Posted by Matt Barnett
Reported by Tim Furlong. Originally aired on NBC10 Philadelphia, September 25, 2024.
Every public library in Delaware lost internet and Wi-Fi service for days after a ransomware attack, and while the investigation ran, the state said almost nothing about what had been taken. NBC10 Philadelphia brought in SEVN-X CEO Matt Barnett to explain how an attack like this reaches a statewide library system, and why the silence coming out of Dover was not necessarily the red flag it looked like.
A note on our role. SEVN-X was not involved in the Delaware incident and had no access to the investigation. Matt spoke to NBC10 as an outside expert, and his comments on attribution and initial access were informed guesses based on how these attacks usually unfold.
The Short Version
The attack landed the week before the segment aired and knocked out internet access at public libraries across the entire state. At the North Wilmington branch, free Wi-Fi was still advertised on the building while a sign on the door asked people not to use it, citing technical difficulties.
Everything that did not depend on a network connection kept working. Patrons could still check out books and use other services. What they could not do was get online.
That distinction sounds minor until you consider who it lands on. For anyone filing a benefits claim, submitting job applications, doing coursework, or accessing a government portal without a computer at home, the terminal in the library is the entire reason for the trip. A statewide outage of that resource runs for as long as the recovery does, and recovery from ransomware is measured in weeks more often than days.
Furlong asked the state directly, on behalf of Delaware viewers, what personal information belonging to library users had been taken and what those users should be doing to protect themselves. The state would not answer either question, and he said on air that he found that frustrating.
Matt's take ran against the grain. Early in a breach, before responders understand the scope, there is very little an organization can say that is both specific and true. Guessing in public and correcting later does more damage than waiting.
“In a lot of ways, I think that’s a prudent step.”
Matt Barnett, CEO, SEVN-X
He put a limit on it in the same breath, noting that you cannot let the silence run too long. That tension is the real story. Investigators need room to establish facts, and the people whose data may be sitting in a criminal marketplace need to know soon enough to act. Breach notification law sets an outer boundary, but the judgment call about the days in between belongs to whoever is running the response, and it is much easier to make well if it was rehearsed in advance.
Matt's read was that nobody picked Delaware libraries on purpose. The likelier story is phishing email sprayed broadly, with the attackers waiting to see where it landed, then working with whatever access came back.
“It’s all about low hanging fruit for these attackers.”
Matt Barnett, CEO, SEVN-X
They pursue anyone and everyone within reach. He placed the operators in Russia or Eastern Europe, part of an established ecosystem where separate crews handle initial access, encryption, negotiation, and payment. Prosecuting them from the United States is difficult enough that many of them make little effort to stay hidden.
The practical implication is that being unimportant protects nobody. Public sector organizations tend to assume that a lack of obvious value keeps them off the list, when the selection criteria was never value in the first place. It was reachability.
Matt described the moment the way most victims experience it. Staff arrive in the morning, and the desktop background has been replaced with a notice saying the files are encrypted. Anything they try to open refuses to work.
Worth understanding: that moment is the end of the attack, not the beginning. Encryption is the last step. Before it, the intruders spent time inside the environment, escalating privileges, mapping shares, locating backups, and in most modern cases copying data out so they retain leverage even if the victim restores cleanly. The wallpaper is simply when they choose to be seen.
That is also why detection matters more than prevention alone. The window between initial access and encryption is where a response can still change the outcome, and organizations that catch nothing until the wallpaper changes have surrendered that window entirely.
None of the following is exotic. Nearly every ransomware case that reaches a statewide outage involves at least one of these being absent.
If you want to know whether these controls would actually hold, a ransomware readiness assessment tests your detection, backup integrity, and recovery procedures against real attack behavior instead of a questionnaire. Penetration testing covers the entry points from the other direction.
Before it is your turn
We test the controls that decide whether an intrusion becomes an outage. Bring us your environment and we will show you what an attacker would reach first.
Meet with an expertNo. SEVN-X had no role in the incident or the investigation. Matt Barnett appeared on NBC10 Philadelphia as an outside subject matter expert to help viewers understand how ransomware attacks like this one typically work.
Most likely they did not target it specifically. Opportunistic phishing sent broadly will eventually land somewhere, and the attackers work with whatever access comes back. Libraries are reachable rather than valuable, and reachable is the criterion that matters.
Say what you know and avoid speculating about what you do not. Early in a response the scope is genuinely unclear, and public guesses that later prove wrong cause real harm. That said, the window for silence is limited by both notification law and the obligation people have to protect themselves, which is why the messaging plan should exist before the incident.
There is no single control, but tested offline backups most often decide whether an incident becomes a recovery or a negotiation, and phishing-resistant MFA closes the entry point attackers use most.