In August 2026, the city administration of Berlin was hit by a serious cyberattack. The ransomware group Rhysida broke into the network of the Berlin Senate and stole a huge amount of data — reportedly close to 1.44 million files. Two departments, responsible for housing and transport, were cut off from the network for days. Housing benefit payments could not be processed. Employees could not access email or the internet. Weeks later, Berlin’s mayor confirmed that the city was being blackmailed. The attackers demanded around 30 bitcoin, worth roughly two million euros, in exchange for not publishing the stolen data. Berlin refused to pay.
This is not a story about a small, careless organization. Berlin is the capital of Germany, with a large budget, a professional IT department, and constant political attention on security. And yet the attackers got in.
If you run a small or mid-sized business, this story is worth your attention — not because you will suffer the exact same attack, but because it destroys a very common and very dangerous assumption: the belief that your company is too small, too boring, or too unknown to be a target.
Attackers Don’t Choose Targets the Way You Think
Many business owners picture cybercriminals as people who study a target for weeks, decide it’s worth the effort, and then attack. In reality, most attacks work the opposite way. Criminal groups run automated tools that scan huge ranges of the internet around the clock, checking millions of addresses for the same handful of weak points: outdated software, exposed login pages, weak or reused passwords, unpatched systems, misconfigured servers. This scanning doesn’t stop for weekends or holidays, and it doesn’t care whether the address it just checked belongs to a government network or a five-person accounting office. When the scan finds a weak point, it gets logged, and either the same tool or a human operator moves in to exploit it. The size of the company behind that weak point rarely matters at this stage. What matters is that the door was left open.
This is also why timing often has nothing to do with your business at all. A company can go years without trouble and then get hit the week after a new software vulnerability becomes public, simply because attackers rushed to scan for that specific weakness before it got patched everywhere. You didn’t do anything to attract attention. Your system just happened to still have the old version installed when the scan came through.
Ransomware groups like Rhysida also don’t need your business to be famous. They need your data to be valuable to someone — to you, to your customers, or to your suppliers. A small accounting firm holds tax records. A small clinic holds medical files. A small logistics company holds contracts and payment details. A local retailer holds customer names, addresses, and payment information. None of this needs to be exciting or high-profile to be useful. It only needs to be something you would rather not have leaked, stolen, or locked away — because that’s exactly what gives an attacker leverage over you. All of this has value, and all of this can be turned into leverage once it’s stolen. The city of Berlin was not attacked because it was uniquely interesting. It was attacked because somewhere in its systems, there was a vulnerability that could be exploited, and once the attackers were inside, the value of the data did the rest of the work for them.
The “We’re Too Small to Matter” Myth
I hear a version of this sentence often from smaller business owners: “We’re not a bank, we’re not a government, nobody wants our data.” It’s an understandable thought, but it doesn’t match how modern cybercrime actually works.
First, smaller companies are frequently used as a way to reach bigger ones. If your business supplies parts, services, or software to a larger client, your systems may be the easiest way into theirs. Attackers know that big companies invest heavily in security, while smaller partners in their supply chain often don’t. Targeting you can be the quickest path to a much bigger prize. This is sometimes called a supply chain attack, and it’s one of the fastest-growing ways companies get breached, because it lets attackers skip the well-defended front door of a large company and walk in through a much weaker side entrance instead. If you handle invoices, logins, deliveries, or shared systems with a bigger partner, that relationship itself can be what makes you interesting to an attacker, regardless of your own size.
Second, ransomware is largely automated. Criminal groups don’t need to manually decide that your company is worth attacking. Once a vulnerability is found by their scanning tools, the attack often proceeds without much human involvement at all, sometimes moving from first access to full encryption of your systems within hours. Your revenue, your industry, and your public profile are irrelevant to a script looking for an unpatched server. Some ransomware operations even work on a franchise model, where the people who write the malware rent it out to other criminals who run the actual attacks. That means there can be dozens of independent groups running scans at once, all looking for the same kind of easy opening, which multiplies the odds that a small business will eventually be found.
Third, recovery costs hit small businesses disproportionately hard. A large city administration like Berlin has the resources, staff, and political backing to manage weeks of disruption, keep paying employees, and rebuild systems from backups while investigations continue in the background. Many smaller companies do not have that cushion. A single week without access to email, invoicing, or customer records can mean missed deadlines, canceled orders, and clients who quietly move to a competitor. Downtime, lost customer trust, and ransom demands can be enough to permanently damage — or end — a small business, especially one that had no cyber insurance and no tested recovery plan in place before the attack happened.
What This Means for Your Business
The Berlin case is a useful reminder of a few basic truths that are easy to forget in daily business life. Software needs to be updated regularly, not eventually. Every update you postpone is a known weak point sitting in your systems, and known weak points are exactly what automated scanners are built to find. Backups need to exist outside your main network, ideally offline or in a separate system entirely, so that a ransomware attack can’t encrypt them along with everything else. A backup that sits on the same network as the data it’s meant to protect isn’t much of a safety net once an attacker is already inside.
Access to sensitive systems should be limited to the people who genuinely need it, and protected with strong authentication, not just a password. Multi-factor authentication, where a login also requires a code from a phone or an app, blocks a large share of attacks even when a password has already been stolen or guessed. It’s one of the cheapest security improvements available, and one of the most effective. And employees need to know what a phishing attempt looks like, because human error remains one of the easiest ways in. A single click on the wrong link, from someone who has never been shown what a fake invoice email or a fake login page tends to look like, can undo every other precaution you’ve put in place. This doesn’t need to be a formal training program; even a short, regular reminder of what to watch for makes a measurable difference.
None of this requires a government-sized budget. It requires treating cybersecurity as a normal part of running a business, in the same way you would treat fire safety or financial bookkeeping — something with a routine, a responsible person, and a regular check-in, not something you deal with only after something has already gone wrong. Berlin had far more resources than most small businesses ever will, and it still took weeks to get email and internet access back for two departments. That gap between “we have some security in place” and “we actually tested whether it works” is where most small businesses get caught out.
The Real Lesson From Berlin
The attack on Berlin’s administration shows that size and importance offer no real protection. A well-funded, well-staffed public authority was still breached, still had data stolen, and is still dealing with the consequences of extortion. If an organization with those resources can be caught out, the idea that a small or mid-sized company is “not interesting enough” to be targeted simply doesn’t hold up.
Cybercriminals are not looking for famous victims. They are looking for open doors. The question worth asking is not “why would anyone target us?” but “where are our doors still open?”
If you’re unsure where your business stands, that’s exactly the kind of question I help companies answer. Reach out, and I’ll take a look at your current setup with you, before an attacker does it for you.
Conclusion: Why Small Businesses Are Targeted by Cyberattacks
The attack on Berlin’s administration shows that size and importance offer no real protection. A well-funded, well-staffed public authority was still breached, still had data stolen, and is still dealing with the consequences of extortion. If an organization with those resources can be caught out, the idea that a small or mid-sized company is “not interesting enough” to be targeted simply doesn’t hold up.
So why are small businesses targeted by cyberattacks in the first place? The honest answer is that most attackers don’t target small businesses on purpose — they target weak points, and small businesses tend to have more of them. Limited IT budgets, outdated software, and no dedicated security staff make smaller companies easier to break into than large ones, even though they hold less obvious value. On top of that, small businesses are often the easiest way for attackers to reach a bigger client further down the supply chain, which makes them a target by association, not by choice. And because ransomware attacks are largely automated, no human ever needs to decide your company is “worth it.” A script finds the open door and walks through it.
This is the real reason small businesses are targeted by cyberattacks so often: not because criminals see something special in them, but because criminals see something missing — the basic protections that make an attack too costly or too difficult to bother with. Cybercriminals are not looking for famous victims. They are looking for open doors. The question worth asking is not “why would anyone target us?” but “where are our doors still open?”
If you’re unsure where your business stands, that’s exactly the kind of question I help companies answer. Reach out, and I’ll take a look at your current setup with you, before an attacker does it for you.
I also recommend you to read:





