Skip to main content

40 years of heritage lost? What a cyberattack does to your team and organization

On December 9, 2024, the National Museum of the Royal Navy in the United Kingdom is attacked by cybercriminals. Their vital servers and digital collections are encrypted. Responsible for IT at the time is George Wilson. In episode 6, season 3 of the podcast Cultuurshift, George takes you to the moment of the attack, the uncertainty, crisis management, and also the impact on heritage and the team. A rare insight into a scenario that you will encounter sooner or later. 

4 minutes24 jun `26

Curious how the National Museum of the Royal Navy resolved the cyberattack? Watch or listen to DEN's podcast Cultuurshift season 3, episode 6: This is what a cyberattack feels like. And this is how you prevent it.

George Wilson is at Southampton airport, on his way to their museum in Belfast to onboard new colleagues when he hears that something seems to be wrong with their systems. He is not overly concerned and suspects it has something to do with the aftermath of a disruption from a few weeks ago. When he lands, an hour and a half later, the devastation becomes clear. 

Three-quarters of the systems

Of the twenty digital systems, fourteen are completely down. Both the front end (ticket sales) and the back end (email, files, collection management) have been encrypted by criminals.

Buying mobile payment devices 

In the first 24 to 48 hours, he tries to get a grip on the scale and impact. When three-quarters of your organization is down, you can't fix everything at once. Wilson and his management team had to make sharp choices. Their absolute priority was the ticketing system: 80% of the museum's revenue comes from ticket sales.  

George: “We immediately started buying those mobile card readers and payment devices that you can connect to a phone. Most people pay with their cards at our locations, so we absolutely didn't want to leave visitors in the cold in that regard.”

At the same time, there were also immediate concerns: had visitor information and other sensitive data been stolen? It ultimately took six weeks to completely rule that out. 

Royal nacy schip buiten
The Royal Navy Museum - ship

Prioritization and mental burden

The second priority was the systems related to the collection. 

“Until February, we truly had no idea about the state of the database. That uncertainty was terrible. You're talking about forty years of work that the entire team has built, and you simply don't know if you'll ever be able to access it again.” 

For a museum that revolves around preserving heritage, the uncertainty brought an enormous mental burden for the team. Only after months of intensive investigation did it turn out that the database was fortunately intact. 

Manually resetting 400 devices

George's team wanted to ensure there was no malware or virus on laptops and phones. This large organization is spread across six locations in the United Kingdom. Everything had to be brought to one place, and about 400 devices had to be completely wiped and reset, which alone was a massive operation. It turned out there had indeed been tampering. 

Lessons for your own organization

  1. Follow the 3-2-1 backup rule

    Ensure at least three copies of your data, spread across two different locations, with at least one being completely offline. 

  2. Test your recovery procedure

    Having a backup is one thing, but do you know how long it takes to restore it? By testing this regularly, you can avoid surprises during a real crisis. 

  3. Close technical gaps

    Use antivirus software and stay up-to-date with software updates.

Backups 

“I would shout it from the rooftops,” Wilson firmly states, "one of our most important lessons is about backups.” 

George: “It was precisely that very last piece, the offline backup, that we lacked at the time of the attack. As a result, we lost several systems permanently and had to rebuild them from scratch. 

"If I could impress one thing upon other organizations, it's this: make sure your backup systems are truly watertight.”

George Wilson - The Royal Navy Museum

How they got in

The museum used Microsoft Defender, which fortunately limited the spread of the ransomware within the network. Yet the criminals found a loophole. The culprit turned out to be a vulnerability in a Microsoft Exchange server.

“It wasn't a human error, like a phishing email,” George explains. “They purely exploited a technical flaw in the system to sneak in.”

Nothing stolen

The handling of the attack was peculiar. No ransom was demanded, and nothing was stolen. A very strange situation, according to George. 

George: “It was truly a very strange situation. Normally, those guys leave a ransom note and immediately seek contact to negotiate. For us, it was different. We did find a note, but it was clearly a sloppy copy-paste template. There was nothing specific about us in it. It only said: 'Come to this chatroom on the dark web, we're waiting for you to talk.' We eventually went there, but no one ever showed up. Very bizarre.”

No concrete message, no ransom demand, and no contact whatsoever. The museum suspects it might have been some kind of opportunistic exercise.

Awakened

A year earlier, The British Library was attacked. “That really woke us up.” They were in the process of improving their own online security, inspired by the lessons learned from the British Library, when the heritage organization itself was hit. 

That's also why he participates in the podcast Cultuurshift: “If just one organization learns from our story, my mission is accomplished.” 

Share this news article

Want to get started with cybersecurity yourself?

In the online workshop Cybersecurity in the cultural sector, you will work on a practical action plan for a secure digital foundation in just two hours. You will map out the key digital systems and data of your organization, gain insight into risks and appropriate measures, and take concrete steps toward structural cybersecurity.

Go to the workshop