Site navigation

British Library Confirms Data Leaked On The Darkweb

Michael Edgar

,

British Library attack
British Library confirms user data was exfiltrated and leaked on the dark web by a ransomware cartel. 

The British Library faced a major IT outage on the 31st of October, later confirming the outage was the result of a cyber-attack by the emerging Rhysida operation. 

“We’re continuing to experience a major technology outage as a result of a cyber-attack. This is affecting our website, online systems and services, as well as some onsite services,” said a library spokesperson in a social media release

The cyber-criminals then posted evidence of stolen internal documents such as HR files and initiated a seven-day auction which concluded this week. After the auction, the library confirmed that the data breach was more severe than initially anticipated. 

“We now have evidence that indicates the attackers might have copied some user data, and additional data appears to have been published on the dark web,” continued the spokesperson. 

“We will continue to work with cybersecurity specialists to examine what this material is, and we will be contacting our users to advise them of the practical steps they may need to take.”

Despite facing issues accessing services over the past month, the British Library has received goodwill from users. However, the recent data breach announcement raises concerns about potential legal and regulatory consequences. 


Recommended reading


The library has already informed the Information Commissioner’s Office (ICO) as per its legal obligations and is collaborating with London’s Metropolitan Police and teams from the National Cyber Security Centre.

“We will continue to work with cybersecurity specialists to examine what this material is and we will be contacting our users to advise them of the practical steps they may need to take,” said a library spokesperson. 

The situation remains under investigation, with updates expected soon as the library collaborates with cybersecurity experts and law enforcement agencies.

The cyber-criminal group, Rhysida, is an emerging ransomware-as-a-service (RaaS) operation which targets various sectors like education, government, healthcare, IT, and manufacturing. Rhysida’s attacks utilise external-facing remote services and exploits vulnerabilities such as Zerologon to gain access to its targets’ networks.

Michael Edgar

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data