Kidnapping a Library: How Ransomware Taught the British Library to Follow Well-Known Best Practices

Brian Myers (Independent Contractor)

BSidesSF 2026 · Day 2 · AMC IMAX

Overview

In this compelling talk at BSides SF, independent information security contractor Brian Myers dissects the catastrophic ransomware attack that crippled the British Library in October 2023. Drawing primarily from the library's remarkably candid 18-page public report, Myers offers a detailed narrative of the incident, its profound consequences, and the critical lessons learned. The presentation serves not only as a technical post-mortem but also as a powerful cautionary tale, illustrating how even a major cultural institution with a degree of security awareness can be brought to its knees by fundamental security oversights and the complexities of managing legacy IT infrastructure.

Watch on YouTube

Visual summary for Kidnapping a Library: How Ransomware Taught the British Library to Follow Well-Known Best Practices by Brian Myers
Visual summary for Kidnapping a Library: How Ransomware Taught the British Library to Follow Well-Known Best Practices by Brian Myers

Key moments

  1. 0:00 Introduction to the British Library attack and talk agenda
  2. 2:00 Why the British Library's attack report is significant
  3. 4:00 Exploring the British Library's immense scale and operations
  4. 6:00 How historical growth complicated British Library's IT systems
  5. 6:40 Overview of British Library's public-facing digital infrastructure

Kidnapping a Library: How Ransomware Taught the British Library to Follow Well-Known Best Practices

Speakers: Brian Myers, Independent Contractor, Information Security

Conference: BSides SF

YouTube: https://www.youtube.com/watch?v=2B3NbFmOLrE

Overview

In this compelling talk at BSides SF, independent information security contractor Brian Myers dissects the catastrophic ransomware attack that crippled the British Library in October 2023. Drawing primarily from the library's remarkably candid 18-page public report, Myers offers a detailed narrative of the incident, its profound consequences, and the critical lessons learned. The presentation serves not only as a technical post-mortem but also as a powerful cautionary tale, illustrating how even a major cultural institution with a degree of security awareness can be brought to its knees by fundamental security oversights and the complexities of managing legacy IT infrastructure.

The talk highlights the Receita ransomware group's modus operandi, the British Library's vulnerabilities, and the arduous, multi-year recovery process that ensued. Myers emphasizes the importance of this story as a valuable addition to any security professional's repertoire, providing vivid examples to underscore the necessity of adhering to well-established best practices. The British Library's unprecedented transparency in reporting the incident, despite its devastating impact, is also praised as a model for corporate communications during a crisis, ultimately helping them avoid regulatory fines.

This incident is a stark reminder that the cost of neglecting foundational security controls and the challenges of legacy system management can far outweigh the perceived "practicality, cost, and impact" of their implementation. The British Library's journey from paralysis to a projected 18-month, multi-million-pound rebuild offers invaluable insights for organizations grappling with similar IT complexities and the ever-present threat of sophisticated cyberattacks.

Background

▶ Watch: Introduction to the British Library attack and talk agenda (0:00)

The British Library is not merely a repository of books; it stands as the National Library of the United Kingdom and one of the world's premier cultural institutions. Its vast collection encompasses everything from the Magna Carta and handwritten Beatles lyrics to the earliest manuscript of Beowulf, alongside extensive digital archives, patents, postage stamps, and sound recordings. With over 200 miles of books and a collection that grows at six miles per year, managing its physical and digital assets requires immense infrastructure, including temperature-controlled archival warehouses in Yorkshire, where automated systems retrieve materials for readers in London. Beyond its core archival function, the library operates public-facing services such as cafes, online bookstores, popular exhibits (like the Harry Potter exhibit, which drew nearly a million visitors), and educational programs.

The library's IT infrastructure reflects its organic growth over decades. Formed in the 1970s from the British Museum's collection, it has since acquired numerous other collections, each with its own disparate information systems, goals, and operational methodologies. This accretion of diverse systems under a single aegis has resulted in a complex and often fragmented IT landscape. The information systems identified in the report include a rich public-facing website for reader accounts and digital archive access, on-site point-of-sale (POS) systems, standard corporate business systems (HR, payroll, firewalls), and a core network managing digital archives and online catalogs.

Prior to the attack, the British Library was not entirely devoid of security measures. They had implemented Multi-Factor Authentication (MFA) across parts of their system, utilized Mobile Device Management (MDM), and conducted risk assessments, indicating a degree of maturity in their information security program. They had also achieved Cyber Essentials certification annually since 2019. However, this certification, a UK government-defined baseline of five technical controls aimed at preventing common internet-borne attacks, is not a comprehensive framework like ISO 27001 or NIST 800-53. Crucially, the library discovered in 2022 that its legacy systems could no longer meet even this minimal bar, leading them to cease re-certifying. This pre-existing vulnerability, coupled with the inherent complexity of integrating disparate, aging systems, created fertile ground for the subsequent catastrophic attack. The problem of legacy systems, with their outdated software, unsupported databases, and custom drivers, meant that critical components of the library's infrastructure were inherently difficult to secure and, as events would prove, almost impossible to recover.

Key Findings

▶ Watch: Why the British Library's attack report is significant (2:00)

The October 2023 attack on the British Library was orchestrated by Receita, a well-known ransomware group that has been active for years, with advisories issued by CISA in 2023 and updated in 2025. Receita is characterized by its "living off the land" approach, avoiding complex zero-day exploits in favor of easier routes to compromise.

The initial compromise, though not fully detailed forensically, was consistent with Receita's standard operating procedure: gaining access through compromised legitimate credentials. In this instance, the attackers logged in via Terminal Services. A critical vulnerability was the specific exception made for the British Library domain itself, which did not enforce MFA. This decision was made due to "practicality, cost, and impact on ongoing programs," despite the library being aware of the risk, albeit "the consequences were perhaps underappreciated."

The attack timeline unfolded rapidly:

  • October 25th: The first verified log entry showed an attacker accessing library systems.
  • October 26th (1:00 AM): An alarm was triggered by attacker activity, waking an IT staff member. This individual investigated but found "nothing devious" as legitimate credentials were used. The account was disabled, and a note was left for the morning crew.
  • Morning Crew: After further investigation, the morning crew re-enabled the account with a new password, again seeing "nothing bad."
  • Following Days: The attackers remained active, conducting reconnaissance using existing system tools (e.g., grep for keywords like "confidential" and "passport") to identify valuable files and expand their access.
  • Saturday Morning (1:30 AM): 440 gigabytes of data were exfiltrated from the network. Shortly thereafter, the ransomware was deployed, encrypting files and some backups.

Upon discovery, the library declared an incident, and its incident response team rapidly convened using WhatsApp—a crucial out-of-band communication channel identified in their plan, given that all internal systems were down. The immediate impact was devastating: the library was "blind and paralyzed." Readers could not register online, the online catalog was inaccessible, book requests ceased, digital assets were unavailable, deliveries from Yorkshire were interrupted, environmental monitoring in warehouses was offline, and phone lines were down.

The forensic investigation revealed that the stolen data included files from finance, technology, and HR departments. This encompassed Personally Identifiable Information (PII) such as contact information for staff, partners, and customers, as well as some personal files belonging to staff members. Beyond data encryption, the attackers aggressively deleted logs and partitions, effectively "destroying" servers. This destruction, particularly of legacy systems with outdated databases and custom drivers, rendered significant portions of the library's infrastructure unrecoverable, leaving them with data but "nowhere to put it." The report explicitly states, "The destruction of servers had the most damaging impact on the library."

The Receita group demanded a ransom, but the British Library, adhering to UK government policy for publicly funded organizations, did not pay. In an attempt to force payment, Receita auctioned 10% of the stolen data on the dark web several weeks later. When this failed, they retaliated by dumping all the stolen data online.

The recovery process has been protracted and costly:

  • Immediately Post-Attack: The library opened in a "pre-digital state," operating on paper only. All corporate desktop and laptop devices were repossessed and reimaged.
  • November 15th (2 weeks post-attack): A public statement was issued, acknowledging the ransomware attack and data theft, but noting the full extent of damage was still being assessed.
  • January (3 months post-attack): Some online catalog access was restored.
  • March (5 months post-attack): Approximately half of the online catalog was restored. The library's public report outlined a three-phase recovery plan: Phase 1 (short-term restoration of minimal functions) was complete; Phase 2 (adapting to the new state, restoring recoverable elements) was ongoing; and Phase 3 (a complete rebuild of infrastructure in the cloud with consistent security) was projected to take 18 months, ending in mid-2025, with an estimated cost of 40% of their cash reserves.
  • Indirect Costs: Payments to authors, typically made when books are checked out, were interrupted, impacting individuals reliant on these small but significant sums.
  • August 2024 (10 months post-attack): Reports indicated the library was hiring contractors for its security rebuild, suggesting potential delays to the 18-month projection.
  • April 2025 (over a year post-attack): The Information Commissioner's Office (ICO), the UK's GDPR regulator, concluded its investigation, commending the British Library for its transparency and imposing no fine.
  • November 2025 (2 years post-attack): The library was still explaining service availability to users on its website.
  • March 2026 (2.5 years post-attack): A link to information about the cyberattack remained prominently on the library's homepage, underscoring the ongoing impact and recovery efforts.

The library identified the root causes as the impracticality of properly isolating network segments due to manual legacy data operations, leading to extensive attacker access, and the destruction of unrecoverable servers.

Technical Deep Dive

▶ Watch: Exploring the British Library's immense scale and operations (4:00)

The Receita ransomware group employed a sophisticated yet common attack methodology, often termed "living off the land," which leverages existing system tools and legitimate credentials to achieve its objectives. Their standard operating procedure, as described by CISA and corroborated by the British Library incident, typically involves:

  1. Initial Access: Receita eschews complex, custom exploits for initial entry. Instead, they prioritize compromising legitimate user credentials, often belonging to vendors or contractors with elevated network access. In this case, the entry point was identified as Terminal Services. The critical technical vulnerability here was the absence of Multi-Factor Authentication (MFA) on the British Library's internal domain, despite MFA being implemented elsewhere. This single point of failure allowed the attackers to bypass a fundamental security control with just a stolen username and password, which could have been obtained via phishing or purchased on the dark web. The library's internal risk register noted this gap, but the "consequences were perhaps underappreciated" – a crucial insight into the disconnect between identified risks and their perceived impact.
  1. Persistence and Lateral Movement: Once inside, Receita did not immediately deploy custom malware. Instead, they utilized tools already present within the operating system to explore the network, escalate privileges, and identify valuable data. The transcript mentions the use of grep (or similar search utilities) to scan files for keywords like "confidential" and "passport," indicating a methodical reconnaissance phase aimed at identifying sensitive data for exfiltration. This "living off the land" approach makes detection more challenging, as attacker activity can blend with legitimate system processes.
  1. Data Exfiltration (Double Extortion): Before deploying the encryption payload, Receita executed a double extortion strategy. This involved staging and exfiltrating data to their own command-and-control servers. In the British Library's case, 440 gigabytes of sensitive data—including financial records, HR information, and Personally Identifiable Information (PII) of staff, partners, and customers, as well as personal staff files—were siphoned off the network. This exfiltration occurred in the early hours of a Saturday morning, a common tactic to minimize detection.
  1. Encryption and System Destruction: Following data exfiltration, the ransomware payload was deployed, encrypting files across the network and impacting some backups. However, a more profound and ultimately more damaging aspect of the attack was the aggressive destruction of servers. The attackers achieved this not through physical damage, but by "aggressively deleting logs and partitions." This rendered significant portions of the library's infrastructure, particularly older, legacy systems, unrecoverable. The historical growth of the library through the acquisition of various collections meant a heterogeneous IT environment with potentially outdated operating systems, unsupported databases, and custom device drivers. These older systems, already difficult to patch and maintain, were particularly susceptible to this type of destructive attack, leading to a situation where the library had recovered data but lacked the necessary infrastructure to restore it.

The "huge blast radius" of the attack, which brought down almost all core library functions (cataloging, circulation, inter-library loan, acquisitions), was a direct consequence of inadequate network segmentation. Once the attackers gained a foothold, the flat network architecture allowed them largely unfettered access across different segments. In contrast, cloud-based SaaS applications for email and finance, which were presumably hosted externally and inherently better isolated, recovered much faster, highlighting the benefits of a segmented, cloud-native approach for critical business functions. The inability to recover legacy servers meant that rebuilding the core library management systems required a complete architectural overhaul, rather than a simple restoration, escalating the recovery timeline and costs dramatically.

Demo / Proof of Concept

▶ Watch: How historical growth complicated British Library's IT systems (6:00)

The talk did not feature a live technical demonstration or a proof of concept specific to the British Library's compromised systems. Instead, the speaker utilized generic screenshots of a Receita ransomware attack, including an example of an encrypted file directory and a typical ransom note from a different victim, to illustrate the visual impact and immediate experience of such an incident. This served to convey the reality of a ransomware attack without delving into a live, interactive technical demonstration.

Defensive Implications

▶ Watch: Overview of British Library's public-facing digital infrastructure (6:40)

The British Library's ordeal offers a wealth of critical defensive implications for organizations across all sectors, particularly those grappling with legacy systems and complex IT environments:

  • Mandatory Multi-Factor Authentication (MFA): The most glaring vulnerability exploited was the lack of MFA on Terminal Services for the British Library's primary domain. This allowed attackers to gain initial access with compromised credentials. The lesson is clear: MFA must be universally enforced, especially for remote access, administrative accounts, and critical systems. Exceptions based on "practicality, cost, and impact" are high-risk decisions that can lead to catastrophic consequences far exceeding the perceived initial overhead.
  • Robust Network Segmentation: The "huge blast radius" of the attack underscored the failure of adequate network segmentation. Once inside, attackers could move laterally with ease, impacting nearly all systems. Organizations must implement granular network segmentation, isolating critical assets, legacy systems, and different functional areas to contain breaches and limit the scope of an attack. This is particularly challenging but essential for environments with acquired, disparate systems.
  • Proactive System Lifecycle Management: The destruction of unrecoverable legacy servers highlights the danger of outdated infrastructure. Organizations need a structured approach to system lifecycle management, including planned upgrades, migrations, and decommissioning of unsupported hardware and software. This involves regular inventory, vulnerability assessments, and budgeting for timely replacements to avoid accumulating technical debt that becomes an insurmountable recovery challenge.
  • Comprehensive Resilience and Recovery Planning: Recovery plans must extend beyond data restoration to include infrastructure rebuilds. Organizations must test their ability to recover not just data, but entire server environments, especially for legacy systems. This includes ensuring immutable backups that are air-gapped or logically separated from the production network, and validating restoration processes regularly. The British Library's discovery that they had data but "nowhere to put it" is a powerful testament to this need.
  • Enhanced Incident Response (IR) Capabilities: The library's IR plan was commendable for identifying out-of-band communication (WhatsApp) when all internal systems failed. However, the prolonged nature of the crisis (extending over two years) also revealed the necessity for IR plans to include provisions for staff well-being and sustained support during extended periods of high stress.
  • Effective Risk Communication and Governance: There was a clear disconnect between the security team's awareness of risks (e.g., lack of MFA on Terminal Services) and the executive understanding of the potential impact. Security teams must improve their ability to articulate risks in business terms, translating technical vulnerabilities into tangible operational and financial consequences. Simultaneously, executive leadership needs to foster a culture where identified risks are fully understood and appropriately prioritized, moving beyond mere "risk register" entries. Stronger, embedded governance structures are essential to drive security initiatives throughout the organization.
  • Review of Acceptable Use Policies and Data Governance: The exfiltration of personal staff files, explicitly allowed in designated areas of the library's IT systems, highlights a critical data governance issue. Organizations must review and strictly enforce acceptable use policies for IT resources, clearly defining what types of data (especially personal PII) can be stored on company systems. This minimizes the scope of sensitive data exposed in a breach.
  • Active Threat Intelligence and Peer Collaboration: Receita was a well-known threat, with CISA advisories issued. Organizations should actively consume threat intelligence and, as the British Library itself noted, "collaborate with sector peers." Sharing information about threats, vulnerabilities, and successful defenses can significantly enhance a collective security posture.
  • Beware of Recovery Shortcuts: The British Library's foresight in identifying the risk of "wishful thinking" leading to "shortcuts" during the 18-month rebuild is crucial. Intense pressure to restore normalcy quickly can compromise long-term security. Organizations must maintain a disciplined approach to rebuilding securely, even if it means extending recovery timelines.
  • Evolving Risk Profiles Post-Attack: A public, high-profile attack can change an organization's threat landscape. The library recognized that while ransomware groups might be less motivated if no ransom was paid, other threat actors seeking to cause chaos or reputational damage might become more interested. Continuous reassessment of the threat model is vital.

Key Takeaways

  • MFA is Non-Negotiable: The absence of Multi-Factor Authentication (MFA) on critical access points, even due to perceived "practicality" or cost, creates an unacceptable risk that can lead to catastrophic compromise. Universal MFA implementation is fundamental.
  • Legacy Systems are a Critical Liability: Outdated and unmanaged legacy IT infrastructure poses significant security vulnerabilities and can render entire systems unrecoverable after a destructive attack, leading to prolonged and costly rebuilds.
  • Network Segmentation is Paramount: Inadequate network segmentation allows attackers to move freely across an environment, turning a localized breach into a widespread operational paralysis. Robust segmentation is essential to contain and limit the blast radius of attacks.
  • Ransomware Means More Than Encryption: Modern ransomware attacks often involve double extortion (data theft) and can include aggressive server destruction (deleting logs, partitions), making infrastructure recovery as challenging as data restoration.
  • Transparency Mitigates Fallout: The British Library's candid and detailed public report, despite the severity of the incident, earned public trust and helped them avoid regulatory fines from the ICO, demonstrating the value of transparent crisis communication.
  • Risk Communication Needs Improvement: A clear disconnect between security teams identifying risks and executives understanding the true business impact (e.g., 40% of cash reserves, 18-month recovery) highlights the need for better risk articulation and stronger, embedded governance structures.

About the Speaker(s)

Brian Myers began his professional career in software development, a field he pursued for a considerable period before transitioning into management. Approximately ten years ago, he "escaped" from management into information security, where he has found his professional home and happiness ever since. Currently, Brian Myers operates as an independent contractor, specializing in assisting companies with the establishment and ongoing operation of effective and comprehensive information security programs. He is passionate about sharing lessons learned from real-world incidents to help organizations strengthen their security posture.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Competent case study walk-through of the British Library ransomware incident, leaning almost entirely on the library's own public post-mortem report. Myers is an effective narrator and the source material is genuinely good — the library's transparency produced one of the more honest breach disclosures in recent memory — but the talk doesn't add much analytical layer on top of it. Useful for practitioners who haven't read the report; redundant for those who have.

Heather Calloway (CISO) — SOLID

A competent, well-structured case study of the British Library breach that earns its place in any security awareness rotation. The incident itself is genuinely instructive, and Myers benefits from a remarkably candid source document — but the talk delivers the case without materially advancing what a senior practitioner should take from it.

→ Top-rated talks at BSidesSF 2026

All talks from BSidesSF 2026