Case file · BRITISH LIBRARY 2023

How ransomware took down the British Library: one remote server without MFA

Published 2026-09-29 · 4 min read · Missing control: MFA on all third-party remote access

One of the largest libraries in the world was knocked offline for months, and its own review traced the most likely way in to a single remote access server that asked for a password and nothing more.[1] This case file covers what happened in October 2023, how the attackers probably got in, what it cost, and the one control that would have made the door much harder to open.

What happened

Early on Saturday, October 28, 2023, a member of the British Library's technology team found they could not get into the network. By mid-morning the library had activated its crisis response.[1] Forensic work later showed the intruders had been inside for at least 3 days. On the night of October 25 the library's monitoring flagged and blocked suspicious activity, and a security manager ran scans and reset a password, without realizing an attacker was already exploring the network.[1]

At about 1:30 a.m. on October 28, roughly 600GB of files, about half a million documents, were copied out of the library. The attackers then encrypted and destroyed large parts of the server estate to slow down any recovery.[1] The ransomware gang Rhysida claimed the attack and demanded 20 bitcoin, then worth about £596,000.[2]

The library did not pay or talk to the attackers.[1] The stolen files were put up for auction, and on November 27 the gang published about 600GB of material, said to be around 90% of what it took, including staff records and scanned passports.[1][2] The library's main catalogue did not return until January 15, 2024, and then only as a searchable, read-only version.[1][2]

How they got in

In March 2024 the library published an unusually frank review of the attack. It said the most likely point of entry was a terminal services server, a machine that lets people log in to the network remotely, installed in February 2020 so trusted outside partners and IT administrators could reach internal systems.[1]

The library had used multi-factor authentication (MFA), a second check such as a code on a phone, for its cloud applications since 2020. But that protection did not extend to logins on this server.[1] The review concluded that the most likely cause was stolen credentials for a privileged account, possibly obtained through phishing, which were then used to log in as a legitimate user.[1] With a working password alone, the attackers were in.

Once inside, they went looking for valuable data. The review says they copied whole folders from the finance, technology and human resources teams, searched for files with sensitive words in their names, and forced backups of 22 databases holding customer contact details.[1]

What it cost

The copying was bad. The destruction was worse. The library had secure backups of its digital collections, but so many servers were wrecked that there was nothing ready to restore them onto.[1] Its review described a technology estate that was unusually complex and full of older systems that could not simply be switched back on.[1]

Early estimates put the cost of recovery at up to about £7 million, a large share of the library's financial reserves.[2][3] The library has said the final figure is still being worked out and that it did not ask the government for extra money.[1] Services took far longer than the catalogue to come back, and some online collections were still limited well into 2025.[2] The UK data protection regulator later decided to take no further action against the library.[4]

The missing control

The missing control: multi-factor authentication on every remote access route, including the one built for outside partners. The library had MFA in place elsewhere, but the server that let third parties and administrators in from outside was protected by a password alone.[1]

A stolen password is a common, cheap starting point for ransomware gangs. A second factor turns that password into half a key. If logins on that server had needed a code or approval from a device the real user held, the credentials the attackers most likely obtained would not have been enough on their own. The library's own list of lessons puts MFA everywhere near the top.[1]

What to do in your business

Watch the case
How ransomware took down the British Library for monthsDrops 2027-01-08
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More identity and access cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. British Library: Learning lessons from the cyber-attack, cyber incident review (8 March 2024)
  2. Wikipedia: British Library cyberattack
  3. Computer Weekly: British Library ransomware attack could cost up to £7m
  4. Infosecurity Magazine: ICO takes no further action on British Library ransomware breach