TL;DR: Rhysida’s breach of Berlin’s state network spread for ten days because segmentation and VPN controls did not answer what a compromised account could reach across departments, leaving 5.79 terabytes across 1.44 million files and nearly 6,000 credential files exposed, according to Unosecur. The case shows that authorization mapping, not perimeter control, determines blast radius in large NHI-heavy environments.
NHIMG editorial — based on content published by Unosecur covering the Berlin ransomware breach: The Ten-Day Gap That Let Rhysida Spread Across Berlin's 600-Site Government Network
By the numbers:
- Rhysida claimed 5.79 terabytes across 1.44 million files from Berlin’s government network.
- Berlin’s compromise affected a shared state backbone spanning 600 sites across the city network.
Questions worth separating out
Q: What breaks when a compromised account has more reach than the network segment it sits in?
A: Segmentation may still stop some traffic, but it does not stop an identity from reaching systems it was already authorised to touch elsewhere.
A: Because those controls govern connectivity, not the permissions already attached to the identity.
Q: How can security teams know whether identity blast radius is actually shrinking?
A: Look for fewer cross-system entitlements, fewer accounts with standing privilege, and faster revocation across connected systems after a change or incident.
Practitioner guidance
- Build an effective-access map Correlate each identity, service account, and shared credential to the systems it can actually reach across departments, not just the segment it belongs to.
- Review standing and inherited permissions Identify accounts that retain access beyond their current business need, especially where access crosses department boundaries or survives role changes.
- Treat shared credentials as containment risks Inventory any credential reused across teams, systems, or operational boundaries and replace it with individually attributable access where possible.
What's in the full article
Unosecur's full analysis covers the operational detail this post intentionally leaves for the source:
- The breach timeline from first alert to second leak, including the crisis unit's response sequence.
- The full set of claimed data categories, including credentials, legal files, and personal records.
- The vendor's explanation of how its identity fabric correlates access across systems and departments.
- Implementation detail on read-only integration and on-prem connectivity through Unochariot.
👉 Read Unosecur's analysis of the Berlin ransomware breach and identity blast radius →
Berlin ransomware breach: what the account blast radius gap exposed?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Account-level blast radius is the control gap Berlin exposed. Segmentation and MFA answered how someone got in, but they did not answer what the compromised account could reach once authenticated. That is the failure mode: identity scope was not mapped tightly enough to stop cross-department spread. For large estates, the practitioner conclusion is that blast radius must be a governed attribute, not a forensic discovery.
A few things that frame the scale:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, according to The 2024 ESG Report: Managing Non-Human Identities.
- Enterprises that have experienced a compromised NHI averaged 2.7 separate incidents in the past 12 months, which shows how quickly repeated exposure compounds operational risk.
A question worth separating out:
Q: Should organisations prioritise identity mapping before another segmentation project?
A: Yes, when the main risk is compromised accounts moving across systems you cannot currently trace. Segmentation remains useful, but it will not tell you who can reach what. A current identity-to-resource map gives responders the information they need to contain lateral movement without guessing.
👉 Read our full editorial: Berlin ransomware breach exposed the gap in account blast radius