CodoraTech CodoraTech
Cybersecurity March 13, 2026

Building a Ransomware Response Plan from Incidents Their Victims Documented

Building a Ransomware Response Plan from Incidents Their Victims Documented

How CodoraTech is funded: CodoraTech is supported by advertising and, in some articles, by affiliate links. Where an article contains affiliate links, we say so at the top of that article.

The British Library published a review of its own ransomware attack that names the server the attackers came through, quantifies what they took and lists the sixteen things the organisation decided to change. UnitedHealth’s chief executive gave the same order of detail to a Senate committee under oath. Those two documents, together with the public record from Maersk, MGM Resorts and Caesars Entertainment, are what a response plan should be built from. Each figure below is marked with whoever published it, because a victim’s own post-mortem and a supplier’s survey are not equivalent evidence.

Key facts

  • British Library, 28 October 2023: about 600GB and roughly 500,000 documents taken; the Library paid nothing
  • Change Healthcare: access on 12 February 2024, ransomware on 21 February, $22 million paid in Bitcoin
  • UnitedHealth put its 2024 response costs at $3.1 billion and the affected population at 190 million people
  • Maersk reinstalled 45,000 PCs, 4,000 servers and 2,500 applications in ten days after NotPetya
  • The FBI states that it does not support paying a ransom

The library that investigated itself in public

On Saturday 28 October 2023 the British Library was attacked by the group known as Rhysida. In March 2024 the Library published its own account, which remains the most detailed self-examination any ransomware victim has released. Approximately 600GB of files, around 500,000 documents, were taken, including personal data belonging to users and staff. The Library was unusually specific about method: wholesale copying of Finance, Technology and People team files accounted for about 60 percent of the stolen content, keyword-based scanning for sensitive documents for the remaining 40 percent, and the attackers forced backup copies of 22 databases. Credit-card data and the Electoral Roll database were not compromised.

The likely entry point was a Terminal Services server installed in February 2020 to give external partners and administrators access, where, in the Library’s words, access was not subject to multifactor authentication. MFA had been implemented for cloud applications in 2020, but on-premises domain connectivity was left unprotected for reasons the review gives as practicality, cost and impact, pending an infrastructure renewal that had not happened. A complex legacy network let the attacker reach far more than a segmented network would have allowed, and years of manual transfers between older applications had multiplied copies of sensitive information across it. The Library paid nothing and made no contact with the attackers, consistent with UK national policy as set out by the National Cyber Security Centre.

Sixteen recommendations, and the three that recur

The review sets out sixteen recommendations. They are worth reading in full because they are unusually unglamorous, and because an organisation wrote them about itself after the worst had already happened.

  • Enhance network monitoring and intrusion response
  • Retain on-call external security expertise
  • Fully implement multifactor authentication
  • Implement network segmentation
  • Practise business continuity plans
  • Manage system lifecycles so that legacy technology is eliminated rather than tolerated
  • Prioritise recovery alongside prevention
  • Establish cyber-risk expertise at senior and board level
  • Proactively manage staff and user wellbeing
  • Collaborate with sector peers on threat intelligence

Nine days between a stolen credential and encryption

Cybersecurity Dive reported the testimony that Andrew Witty, chief executive of UnitedHealth Group, gave to the Senate Finance Committee on 1 May 2024. Attackers used stolen credentials on a Citrix remote-access portal that lacked multifactor authentication, despite a company policy requiring MFA on all external-facing systems. In Witty’s words, that was the server through which the cybercriminals were able to get into Change. The parallel with the British Library is exact: a remote-access route without MFA, sitting in front of a flat legacy network, in two different sectors and two different countries a year apart.

The recovery decision is the second lesson. UnitedHealth did not restore from legacy backups; it rebuilt the Change platform on modern cloud technology, because backup isolation failures and systems described as roughly 40 years old hampered any restore. The reported cost of the attack was $3.1 billion in 2024 response costs, a $22 million Bitcoin ransom confirmed by Witty, and an affected population that reached 190 million individuals, nearly double the 100 million UnitedHealth had estimated in October 2024. Change has said it is not aware of any misuse of the exposed data.

  1. 12 February 2024: initial access through the Citrix portal using stolen credentials
  2. Roughly nine days of dwell time inside the environment
  3. 21 February 2024: ransomware deployed by ALPHV/BlackCat
  4. Recovery by rebuild rather than restore, after backup isolation failures

Forty-five thousand PCs, rebuilt in ten days

Maersk’s chairman, Jim Hagemann Snabe, described the company’s NotPetya recovery publicly at the World Economic Forum in Davos in January 2018, which is a rare on-the-record account from the top of an affected company. BleepingComputer reported the scope: 45,000 PCs, 4,000 servers and 2,500 applications reinstalled in a ten-day window from late June to early July 2017. Snabe said the work would normally take six months. Maersk kept about 80 percent of its normal shipping volume moving on manual processes while its IT was down, against a normal throughput of a ship of 20,000 containers every fifteen minutes, and estimated damages of $250 million to $300 million, in the same range as the estimates published by Merck and FedEx.

Two details make this the reference case for destructive recovery rather than a ransomware story. The initial vector was a malicious update to M.E.Doc Ukrainian accounting software, which then spread to international offices over VPN, so a supply-chain compromise rather than a phishing message. And the CIA attributed NotPetya to Russia’s GRU, with Snabe describing Maersk as collateral damage of probably a state attack. There was no functioning payment path to buy a decryption key. Any plan that assumes payment is available as a fallback should account for that.

Caesars paid, the FBI says do not, and the UK may ban it

September 2023 produced the cleanest natural experiment on the payment question. TechTarget reported that MGM Resorts was hit by ALPHV/BlackCat using Scattered Spider social engineering, with the entry route running through the help desk and identity and access management via Okta. MGM’s own filing with the Securities and Exchange Commission put the impact at roughly $100 million against Adjusted Property EBITDAR, plus under $10 million in one-time consulting, legal and advisory costs, and said cyber insurance would be sufficient to cover it. Whether MGM received or paid a ransom demand is not confirmed on the record, and MGM did not comment; several secondary outlets assert that it refused, and this article does not. Caesars Entertainment, hit by the same campaign, paid roughly half of a $30 million demand according to Wall Street Journal reporting relayed by TechTarget. Same attacker, same window, same sector, different choices, and both suffered anyway.

The named positions on payment do not line up neatly. The FBI states plainly that it does not support paying a ransom, giving two reasons: paying does not guarantee that data comes back, and it encourages perpetrators to target more victims. The UK government went further. Pinsent Masons reported that its consultation response, published on 22 July 2025, proposes an outright ban on payments by public sector bodies and critical national infrastructure operators, a payment prevention regime requiring businesses to notify authorities before paying, and mandatory reporting of certain incidents within 72 hours, to be explored through the Cyber Security and Resilience Bill. No framework is yet enacted.

The counter-argument is also on the record and comes from practitioners rather than criminals. Ellie Ludlam of Pinsent Masons questions whether a ban simply pushes attackers toward other ways of monetising an intrusion, and how an organisation is supposed to recover with no payment option at all, and flags that the scope and penalties of the proposed reporting regime remain unresolved. Decide the question in advance, in writing, with your lawyers and your insurer. The middle of an incident is the worst time to start.

Sources: British Library · Cybersecurity Dive · BleepingComputer · TechTarget · Federal Bureau of Investigation · Pinsent Masons