Skip to content
Cybersecurity

Cyber Attacks on Companies in Berlin and Brandenburg: Current Situation, Typical Attack Paths and What SMEs Should Do Now

Figures from BSI, BKA, Bitkom and Brandenburg police, attacks on Berlin's administration and hospitals, common entry points and priorities for SMEs.

Published on 5 min read

Meeting room with a white table and a wall display showing a blue network of nodes and lines.

In August 2026, attackers gained access to the Berlin state network and copied several terabytes of data from two Senate departments. The case shows that cyber attacks hit public authorities, hospitals and companies in the region. The situation reports of the BSI, the BKA and the Brandenburg police and the documented cases show a recurring pattern: most successful attacks exploit known weaknesses in organisation and operations, not unknown vulnerabilities.

The situation in figures

The German Federal Office for Information Security (BSI) continues to rate the situation as tense in its 2025 report: an average of 119 new vulnerabilities per day became known, and around 80 per cent of reported attacks targeted SMEs. The BSI’s conclusion for 2026: protect attack surfaces through restrictive access management, timely updates and as few publicly reachable systems as possible.

In its Bundeslagebild Cybercrime 2025, the Federal Criminal Police Office (BKA) reports that ransomware attacks rose to 1,041. Bitkom’s Wirtschaftsschutz 2026 study reports that only 67 per cent of companies surveyed could reliably detect an attack, down from 87 per cent the year before. The Brandenburg State Criminal Police Office notes in its Lagebild Cybercrime 2024 that many ransomware cases go unreported because companies first want to restore operations and avoid reputational damage.

Documented cases from the region

Berlin state network, August 2026. Between 7 and 12 August 2026, the Rhysida ransomware group copied data from two Senate departments. The perpetrators demanded 30 bitcoin, the state did not pay, and on 4 September the group published around 5.7 terabytes on the darknet. According to media reports, initial access came via valid VPN credentials without multi-factor authentication. The exfiltration went unnoticed for five days.

Kammergericht Berlin, September 2019. The Emotet trojan entered the court’s network via a forged email and downloaded the Trickbot malware. The forensic final report named an unsegmented network and local administrative rights on office PCs as decisive factors. The court had to be taken offline completely.

Brandenburg companies, 2024. The Brandenburg police’s 2024 report documents a company that paid around 3,000 euros in bitcoin after being encrypted; the perpetrators had entered via an openly reachable remote desktop connection with an insecure password. At another company, several servers were encrypted and around 200 gigabytes copied, with a demand of 100,000 US dollars. It did not pay because it could restore the data from backups.

The typical attack paths

  1. Stolen or guessed credentials. In the state network and in the Brandenburg RDP case, a username and password were enough. Without multi-factor authentication on remote access, every leaked password becomes full access.
  2. Phishing and social engineering. Emotet at the Kammergericht began with an email. The Brandenburg police also describe payment diversion fraud, in which perpetrators change the bank details on invoices.
  3. Unpatched, publicly reachable systems. With 119 new vulnerabilities a day, the speed of patching is decisive.
  4. Missing segmentation and too many rights. At the Kammergericht, the malware could move freely.
  5. Missing detection. Five days of exfiltration without an alarm in the state network. Without monitoring, a break-in goes unnoticed until the extortion demand arrives.

What SMEs should do now

The most effective measures are known and within reach of SME budgets. In this order:

  1. Secure remote access. Every VPN, remote desktop and remote maintenance access gets multi-factor authentication, and open RDP ports are closed.
  2. Reduce the attack surface. Inventory of all publicly reachable systems, a fixed patch schedule with an emergency path for firewalls and VPN gateways, and shutting down services no longer needed.
  3. Segment the network. Workstations, servers, backups, building services and guest Wi-Fi in separate zones, and local administrative rights withdrawn.
  4. Keep backups separated and immutable. The Brandenburg case with the 100,000-dollar demand was resolved without payment because the restore worked.
  5. Build detection and an emergency plan. Monitoring for unusual data volumes and login times, an emergency plan with contact list, decision paths and reporting obligations. The police’s central cybercrime contact point is available to companies in both states.
  6. Involve staff and suppliers. Short, regular training with a simple reporting channel; for service providers, written security requirements, deletion deadlines and reporting obligations.

Key points

  • Around 80 per cent of reported attacks hit SMEs, and only 67 per cent of companies can still reliably detect an attack.
  • The documented cases from Berlin and Brandenburg began with credentials without a second factor, phishing or open remote access, and escalated in unsegmented networks.
  • Multi-factor authentication, a patch schedule, segmentation and separated backups decide both the likelihood and the damage of an attack.

How DEVACON supports companies, hospitals and public authorities in Berlin and Brandenburg with assessment, segmentation, multi-factor authentication and emergency planning is described on the page Cybersecurity.

Sources

  • German Federal Office for Information Security (BSI): The State of IT Security in Germany 2025, reporting period 1 July 2024 to 30 June 2025, bsi.bund.de/lagebericht
  • Federal Criminal Police Office (BKA): Bundeslagebild Cybercrime 2025, press release of 12 May 2026, bka.de
  • Bitkom: Wirtschaftsschutz 2026, study report, bitkom.org; summary at Security-Insider, 2 September 2026, security-insider.de
  • Brandenburg State Criminal Police Office: Lagebild Cybercrime im Land Brandenburg 2024, published October 2025, polizei.brandenburg.de
  • Berlin Senate Chancellery: Current situation after the ICT incident in the Berlin state network, press release of 3 September 2026, berlin.de
  • State of Berlin: Cyber attack on the state network, information for citizens, berlin.de/cyberangriff
  • heise online: Cyberattacke auf Berlin könnte größere Folgen haben als bisher gedacht, 6 September 2026, heise.de
  • Security-Insider: Berlin-Hack 2026: Ransomware, Datenabfluss und KRITIS-Lücke, 18 September 2026, security-insider.de
  • G DATA: Kammergericht Berlin, final report on the Emotet infection, January 2020, gdata.de

Topics Ransomware Phishing Network Berlin

This article comes from the DEVACON blog and was editorially revised for the new website.