CSIDB logo
Incident

British Museum

Incident posture

Attack window
Jan 2025
Location
United Kingdom
Status
Unknown
CIA posture
Available to members
Updated
2026-09-03 10:21

Linked entities

Victim
British Museum
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jan 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A recently dismissed IT contractor allegedly trespassed into the museum and shut down several of its IT and security systems, prompting a partial closure and temporary shutdown of exhibitions. Police were called late on a Thursday evening and arrested a man in his 50s at the scene on suspicion of burglary and criminal damage; he was later bailed pending further enquiries. The incident forced the closure of some galleries and all temporary exhibitions over the weekend, with limited visitor capacity and priority given to members and existing ticket holders, who were offered refunds or the option to reschedule. Staff worked to restore full operations, and the museum apologized for the inconvenience caused to visitors.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On Thursday evening, 23 January 2025, the British Museum suffered an alleged IT attack at the hands of a former contractor. The Metropolitan Police received a report at 20:25 GMT that a man had entered the museum and caused damage to its security and IT systems. Officers attended the scene promptly and arrested a man in his 50s on suspicion of burglary and criminal damage. He was subsequently bailed pending further enquiries. According to a British Museum spokesperson speaking to the BBC, the individual in question was an IT contractor who had been dismissed from the museum the previous week. After being let go, the former contractor trespassed into the building and shut down several of the museum's systems before being apprehended by police at the scene. The combination of unauthorised physical entry and subsequent digital disruption caused immediate operational problems for one of the United Kingdom's most prominent cultural institutions, which houses internationally significant artefacts including the Rosetta Stone, the Anglo-Saxon ship burial from Sutton Hoo, and the contested Parthenon Sculptures.

The incident had tangible consequences for museum operations and the visiting public. Following the shutdown of multiple IT systems, the museum was partially closed to visitors on Friday, 24 January 2025, with several galleries unable to open. All three of the museum's temporary exhibitions at the time, including Silk Roads and Picasso: Printmaker, were closed on that Friday and remained closed over the weekend. The permanent collection areas were also affected, with overall visitor capacity described as limited. The museum prioritised members and individuals who already held tickets for the affected period, and tickets for the temporary exhibitions that had been pre-purchased were subject to refunds or rescheduling. Ticket holders were contacted ahead of their planned visits, and the museum apologised for the inconvenience while directing customers to its box office for rebooking or other arrangements. The museum indicated that staff were working to restore full services as quickly as possible, though the temporary exhibitions would remain closed throughout the weekend following the attack.

The attack itself combined physical trespass with digital sabotage. The former contractor entered the museum building without authorisation before accessing and shutting down IT systems, suggesting that either retained access credentials, familiarity with the museum's infrastructure from his previous role, or a combination of both enabled the intrusion. The systems affected included security systems alongside general IT infrastructure, indicating a broad rather than narrowly targeted disruption. The fact that the individual was able to enter the building and remain on site long enough to cause damage to both physical security infrastructure and digital systems points to a window of vulnerability that was ultimately closed by the rapid response of Metropolitan Police officers. Police described the damage as affecting both security and IT systems, and the man was arrested at the scene rather than after a pursuit, suggesting that either on-site security personnel or police attendance interrupted the activity. The arrest itself was made on suspicion of burglary, reflecting the unauthorised entry into the building, and criminal damage, reflecting the destruction or disruption caused to the museum's systems.

The museum's response focused on containment, communication, and gradual restoration of services. Upon detecting the intrusion and the resulting system shutdowns, museum staff worked alongside police to secure the premises and address the immediate impact. Communication with the public was prioritised through direct contact with ticket holders and broader statements to the media explaining the situation. The decision to close temporary exhibitions while keeping some permanent collection areas open, with limited capacity, represented an effort to maintain as much public access as possible while technical teams worked on restoring shut-down systems. The museum also offered refunds to affected customers and the option to reschedule visits through the box office. The speed of the police response, with officers attending on the same evening as the incident report and arresting the suspect at the scene, limited the duration of the active intrusion. However, the operational impact persisted into the weekend, with temporary exhibition closures announced in advance and visitor capacity remaining restricted.

The broader significance of the attack lies in its combination of insider knowledge with immediate physical access. The perpetrator was not an external threat actor attempting to breach the museum's network from afar but rather a former contractor who had been dismissed only days earlier. This pattern, an insider or former insider using retained knowledge and access to cause disruption, represents a particular category of risk for organisations that rely on contractors for critical IT functions. The British Museum had named as the top UK visitor attraction in 2023, with 5,820,860 visitors recorded that year, making any operational disruption felt by a large audience. The incident underscores the vulnerability of cultural and public institutions to attacks that exploit the intersection of physical and digital access, particularly when those carrying out the attack have recent familiarity with internal systems. As of the available reporting, the museum continued efforts to return to full operational status while police enquiries into the incident remained ongoing with the arrested individual released on bail.

Sources

Sources available to members: 1 source.

CSIDB