How ransomware took down the British Library: one remote server without MFA
One of the largest libraries in the world was knocked offline for months, and its own review traced the most likely way in to a single remote access server that asked for a password and nothing more.[1] This case file covers what happened in October 2023, how the attackers probably got in, what it cost, and the one control that would have made the door much harder to open.
What happened
Early on Saturday, October 28, 2023, a member of the British Library's technology team found they could not get into the network. By mid-morning the library had activated its crisis response.[1] Forensic work later showed the intruders had been inside for at least 3 days. On the night of October 25 the library's monitoring flagged and blocked suspicious activity, and a security manager ran scans and reset a password, without realizing an attacker was already exploring the network.[1]
At about 1:30 a.m. on October 28, roughly 600GB of files, about half a million documents, were copied out of the library. The attackers then encrypted and destroyed large parts of the server estate to slow down any recovery.[1] The ransomware gang Rhysida claimed the attack and demanded 20 bitcoin, then worth about £596,000.[2]
The library did not pay or talk to the attackers.[1] The stolen files were put up for auction, and on November 27 the gang published about 600GB of material, said to be around 90% of what it took, including staff records and scanned passports.[1][2] The library's main catalogue did not return until January 15, 2024, and then only as a searchable, read-only version.[1][2]
How they got in
In March 2024 the library published an unusually frank review of the attack. It said the most likely point of entry was a terminal services server, a machine that lets people log in to the network remotely, installed in February 2020 so trusted outside partners and IT administrators could reach internal systems.[1]
The library had used multi-factor authentication (MFA), a second check such as a code on a phone, for its cloud applications since 2020. But that protection did not extend to logins on this server.[1] The review concluded that the most likely cause was stolen credentials for a privileged account, possibly obtained through phishing, which were then used to log in as a legitimate user.[1] With a working password alone, the attackers were in.
Once inside, they went looking for valuable data. The review says they copied whole folders from the finance, technology and human resources teams, searched for files with sensitive words in their names, and forced backups of 22 databases holding customer contact details.[1]
What it cost
The copying was bad. The destruction was worse. The library had secure backups of its digital collections, but so many servers were wrecked that there was nothing ready to restore them onto.[1] Its review described a technology estate that was unusually complex and full of older systems that could not simply be switched back on.[1]
Early estimates put the cost of recovery at up to about £7 million, a large share of the library's financial reserves.[2][3] The library has said the final figure is still being worked out and that it did not ask the government for extra money.[1] Services took far longer than the catalogue to come back, and some online collections were still limited well into 2025.[2] The UK data protection regulator later decided to take no further action against the library.[4]
The missing control
The missing control: multi-factor authentication on every remote access route, including the one built for outside partners. The library had MFA in place elsewhere, but the server that let third parties and administrators in from outside was protected by a password alone.[1]
A stolen password is a common, cheap starting point for ransomware gangs. A second factor turns that password into half a key. If logins on that server had needed a code or approval from a device the real user held, the credentials the attackers most likely obtained would not have been enough on their own. The library's own list of lessons puts MFA everywhere near the top.[1]
What to do in your business
- List every way in from outside. Write down each remote desktop, VPN, vendor portal and remote support tool that can reach your systems, including ones set up years ago for one supplier.
- Turn on MFA for all of them. Make a second factor mandatory on every remote login, not just email and cloud apps, and start with admin and vendor accounts.
- Close what nobody uses. Switch off remote access that was set up for a past project or former partner, and review the list every quarter.
- Keep backups you can actually restore. Store copies offline or in a separate account, and test restoring one system onto fresh equipment so you know how long it takes.
- Act on alerts in full. When your security tools block something odd, treat it as a possible intruder and check which account was involved, rather than only resetting a password.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: Employee offboarding checklist: how to cut off a former employee's access the same day
- Guide: How to verify callers before password resets, and protect your phone number from SIM swaps
- Guide: Which two-step login actually stops phishing, and how a small office rolls it out
- How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- How the 2020 Twitter hack happened: a fake help desk call and an admin tool
- How the Mirai botnet knocked Twitter and Netflix offline with factory passwords
- How the Ronin bridge was hacked: a fake job offer and $600 million
- How Uber got hacked in 2022: a stolen password and one tired tap
- Every identity and access control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.