The British Library ransomware attack was likely caused by the compromise of third-party credentials coupled with no multifactor authentication (MFA) in place to stop the attackers, despite previous warnings about these risks.
The lack of MFA on the domain was identified and raised as a risk when MFA was introduced to other parts of the Library in 2020, “but the possible consequences were perhaps under-appraised,” the report stated.
https://blogs.bl.uk/living-knowledge/2024/03/learning-lessons-from-the-cyber-attack.html
@ecksmc I’ve wondered how much of the stolen information and files is now part of OpenAI.
This report sheds new light on the October 2023 attack, which shut down digital services and breached the personal data of Library users and staff.
https://www.infosecurity-magazine.com/news/british-library-ransomware-attack/