{"id":2934,"date":"2026-09-29T11:07:13","date_gmt":"2026-09-29T09:07:13","guid":{"rendered":"https:\/\/blog.eprivacy.eu\/?p=2934"},"modified":"2026-09-29T11:07:13","modified_gmt":"2026-09-29T09:07:13","slug":"berlin-shows-without-nis-2-you-are-at-high-risk","status":"publish","type":"post","link":"https:\/\/blog.eprivacy.eu\/?p=2934","title":{"rendered":"Berlin Shows: Without NIS-2, You Are at High Risk"},"content":{"rendered":"\n<p>In August 2026, the Rhysida ransomware group infiltrated the Berlin state network via a phishing email. It used valid login credentials that were stored unprotected in Word files and, between August 7 and 12, stole approximately 5.7 terabytes (1.44 million files) from two Senate administrative offices. The attack was not detected until August 13, due to a system malfunction. By the time the authorities were isolated, the data exfiltration had long since ended. After the ransom deadline expired in September, Rhysida published the data openly on the dark web: personnel files, plaintext passwords, disciplinary proceedings, highly sensitive security protocols, and detailed plans for critical infrastructure.<\/p>\n\n\n\n<p><strong>Why the Attack Was So Severe<\/strong><br>Although Berlin had reporting requirements, it lacked an adequate risk management system to detect attacks early on. In 2025, funding for IT security was even cut. What measures need to be improved:&nbsp;<\/p>\n\n\n\n<ol><li>Risk Management<\/li><li>Continuous Monitoring<\/li><li>Crisis Management<\/li><\/ol>\n\n\n\n<p><strong>Berlin was just the beginning. Close your gaps.<\/strong><br><br>Check now to see if your measures meet the necessary requirements before an incident occurs.<\/p>\n\n\n\n<p>Our consulting packages help you with:&nbsp;<\/p>\n\n\n\n<ul><li>An analysis of the current situation<\/li><li>Identification, prioritization, and documentation of measures<\/li><li>Review of reporting processes<\/li><li>Training to ensure this doesn&#8217;t happen to you in the first place<\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<p>In August 2026, the Rhysida ransomware group infiltrated the Berlin state network via a phishing email. It used valid login credentials that<\/p>\n<p class=\"link-more\"><a class=\"myButt \" href=\"https:\/\/blog.eprivacy.eu\/?p=2934\">Read More<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[1],"tags":[],"_links":{"self":[{"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=\/wp\/v2\/posts\/2934"}],"collection":[{"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2934"}],"version-history":[{"count":1,"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=\/wp\/v2\/posts\/2934\/revisions"}],"predecessor-version":[{"id":2935,"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=\/wp\/v2\/posts\/2934\/revisions\/2935"}],"wp:attachment":[{"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2934"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2934"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2934"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}