The British Library said personal data stolen in its 31 October cyberattack was leaked online and appeared to be offered for sale, with evidence indicating the material came from internal HR records. Images posted by the attackers appeared to show employment contracts and passport information, and the library warned that employee data had been exposed while major disruption continued across its website, online systems, reading rooms, and public Wi‑Fi. The institution urged users to change any reused passwords and said it was working with the UK National Cyber Security Centre, the Metropolitan Police, and external cybersecurity specialists.
The ransomware group Rhysida claimed responsibility and advertised the stolen data on its leak site with a starting bid of 20 bitcoin, in what researchers described as a double-extortion operation combining system encryption with data theft. US agencies including the FBI and CISA had recently warned that Rhysida has targeted organizations across education, manufacturing, IT, and government, while private-sector researchers linked the group to attacks in Europe, the Middle East, and the Americas and assessed it may be a rebrand of the older Vice Society operation. Analysts said Rhysida commonly gains access through phishing or compromised VPN accounts and uses ransom notes titled CriticalBreachDetected.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Security researchers reported that Rhysida likely emerged from the older Gold Victor/Vice Society operation, suggesting the group was part of a ransomware rebranding pattern.
Before the British Library reporting in late November 2023, the FBI and CISA issued a warning that Rhysida had been targeting organizations across multiple sectors since May 2023.
Following the breach and data leak, the library said it was investigating the incident with support from the UK National Cyber Security Centre, the Metropolitan Police, and external cybersecurity specialists.
The British Library confirmed that personal data stolen in the attack had been leaked online, saying the material appeared to come from internal HR files and advising users to change reused passwords.
By 2023-11-21, the Rhysida ransomware group had claimed responsibility for the British Library incident and advertised allegedly stolen data on its leak site with a starting bid of 20 bitcoin.
On 2023-10-31, the British Library suffered a cyberattack that disrupted its website, online systems, reading rooms, and public Wi‑Fi, with some impacts expected to last for months.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
theguardian.com
Open sourcetheguardian.com
Open sourcebbc.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.