SEVN-X Blog

Ransomware Hits Delaware Public Libraries, are they safe?

Written by Matt Barnett | Jan 22, 2025, 4:57:19 PM
Ransomware

Ransomware Hits Delaware Public Libraries

Posted by Matt Barnett

Reported by Tim Furlong. Originally aired on NBC10 Philadelphia, September 25, 2024.

Every public library in Delaware lost internet and Wi-Fi service for days after a ransomware attack, and while the investigation ran, the state said almost nothing about what had been taken. NBC10 Philadelphia brought in SEVN-X CEO Matt Barnett to explain how an attack like this reaches a statewide library system, and why the silence coming out of Dover was not necessarily the red flag it looked like.

A note on our role. SEVN-X was not involved in the Delaware incident and had no access to the investigation. Matt spoke to NBC10 as an outside expert, and his comments on attribution and initial access were informed guesses based on how these attacks usually unfold.

The Short Version

Ransomware Hits Delaware Public Libraries

  • A ransomware attack took internet and Wi-Fi offline at every public library in Delaware, statewide, for more than a week.
  • Books, checkouts, and in-person services kept running. Connectivity was the casualty, which hit hardest for patrons who rely on library computers.
  • The state declined to say what patron data was taken or what users should do, which frustrated reporters but may have been the right early call.
  • Matt Barnett's read was opportunistic phishing rather than a targeted campaign, with libraries qualifying as reachable rather than valuable.
  • The lesson for public institutions is unglamorous: MFA, tested offline backups, network separation, and a communications plan written before you need it.

What Actually Happened

The attack landed the week before the segment aired and knocked out internet access at public libraries across the entire state. At the North Wilmington branch, free Wi-Fi was still advertised on the building while a sign on the door asked people not to use it, citing technical difficulties.

Everything that did not depend on a network connection kept working. Patrons could still check out books and use other services. What they could not do was get online.

That distinction sounds minor until you consider who it lands on. For anyone filing a benefits claim, submitting job applications, doing coursework, or accessing a government portal without a computer at home, the terminal in the library is the entire reason for the trip. A statewide outage of that resource runs for as long as the recovery does, and recovery from ransomware is measured in weeks more often than days.

Why the State Said So Little

Furlong asked the state directly, on behalf of Delaware viewers, what personal information belonging to library users had been taken and what those users should be doing to protect themselves. The state would not answer either question, and he said on air that he found that frustrating.

Matt's take ran against the grain. Early in a breach, before responders understand the scope, there is very little an organization can say that is both specific and true. Guessing in public and correcting later does more damage than waiting.

“In a lot of ways, I think that’s a prudent step.”

Matt Barnett, CEO, SEVN-X

He put a limit on it in the same breath, noting that you cannot let the silence run too long. That tension is the real story. Investigators need room to establish facts, and the people whose data may be sitting in a criminal marketplace need to know soon enough to act. Breach notification law sets an outer boundary, but the judgment call about the days in between belongs to whoever is running the response, and it is much easier to make well if it was rehearsed in advance.

Why a Library System

Matt's read was that nobody picked Delaware libraries on purpose. The likelier story is phishing email sprayed broadly, with the attackers waiting to see where it landed, then working with whatever access came back.

“It’s all about low hanging fruit for these attackers.”

Matt Barnett, CEO, SEVN-X

They pursue anyone and everyone within reach. He placed the operators in Russia or Eastern Europe, part of an established ecosystem where separate crews handle initial access, encryption, negotiation, and payment. Prosecuting them from the United States is difficult enough that many of them make little effort to stay hidden.

The practical implication is that being unimportant protects nobody. Public sector organizations tend to assume that a lack of obvious value keeps them off the list, when the selection criteria was never value in the first place. It was reachability.

What Day One Looks Like Inside

Matt described the moment the way most victims experience it. Staff arrive in the morning, and the desktop background has been replaced with a notice saying the files are encrypted. Anything they try to open refuses to work.

Worth understanding: that moment is the end of the attack, not the beginning. Encryption is the last step. Before it, the intruders spent time inside the environment, escalating privileges, mapping shares, locating backups, and in most modern cases copying data out so they retain leverage even if the victim restores cleanly. The wallpaper is simply when they choose to be seen.

That is also why detection matters more than prevention alone. The window between initial access and encryption is where a response can still change the outcome, and organizations that catch nothing until the wallpaper changes have surrendered that window entirely.

What Public Institutions Should Take From This

None of the following is exotic. Nearly every ransomware case that reaches a statewide outage involves at least one of these being absent.

Close the entry point

  • Require phishing-resistant MFA on email, VPN, and remote access. Hardware keys and authenticator apps hold up where SMS codes do not.
  • Patch anything internet-facing on a defined schedule, and know what is internet-facing in the first place.
  • Filter email aggressively, and pair it with training built around the phishing your staff actually receives.

Limit how far it spreads

  • Separate public-access networks from staff systems, and separate both from anything administrative. A patron terminal should not be able to reach a domain controller.
  • Apply least privilege to service accounts, which is where attackers usually find the keys to move laterally.
  • Deploy endpoint detection that alerts on behavior, so lateral movement surfaces before encryption starts.

Be able to come back

  • Keep backups offline or immutable. Backups reachable from the network get encrypted along with everything else.
  • Test restores rather than confirming that backup jobs completed. Those are different claims, and only one of them matters.
  • Write down your recovery order. Deciding which systems come back first while the building is dark wastes days.

Decide who speaks before you need to

  • Draft holding statements now, so the early hours do not require improvisation. Tabletop exercises are where you discover that nobody knows who approves the public statement.
  • Know your notification obligations and the clock attached to them, including any state requirements covering patron or student records.
  • Line up incident response contacts in advance. Negotiating a contract while encrypted is the worst possible time to do it.

If you want to know whether these controls would actually hold, a ransomware readiness assessment tests your detection, backup integrity, and recovery procedures against real attack behavior instead of a questionnaire. Penetration testing covers the entry points from the other direction.

Before it is your turn

Would your recovery plan survive contact?

We test the controls that decide whether an intrusion becomes an outage. Bring us your environment and we will show you what an attacker would reach first.

Meet with an expert

Frequently Asked Questions

Was SEVN-X involved in the Delaware library incident?

No. SEVN-X had no role in the incident or the investigation. Matt Barnett appeared on NBC10 Philadelphia as an outside subject matter expert to help viewers understand how ransomware attacks like this one typically work.

Why would attackers target a public library system?

Most likely they did not target it specifically. Opportunistic phishing sent broadly will eventually land somewhere, and the attackers work with whatever access comes back. Libraries are reachable rather than valuable, and reachable is the criterion that matters.

Should an organization tell the public what was taken right away?

Say what you know and avoid speculating about what you do not. Early in a response the scope is genuinely unclear, and public guesses that later prove wrong cause real harm. That said, the window for silence is limited by both notification law and the obligation people have to protect themselves, which is why the messaging plan should exist before the incident.

What single control prevents the most ransomware damage?

There is no single control, but tested offline backups most often decide whether an incident becomes a recovery or a negotiation, and phishing-resistant MFA closes the entry point attackers use most.