The British Library suffered a major ransomware attack attributed to Rhysida that knocked out its website, online catalogue, digital collections, email, phone network, public Wi‑Fi, and parts of its onsite operations in London and Yorkshire. The disruption forced staff to fall back on limited manual processes for reader services, item ordering, and payments, while the library kept its sites open with reduced functionality. The library said it worked with the UK National Cyber Security Centre, law enforcement, private forensic specialists, and the Metropolitan Police as it investigated and contained the incident.
Rhysida claimed responsibility, leaked internal HR documents, and attempted to auction stolen data for 20 bitcoin before publishing about 573GB of files, including data reportedly taken from CRM systems. The library later said stolen information included personal data such as names, email addresses, and in some cases postal addresses and phone numbers, though not apparently financial data. Recovery took months: by mid-January the library had begun restoring its online catalogue, but warned that broader remediation could take many more months and carry multimillion-pound costs. The outage also disrupted the UK Public Lending Right scheme, delaying royalty payments to more than 20,000 authors and other contributors.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
By 2024-01-16, reporting indicated the British Library expected to use its financial reserves to cover recovery costs from the cyberattack. This added a new dimension to the incident by highlighting its direct financial impact on the institution.
By 2024-01-15, reporting said the incident had been identified as a Rhysida ransomware attack involving theft and publication of about 573GB of data, including nearly 500,000 files, many from CRM systems. The library said stolen information included names, email addresses, and in some cases postal addresses and phone numbers, but apparently not financial data.
On 2024-01-15, the British Library said it had started restoring its online catalogue, making most physical holdings at St Pancras discoverable again. It warned that ordering and access would remain slower and more manual, and that full recovery would take several more months.
By early January 2024, the cyberattack had delayed UK Public Lending Right payments to authors, illustrators, translators, and other contributors because the affected systems remained unavailable. The British Library said it aimed to issue payments before the end of March and provide a firmer timetable by the end of January.
By 2023-11-21, the British Library confirmed that internal HR documents had been leaked following the ransomware attack. It said it was working with the Metropolitan Police and the NCSC on a forensic investigation while major service disruptions continued.
On 2023-11-20, the Rhysida ransomware group claimed responsibility for the British Library attack and began a seven-day dark web auction of allegedly stolen data for 20 bitcoin. The group also leaked internal HR documents as proof of compromise.
On 2023-10-31, the library confirmed the outage was caused by a cyber incident and said it had launched an investigation with support from the UK National Cyber Security Centre and other cybersecurity specialists. The attack disrupted both online services and onsite operations, including phone and Wi‑Fi services.
On 2023-10-29, the British Library said it was experiencing a major technology outage affecting its website, catalogue, digital collections, reader registration, and some onsite services. Its London and Yorkshire sites remained open, with some services handled manually.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
independent.co.uk
Open sourcetheguardian.com
Open sourceweb.archive.org
Open sourcebbc.com
Open sourcecomputerweekly.com
Open sourcenytimes.com
Open sourceweb.archive.org
Open sourcetheguardian.com
Open sourcecomputerweekly.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.