A deadline ran out on Friday afternoon. After that, 1.4 million files from Berlin's state administration sat online as a download, free for anyone who wants them.
The sequence, briefly. Between 7 and 12 August, a group called Rhysida copied data out of two senate departments: urban development, building and housing, plus mobility, transport, climate protection and environment. On 14 August it was noticed. Both departments were cut off from the state network and were effectively unable to work for over a week. Rhysida demanded 30 bitcoin, roughly two million euros, and set a deadline. Berlin refused to pay. That was the right call, and it was also the end of the options. On 4 September everything went public.
What is in it, according to reporting over the past days:
- personnel files, work certificates, salary lists
- penalty and enforcement proceedings
- identity documents, IBANs, passwords in plaintext inside Office files
- documents from Bundesrat committees
- a critical-infrastructure vulnerability analysis of Berlin's drinking water supply
- contingency planning for the defence case, including lists of infrastructure to be protected in an emergency
And the consequence nobody on the panel talks about, which the affected people feel very concretely: more than 50,000 households could not apply for or receive housing benefit for weeks. Education and participation benefits were hit too. The attack on the secret plans was the headline. The attack on the rent was the effect.
Now the part I have not been able to put down since Friday. This is not a wild-west environment. It is one of the most densely regulated IT landscapes this country has. BSI baseline protection, ISO 27001, GDPR, classified information rules, data protection officers, information security officers, procurement law, the court of audit, and NIS2 at the door. The state's central IT provider, ITDZ Berlin, has been certified to ISO 27001 on the basis of IT-Grundschutz since 2015 and submits to annual surveillance audits. The scope covers the information security management system “and the entire technical and structural infrastructure of all service buildings including the High Secure Data Centre”.
The certificate did not lie. It said exactly what a certificate can say: that on a given date, within a defined scope, a process could be described and demonstrated. The attacker is testing something else.
The auditor announces himself
An audit is a sample with an appointment. It has a scope, a preparation phase, a list of evidence to submit, and a person who ends up judging documents rather than a live confrontation. Everyone involved knows when it starts. That is not fraud, that is the design.
The attacker has no appointment. He has no scope. He is not looking for the average security level, he is looking for the worst spot, and he has to find it once. The defence has to be right everywhere, every day, in August too, including in the unit that was never in scope.
None of this is new, and it is still not priced in. Because the certificate does something that hides the asymmetry: it closes a question. It has an issue date, a document, a folder it lives in, and a person who can hold it up. It feels like a state. Attack surface is not a state. It is a running process that changes with every new interface, every new supplier and every staff handover.
This is not an accusation against ITDZ, and it should not become one. That certificate says nothing about the file storage of a specialist department, and it does not claim to. That is precisely the problem. We use an instrument that makes a narrow, accurate statement as the answer to the only question anyone actually asks: are we secure?
A certificate says: on the reporting date, the process was describable. An attack asks: did it hold on Tuesday at three? Both can be true. Only one of them hangs in the corridor.
Regulation manufactures the loot
This is the part I like least, because more effort does not dissolve it.
To prove you are secure, you have to write down how you are secure. Network diagrams. Role concepts. Risk analyses. Contingency and recovery plans. Records of processing activities. Supplier contracts with access arrangements. Vulnerability analyses of critical infrastructure. Every single one of those documents is sensible. Every single one is also a map.
The vulnerability analysis of Berlin's drinking water supply exists because a rule demands it, and the rule is reasonable. But afterwards that document sits as a file inside an administration, on the same network as the housing benefit applications, protected by the same procedures as a meeting protocol. Whoever has the file no longer needs to understand the infrastructure. It has been explained to him, sorted, with a table of contents, by experts, on behalf of the state.
The attacker does not need to analyse the system. He needs to find the file in which it was analysed. That file exists because a regulation asked for it.
The same goes for the plaintext passwords in Office documents. Those do not come from stupidity, or at least not only. They come from handovers, from deputising arrangements, from supplier changes, from the entirely legitimate need for work to continue when somebody is ill. A process that demands traceability produces documentation. Documentation is portable. 5.8 terabytes portable.
The more thorough the compliance, the better the loot. That is not polemics, it is arithmetic. And it is why the reflex after an incident like this, namely more documentation duties, is in part a contribution to the next one.
Why nobody gets out
Because everyone is behaving rationally. That is the uncomfortable part.
The auditor is paid for the attestation. The consultant for the concept. The department head needs a paper to show the court of audit, the data protection officer and the committee. The leadership needs a sentence for the press conference. All of these people are doing their jobs, and all of these outputs have an invoice number, a date and an addressee.
The attack that did not happen has none of that. No document, no meeting, no evidence. I have written elsewhere that organisations pay for what they can see, and therefore optimise away exactly the work whose result is invisible. Security is the purest case of that pattern. Compliance is visible. Hardening would be effective. Count the ink and you get ink.
I do not exempt myself. I have written enough concepts to know how good a finished document feels, and how closely that feeling resembles the feeling of having solved a problem.
What actually shifted
I am careful with the sentence that the world has changed. I have argued myself that it is usually not a diagnosis but a negotiating move: whoever says it normally wants to push something through for which they lack the argument. So here is the evidence rather than the phrase.
Rhysida is not a state. It is a business model, ransomware as a service, active since 2023, with an affiliate programme and revenue share. That structure gave a German federal state a deadline, in a currency no central bank issues, and enforced a penalty when the deadline passed. Berlin could answer with exactly two things: pay or do not pay. A constitutional state has many instruments, but almost all of them assume the counterparty has an address, a border, a bank account, a reputation to lose or a court of jurisdiction. None of that applies here.
At the same time, the ability of public administrations to function at all rests on software that is built, operated and can be switched off somewhere else. That is the other half of the same shift, and I have worked it through here. The state has not become weak. It has remained responsible for things it no longer controls technically, only contractually and through regulation. Regulation is the last instrument it definitely owns. Which is exactly why it gets overstretched.
The thread holding up what we consider secured has not snapped. It is thinner than the paperwork suggests. It consists of a few people who really know their systems, a handful of services that happen to be patched, and a backup whose restore is only tested for real when it matters.
The objection
Up to here this reads like a reckoning with rules, and that is the point at which I would stop trusting the text. The objections, in the order they occurred to me.
Without baseline protection it would be worse. Probably true. BSI baseline protection has raised the floor, and a floor is worth more than any individual act of heroism. My claim is narrower: the floor is being sold as a ceiling. A passed audit proves that minimum requirements were met on the reporting date. It does not prove that a motivated attacker fails, and it is not meant to.
This is hindsight. Fair. After an incident everything looks negligent, and I am sitting here with three days of reporting and no knowledge of the situation on the ground. Which is why the yardstick has to be one you can state in advance. That is the next paragraph.
So what would have helped? Not a moral, a list. Keep less data, because deleted data cannot leak. No credentials in documents, enforced technically instead of forbidden in a policy. Segment networks so one access does not open two departments. Treat compliance documents as crown jewels, with their own classification and their own storage, because they are the most valuable summary of the target that exists. And rehearse the outage, with a real stopwatch, including the question of how housing benefit gets paid without the specialist system. All of it unspectacular, none of it producing a certificate.
And NIS2? It brings two things that actually bite: personal liability for management, and reporting deadlines. Deadlines are interesting because for the first time they measure a speed rather than a description. Everything else in NIS2 measures, again, whether you can write down what you do. I would not abolish the directive. I would only stop confusing compliance with it for security.
Security is no longer a state
The word we use comes from a world with walls. Secure was a condition you reached, verified and then held. That is why a certificate fits it so well, and why a passed audit feels like a result.
What Berlin is demonstrating is a different word. Not a state, a speed. The questions that would have told you something are all about time and reach. How long does somebody copy data before it is noticed: here, days. How far does a single access reach: here, across two departments. How long until the benefit flows again: here, weeks, for more than 50,000 households. Every organisation can measure those three numbers in advance, with no incident, no auditor and no certificate. They are uncomfortable because they close nothing. They stay bad for as long as they are bad.
The comforting thing about the old idea was that security is something you can finish. That idea is the real loss, and it is not coming back. What can come back is honesty about the order of magnitude: a federal state was made unable to work by a handful of people, and the decisive numbers appeared in no audit report.
The certificate was valid. The data is gone. Both are true at the same time, and that is exactly the problem.
Related
- NIS2 Compliance Guide. What the directive actually demands if you take it seriously instead of ticking it off.
- Zero Trust Security. The technical answer to the question in this piece: what if the attacker is already inside?
- The Switch-Off. The same shift from the other side: responsibility without control.
- Fear Is Not a Probability. Why felt security and measured risk drift so far apart.
- Thinking Looks Like Doing Nothing. The mechanism underneath: organisations pay for what they can see.
- “The World Has Changed” Is Not a Diagnosis. Why I am careful with that sentence, even when it holds up, as it does here.