Rhysida ransomware attack kept British Library services offline for weeks
- Organization
- The British Library
- Exploit
- Ransomware
- Industry
- Libraries and Archives
The British Library, the United Kingdom's national library, was hit by a ransomware attack on October 28, 2023. The intrusion took down phone lines and on site services at its main building in London and its site in Yorkshire, along with the library's website, digital collections and online catalogue.
The library confirmed on November 14 that ransomware was responsible. Weeks after the attack it was still operating on paper. Readers could obtain only temporary passes, and collection items had to be ordered manually using printed catalogues and paper forms. The library said it anticipated restoring many services in the next few weeks but that some disruption might persist for longer, and Infosecurity Magazine reported that full recovery could take weeks or possibly months.
On November 20 the Rhysida ransomware group claimed the attack and put the stolen files up for auction on its leak site, opening bids at 20 bitcoin, worth roughly 600,000 pounds at the time, with a deadline of November 27. Rhysida said the data would go to a single buyer with no resale, a promise security researchers noted victims have no way to verify.
As proof, the group posted low resolution images of documents that appeared to include passport scans and employment paperwork in the format used by HM Revenue and Customs, indicating staff records were among the files taken. The library said it was still working to understand the full scope of the compromise.