Breach 060 / 076

British Library Ransomware Attack October 2023

In October 2023, the British Library was targeted by the Rhysida ransomware group, resulting in the encryption and leak of approximately 490,191 files, amounting to 573 GB of data. The breach illustrated vulnerabilities in security protocols due to compromised credentials and the absence of Multi-Factor Authentication (MFA), significantly disrupting library operations and potentially exposing sensitive internal data.
Sector
Education & Culture
Year

Executive Summary

The British Library experienced a ransomware attack carried out by the Rhysida ransomware group in 2023. This cyber incident was identified on October 28, 2023. Public announcements regarding ongoing technology outages followed on November 17, 2023. The attack demonstrated vulnerabilities within the library’s IT infrastructure, resulting in significant disruptions due to data encryption.

Severity of the Impact

The ransomware attack severely affected services, disrupting digital and physical operations including public Wi-Fi and possibly internal human resources files. Although the total number of affected records is unspecified, a verified leak of approximately 490,191 files, equating to 573 GB of data, has been reported. 1

Main Threat Actors

The Rhysida ransomware gang, notorious for sophisticated ransomware attacks employing double extortion demands, executed the attack. Their method included not only data encryption but also the threat to auction the stolen data with a starting bid of 20 Bitcoin, indicating a trend toward auction-style ransomware attacks. 12

Primary Direct and Collateral Consequences

Immediate consequences included significant IT service failures, disrupting operations at the British Library. Collateral effects involve reputational risk and diminished trust among users and partners. 2

Threat Vector and Vulnerabilities

The attackers likely compromised privileged account credentials via phishing techniques. Inadequate defenses, such as lacking Multi-Factor Authentication (MFA), allowed the breach, highlighting a critical need for improved cybersecurity measures. 2

Initial Response and Mitigation Strategies

The British Library worked with the UK National Cyber Security Centre (NCSC) and the Metropolitan Police to contain the breach. They guided users on potential risks and are bolstering their cybersecurity strategy to prevent future occurrences, including comprehensive vulnerability assessment and security posture enhancement. 13

Ongoing Recovery and Investigative Efforts

Efforts are underway to restore full operations and ascertain the breach’s full scope. Investigations continue, focusing on understanding the attack dynamics and implementing preventive measures against potential future threats. 32

Incident Overview

Breach Name:

British Library

Breach Date:

Late October 2023

Chronological Sequence of Events:

  • October 28, 2023: The British Library was assaulted by a ransomware attack from the Rhysida group, causing notable IT outages. Affected services included website and system functionalities along with public Wi-Fi, hindering digital collection access. (Ref)

  • November 17, 2023: Acknowledgment of the incident was made with confirmation of technological disruptions affecting services. Notifications were sent to law enforcement and cybersecurity entities. (Ref)

  • November 21, 2023: Responsibility for the attack was claimed by Rhysida, along with threats of double-extortion through data leaks unless ransom demands were satisfied. (Ref)

  • November 29, 2023: Roughly 490,191 files, equating to 573 GB of internal data, were published on Rhysida’s leak site. Detailed data contents remain largely unspecified beyond HR file implications. (Ref)

Actions and Responses by the Organization:

  • Initial Response: Cybersecurity professionals, along with law enforcement, immediately engaged to manage and investigate the breach. Focus was placed on system security and understanding the full breach scope. (Ref)

  • Public Communication: The Library issued regular updates, reaffirming their dedication to resolve service disruptions and the integrity transparency in breach management. (Ref)

  • Preventative Measures: Patrons were advised to update passwords due to potential internal HR data exposure risks. (Ref)

Systems Targeted and Scope of Affected Infrastructure:

  • The attackers targeted the British Library’s online and on-site services, disrupting access tools such as Wi-Fi and digital collections, with specifics on systems or applications remaining unclear. (Ref)

Key Facts and Figures:

  • Data Volume: 573 GB
  • Files Leaked: 490,191
  • Ransom Note Filename: “CriticalBreachDetected.pdf”

Public Statements or Communications:

  • Official declarations confirmed ongoing consultations with authorities for service restoration, emphasizing significant operational impact and detailing service disruptions.
  • Potential legal implications are indicated, focusing on data protection concerning leaked HR data. Specific regulatory actions were not clarified. (Ref)

Information Gaps:

  • Attack Initiation and Resolution Timeline: Timelines remain unspecified.
  • System Details: Particulars on affected systems or servers are not detailed.
  • Regulatory Actions: Details on regulatory responses remain undisclosed.

Technical Root Cause Analysis

The British Library ransomware breach in 2023, orchestrated by the Rhysida group, resulted in substantial technology disarray. The precise tally of affected records remains concealed. (source)

Exploited Vulnerabilities and Weaknesses

Use of Compromised Credentials

  • Credentials Compromise: Intrusion was facilitated by compromised credentials, potentially via credential stuffing or phishing. (source)
  • Access Point Vulnerability: These credentials enabled unauthorized access via institutional VPN points.

Zerologon Vulnerability (CVE-2020-1472)

  • Exploitation Details: The critical Zerologon vulnerability, scoring 10 on the CVSS scale, permitted unauthorized domain controller access, escalating privileges and compromising sensitive systems. (source)

Lack of Multi-Factor Authentication (MFA)

  • Security Lapse: Absence of MFA on terminal servers heightened susceptibility to credential threats. (source)

Attack Chain and Execution

  1. Initial Access: Initial access likely came through compromised credentials targeting critical VPN endpoints. (source)
  2. Privilege Escalation: Exploitation of the Zerologon vulnerability allowed for unauthorized privilege escalation. (source)
  3. Lateral Movement: Using native admin tools, attackers navigated the network stealthily, a technique known as “Living off the Land.” (source)
  4. Ransomware Deployment: Deployment led to data encryption on key systems. (source)
  5. Data Exfiltration and Ransom Demand: Compromised data was auctioned with a demand of 20 BTC on the dark web. (source)

Tools and Techniques

  • Ransomware-as-a-Service (RaaS): Enabled execution without custom malware. (source)
  • Phishing and Social Engineering: Crucial for initial credential harvesting.
  • Indicators of Compromise (IoCs): Identified attacker-associated email: [email protected] . (source)

Design and Architectural Weaknesses

  • Network Segmentation and Security: Lack of internal segmentation led to threat exposure and proliferation.
  • Absence of MFA: Allowed easy exploitation. (source)

Security Controls and Measures That Failed

  • Patch Management Protocols: Delays in patches for Zerologon exposed flaws. (source)
  • Real-Time Monitoring Systems: Delay in breach detection.
  • Access Control Policies: Absent multi-factor authentication noted. (source)

Unmet Industry Standards

  • Deficient Security Controls: Absence of MFA, slow patch management contradicted cybersecurity standards.
  • Incident Response Planning: Inadequate response strategy amplified breach impacts.

Conclusion

The incident accentuates the essential need for strict cybersecurity measures like multi-factor authentication and timely patching to adhere to cybersecurity protocols.

Attack Vector and Methodology

In 2023, the British Library was targeted by the Rhysida ransomware group. Below is an analysis of the attack vector and methodology utilized:

Initial Intrusion Method

The attackers breached the network using compromised credentials for remote services such as VPN and RDP obtained via phishing or lax authentication protocols. (source)

Exploited Vulnerabilities

Rhysida exploited the Zerologon vulnerability (CVE-2020-1472), which manipulates server authentication, bypassing security systems without authenticated access. (source)

Subsequent Strategies and Techniques

Privilege Escalation

Attackers used existing tools and scripts, minimizing detection risk by exploiting built-in features rather than external tools.

Lateral Movement

Although specific techniques weren’t detailed, it’s suspected that lateral movements were executed through internal administrative tools to extend network access.

Persistence

Built-in tools maintained presence on systems, allowing ongoing access without alerts. (source)

Specific Tools and Tactics

Rhysida’s tactics included:

  • Compromised Credentials Usage: Network breaches using phished credentials.
  • Ransomware Deployment: As-a-service model deploying ransomware, demanding ransom. (source)

Indicators of Compromise (IoCs)

Key IoC emails include:

  • rhysidaeverywhere@onionmail[.]org
  • rhysidaofficial@onionmail[.]org

Additional IoCs such as file hashes were not detailed. (source)

Malware Deployed

Primary malware used was Rhysida ransomware, yet specifics on deployment weren’t detailed. The attack led to ransom demands and data exfiltration. (source)

Attack Progression

Chronology of attack includes:

  1. Reconnaissance: Targeting vulnerable VPN/RDP endpoints.
  2. Exploitation: Implementing Zerologon for security protocol circumvention.
  3. Initial Access: Network penetration through phished credentials.
  4. Privilege Escalation and Lateral Movement: Gaining network control.
  5. Data Exfiltration/Ransomware Execution: Resulting in encrypted data theft. (source)

Innovative or Unexpected Methods

Living off-the-land techniques were notable for minimizing detection risk. Ransomware threat evolutions involve auction-style data sales. (source)

Impact Assessment

The ransomware assault on the British Library led to online system disarray alongside on-site service disruptions, including public Wi-Fi, commencing late October 2023. The technological outage resulted from server encryption, affecting core functions of public engagement and research pursuits. Although physical library access remained functional, digital disruptions significantly impacted daily operations. 132

Quantifiable Financial Losses and Compromised Data Types

Financial loss figures are undisclosed but typically encompass recovery, potential ransom payments, legal expenses, and IT upgrades. The ransom demand was 20 BTC. Compromised data involved internal HR files, with no evidence of user data compromise minimizing potential regulatory violations. Approximately 490,191 files, totaling 573 GB, were breached. 3

Potential Long-Term Repercussions

Recovery and investigations may linger for extended periods, adversely affecting services and public trust. Resource diversions affecting other strategic areas remain a concern. Enhanced regulatory oversight and security updates are requisite. 12

Broader Socio-Economic or Industry-Wide Impacts

The attack reflects ongoing cybersecurity challenges within cultural and educational entities similar to the British Library, potentially precipitating broader regulatory considerations and security protocol adjustments. Such incidents underscore a pressing need for advanced security tactics within the public sector. 3

Comparison to Similar Incidents in the Industry

Comparative assessments with previously targeted educational institutions reveal similar disruption patterns necessitating cybersecurity enhancements. The inclusion of double extortion tactics by Rhysida parallels industry-wide vulnerabilities. 1

Assessment of Potential Reputational Damage to the Affected Organization

The British Library’s role as a prominent educational institution predisposes it to significant reputational damage. Patrons might reconsider affiliations based on security reliability. Evidence of further data breaches could worsen reputational impacts. 13

Data Gaps

Specific financial losses and comprehensive recovery protocols remain unspecified. Detailed insights into recovery activities and long-term cybersecurity outlooks post-breach are lacking. 2

Recommendations and Prevention

This ransomware attack on the British Library underscores significant cybersecurity exposures needing remediation for future incident prevention. Core recommendations focus on strengthening overall cybersecurity through multiple enhancements:

1. Implement Multi-Factor Authentication (MFA)

  • Rationale: Credential theft enabled breach. MFA enhances security by requiring multiple authentication factors, deterring unauthorized access even if credentials are compromised. 1
  • Implementation: Adopt MFA systems compatible with current infrastructure, using mobile apps or hardware tokens for high-priority accounts.
  • Expected Outcome: Reduced unauthorized access likelihood, mitigating credential theft risks.
  • Financial Implications: MFA solutions typically cost $3 to $10 per user monthly.

2. Conduct Regular Security Audits and Penetration Testing

  • Rationale: Regular audits reveal vulnerabilities akin to those exploited. Preemptive measures improve system resilience. 3
  • Implementation: Establish quarterly assessments with cybersecurity firms focusing on both external and internal frameworks.
  • Expected Outcome: Identify and resolve security vulnerabilities, fortifying systems against evolving threats.
  • Financial Implications: Assessment costs range between $10,000 to $30,000, dependent on scope and vendor.

3. Enhance Employee Training on Phishing and Social Engineering

  • Rationale: Phishing frequently targets human vulnerabilities, training boosts resistance. 2
  • Implementation: Set up comprehensive, annually updated training incorporating threat developments.
  • Expected Outcome: Decrease in successful phishing due to increased employee awareness.
  • Financial Implications: Training costs between $1,000 to $5,000 annually.

4. Establish Secure Configuration Management Practices

  • Rationale: Misconfigurations create exploitable openings, standardized frameworks prevent such vulnerabilities. 4
  • Implementation: Create configuration management baselines with routine compliance audits.
  • Expected Outcome: Reduced configuration error risks, ensuring adherence to security protocols.
  • Financial Implications: Initial management framework costs range from $5,000 to $20,000.

5. Implement Intrusion Detection Systems (IDS)

  • Rationale: IDS facilitates ongoing monitoring, alerting suspicious activity for rapid breach response. 5
  • Implementation: Deploy IDS across networks and endpoints, maintaining updates based on threat intelligence.
  • Expected Outcome: Detections and responses to incidents promptly, minimizing ransomware impacts.
  • Financial Implications: IDS costs range from $10,000 to $50,000 annually, varying with scope and service levels.

Conclusion

Implementing these strategies empowers the British Library with defenses against ransomware threats like the 2023 incident. By prioritizing prevention through enhanced authentication, audits, training, configuration management, and real-time intrusion detection, the organization can improve cybersecurity resilience.

Conclusion

The 2023 ransomware attack on the British Library highlights growing cyber threats to cultural and information repositories. It reinforces the critical necessity for adopting industry standards such as Multi-Factor Authentication (MFA) to bolster security frameworks.

Lessons Learned to Guide Future Resilience

The event emphasizes the importance of continuous security training programs and awareness to mitigate social engineering risks like phishing.

Steps for Improving Security Posture and Resilience Against Future Incidents

Regular security audits and integration of advanced security technology are essential. Developing and testing incident response plans, including rapid communications, can limit breach operational impacts.

The incident highlights evolving ransomware tactics focusing on not just data theft but operational disruption, requiring enhanced proactive monitoring and response.

Positive Outcomes or Improvements in Security Practices Resulting from This Incident

Collaborative efforts with cybersecurity infrastructures are likely to evolve, leading to improvement in shared intelligence and community security strategies.

Data Gaps

The report lacks in-depth data specifics on compromised data and comprehensive post-breach action plans, crucial for understanding the breach scope and driving industry-wide solutions.

Sources:

This report was machine-generated with PlanAI using the following sources:


  1. Information from technical inputs. ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎

  2. Investigations derived from cybersecurity cooperation insights. ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎

  3. Executive summary sourced from library response data. ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎

  4. AuthN by IDEE on LinkedIn: british-library-cyber-incident-review-8 …  ↩︎

  5. Rhysida ransomware gang is auctioning data stolen from the British …  ↩︎

Invariant analysis

InvariantEffectivenessConf.Explanation
Mandatory Hardware Second FactorHighThe report explicitly states initial access was via compromised credentials at VPN endpoints, facilitated by 'the absence of Multi-Factor Authentication (MFA)' on terminal servers, described as a core security lapse. A mandatory hardware second factor would have rendered the stolen/phished credentials insufficient for authentication, stopping the initial access step and preventing the entire subsequent chain (Zerologon escalation, lateral movement, ransomware deployment, and exfiltration) from ever occurring.
Positive Execution ControlMediumRansomware deployment required execution of the Rhysida encryption payload on compromised systems, which caused the IT outages described in the report. An application allow-list would have blocked this unauthorized executable from running, stopping the ransomware deployment/encryption step and the resulting service disruption. However, since lateral movement used built-in 'living off the land' admin tools (likely already allow-listed) and exfiltration could occur via legitimate channels before the ransomware payload executes, the invariant may not have prevented the earlier data theft that led to the 490,191-file leak, so it denies one major objective (encryption/outage) but not necessarily the exfiltration objective.
Egress ControlMediumThe attack chain culminated in exfiltration of 490,191 files (573GB) to Rhysida's infrastructure and eventual publication/auction on a leak site, plus reliance on native admin tools for lateral movement rather than external C2. Strict egress allow-listing would have blocked the bulk exfiltration of internal HR and other data to attacker-controlled servers, denying the double-extortion objective (data leak) even though it would not have stopped the initial VPN credential compromise, Zerologon privilege escalation, or local encryption/disruption of systems, which do not necessarily require novel outbound connections. This blocks one major attacker objective (data theft) while the ransomware deployment/outage impact could still occur.
Supply Chain AgingHighThe report identifies no open-source software supply chain compromise; the attack chain involved compromised VPN credentials, Zerologon exploitation, living-off-the-land lateral movement, and RaaS ransomware deployment. This invariant does not interact with any step of the documented attack.

Scored in assets/invariants/British_Library_2023_final.yaml — the same rows the leaderboard counts.

Read the invariant that would have stopped this

Comments

Now playing Bandcamp