Live data from Hacker News

British Library cyber incident review [pdf]

bl.uk

1–10 of 70 posts

Re: British Library cyber incident review [pdf]

#2
I happened to be there while this attack was in progress (ocotober 23). And all there systems were really offline, POS didnt work, wifi didn’t work, literally anything connected to a computer didnt work.

What’s unfortunate is that they flagged this vulnerability in 2022 and planned to review it in 2024 ???

Does it usually take this long to identify impact of users? They mentioned they paid for identity protection for their staff & ex-staff as well.

Re: British Library cyber incident review [pdf]

#3
"The Library utilises numerous trusted partners for software development, IT maintenance, and other forms of consultancy" ... "this terminal server was protected by firewalls and virus software, but access was not subject to Multi-Factor Authentication (MFA)"

¯\_(ツ)_/¯

Re: British Library cyber incident review [pdf]

#4
Good report. Well written incident summary useful for cyber-students to follow and learn.

> The Library utilises numerous trusted partners for software development, IT maintenance, and other forms of consultancy

> increasing complexity of managing their access was flagged as a risk.

> first detected unauthorised access to our network was identified at the Terminal Services server. This terminal server had been installed in February 2020 to facilitate efficient access for trusted external partners

Sadly their response seems to be using more cloud infrastructure and outsourcing more.

trusted != trustworthy

The essential lesson - that good IT and security people within your company cost money. It is worth paying for vigilance, loyalty and care - has not been heeded.

Re: British Library cyber incident review [pdf]

#5
post #3

"The Library utilises numerous trusted partners for software development, IT maintenance, and other forms of consultancy" ... "this terminal server was protected by firewalls and virus software, but access was not subject to Multi-Factor Authentication (MFA)" ¯\_(ツ)_/¯

Occasionally malware groups do patch vulnerabilities to maintain exclusive control over the victim machines. But that wouldn't be my default expectation, so relying on virus software to provide security does not seem like a great idea.

Re: British Library cyber incident review [pdf]

#6

I happened to be there while this attack was in progress (ocotober 23). And all there systems were really offline, POS didnt work, wifi didn’t work, literally anything connected to a computer didnt work. What’s unfortunate is that they flagged this vulnerability in 2022 and planned to review it in 2024 ??? Does it usually take this long to identify impact of users? They mentioned they paid for identity protection for…

I work in a related field (cyber insurance response) - typically takes a few months to identify exfiltrated data and then analyse it to understand what is in it. This might seem simple but there are usually in the region of hundreds of thousands to millions of files, and that may contain spreadsheets with tens of thousands of rows. This all has to be analysed, filtered and reduced to the point you have a list of PII which has been impacted, and can decide on what to do.

Credit monitoring is usually offered as standard when a breach occurs, the UK is much less litigation friendly than the US so in the absence of any actual harm, that would discharge most of their obligations to protect you following an incident.

Re: British Library cyber incident review [pdf]

#7

Good report. Well written incident summary useful for cyber-students to follow and learn. > The Library utilises numerous trusted partners for software development, IT maintenance, and other forms of consultancy > increasing complexity of managing their access was flagged as a risk. > first detected unauthorised access to our network was identified at the Terminal Services server. This terminal server had been instal…

> Sadly their response seems to be using more cloud infrastructure and outsourcing more.

CYA - it stops being their management's fault if its outsourced,

Re: British Library cyber incident review [pdf]

#8
This report is a joke.

No root cause. On other forums it is understood they were running very old and unpatched VMware os. Which is simply embarrassing and everybody within their IT team should be fired immediately for gross negligence.

They can't inform people whos data has been compromised because they refuse to pay the ransom and have no other way to tell what was stolen. Farcical.

Their ability to rebuild in a timely manner was hampered by not having any spare servers and presumably because all their server hardware was compromised and couldnt be used for restore.

Re: British Library cyber incident review [pdf]

#9

This report is a joke. No root cause. On other forums it is understood they were running very old and unpatched VMware os. Which is simply embarrassing and everybody within their IT team should be fired immediately for gross negligence. They can't inform people whos data has been compromised because they refuse to pay the ransom and have no other way to tell what was stolen. Farcical. Their ability to rebuild in a ti…

>They can't inform people whos data has been compromised because they refuse to pay the ransom and have no other way to tell what was stolen.

That doesn't fit their claims on page 7 about reviewing the lost data and contacting affected users.

Post reply on HN