British Library security incident

Rhysida ransomware. Months-long systems outage; data auctioned on dark web.

Last modified

Summary

  • Environment: Cultural/Government
  • Operational impact: Months-long systems outage; data auctioned on dark web
  • Financial impact: £6-7M recovery
  • Record status: Developing record. Reviewed September 19, 2026; updated as evidence emerges.

What happened

In 2023, British Library experienced an incident in its cultural/government environment. The retained source describes the attack path as follows: Rhysida ransomware. [1]

The documented consequence was: Months-long systems outage; data auctioned on dark web. [1]

Impact

  • Documented impact: Months-long systems outage; data auctioned on dark web. [1]
  • Documented financial consequence: £6-7M recovery. [1]

Threat Group & Attack Vector

The retained source describes the attack path as follows: Rhysida ransomware. The canonical record does not add intrusion steps beyond those supported by the source. [1]

Actors

  • Rhysida — identified in the supported attack description. [1]

TTPs

Response

The retained source describes system restoration or operational recovery work. [1]

This account is bounded to Learning Lessons from the Cyber-Attack. Details absent from that evidence are left unresolved rather than inferred. [1]