forensic discovery.

Standing privilege is the real accelerator in long-lived government networks. When access persists across departments, inherited permissions and shared credentials turn one compromise into a multi-system problem. This is not merely an incident response weakness; it is a governance failure in how access is granted, reviewed, and retired. The operational conclusion is that unmanaged persistence is what makes a breach hard to contain.

Runtime authorization visibility matters more than authentication completeness. A network can have strong login controls and still fail to answer the only question that matters during containment: what can this identity do right now. That is the point where NHI governance, PAM discipline, and IAM visibility converge. The practitioner conclusion is to treat effective access as a first-class security control.

Cross-system access mapping is now a board-level resilience requirement. Berlin’s crisis team had to reconstruct access after the fact because the environment did not already expose a complete identity-to-resource picture. That is exactly the kind of delay that turns a contained intrusion into a public-sector crisis. The practitioner conclusion is to keep the blast-radius map current before the breach, not after it.

The named concept here is identity blast radius. It is the full set of systems, data, and delegated paths a single identity can touch across the environment. In complex NHI and human IAM estates, that blast radius often exceeds what any single team believes it owns. The practitioner conclusion is to govern reach, not just login.

From our research:

What this signals

Berlin’s case should push identity teams to treat effective access as a runtime security problem, not a quarterly review artifact. If you cannot answer what a compromised account can reach across every connected system, you do not yet have enough control to contain a fast-moving intrusion. The practical shift is toward live identity-to-resource mapping and away from assumptions based on departmental ownership.

Identity blast radius: this is the governance gap organisations keep rediscovering after the fact. The term matters because it joins IAM, PAM, and NHI oversight into a single operational question: what can this actor actually reach right now? Teams should expect more board attention on that answer as ransomware groups continue to exploit authorization drift.

For practitioners, the signal is clear: resilience depends on knowing whether access can be revoked faster than attackers can use it. That means cross-system revocation procedures, ownership for shared credentials, and continuous visibility into standing privilege need to sit alongside segmentation and MFA in programme design. See also the 52 NHI Breaches Report for the recurring patterns behind these failures.


For practitioners

  • Build an effective-access map Correlate each identity, service account, and shared credential to the systems it can actually reach across departments, not just the segment it belongs to. Use that map to define blast radius before an incident forces manual reconstruction.
  • Review standing and inherited permissions Identify accounts that retain access beyond their current business need, especially where access crosses department boundaries or survives role changes. Remove access that is not tied to an explicit owner and an active use case.
  • Treat shared credentials as containment risks Inventory any credential reused across teams, systems, or operational boundaries and replace it with individually attributable access where possible. Shared secrets make it impossible to know which systems a compromised login can reach.
  • Rehearse cross-system revocation Test how quickly you can revoke access across all connected systems after compromise, including delegated and partially offboarded accounts. The goal is to prove you can shrink the blast radius before attacker use becomes exfiltration.

Key takeaways

  • Berlin’s breach shows that authentication and segmentation can both be present while identity blast radius remains dangerously unknown.
  • The scale of exposure was large, with 5.79 terabytes and nearly 6,000 credential files claimed by Rhysida.
  • The control that changes containment outcomes is effective access mapping, because responders must know what an identity can reach before they can revoke it.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Inventory and OwnershipThe article is about unknown and uncatalogued identity reach across connected systems.
Recommendation — Inventory every non-human and shared identity with cross-system reach and assign a clear owner.
NIST CSF 2.0PR.AC-4 — Access Permissions and AuthorisationsThe core problem is whether compromised identities have excessive reachable access.
Recommendation — Review access permissions continuously and remove entitlements that expand blast radius without business need.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeStanding privilege and inherited access are the conditions that made containment harder.
Recommendation — Apply least privilege to reduce the number of systems any single account can reach.
CIS Controls v8CIS-5 — Account ManagementAccount management is central because shared and partially offboarded accounts increased exposure.
Recommendation — Reconcile accounts and disable stale or shared access paths before they become a containment problem.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementThe incident pattern includes credential exposure followed by spread through reachable systems.
Recommendation — Map credential exposure and lateral movement paths to the identities that can still touch adjacent systems.

Key terms

  • Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
  • Standing Privilege: Standing privilege is access that remains active even when no immediate task requires it. For NHI programmes, it is a common failure mode because long-lived credentials and persistent roles create unnecessary exposure. Reducing standing privilege usually means tighter expiry, on-demand access, and clearer review of who or what still needs access.
  • Effective Access: The actual permissions an identity can exercise after inheritance, nested groups, delegation, and object-level controls are evaluated. In Active Directory, effective access is more useful than direct membership because it reveals the true operational reach of a service account.
  • Cross-Platform Revocation: Cross-platform revocation is the process of removing a credential or entitlement everywhere it is trusted. In NHI environments, this matters because a service account or token may be active in several systems, and revoking it in only one place leaves usable access behind.

What's in the full article

Unosecur's full analysis covers the operational detail this post intentionally leaves for the source:

  • The breach timeline from first alert to second leak, including the crisis unit's response sequence.
  • The full set of claimed data categories, including credentials, legal files, and personal records.
  • The vendor's explanation of how its identity fabric correlates access across systems and departments.
  • Implementation detail on read-only integration and on-prem connectivity through Unochariot.

👉 The full Unosecur post covers the breach timeline, claimed exfiltration, and access-control implications in more detail.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on September 11, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org