Topics

in vogue

AI

Amazon

Article image

Image Credits:Peter Macdiarmid / Getty Images

Apps

Biotech & Health

Climate

an angled shot looking down at the inside of the British Library, with desks on the ground floor and a huge glass wall with books behind

Image Credits:Peter Macdiarmid / Getty Images

Cloud Computing

Commerce

Crypto

Enterprise

EVs

Fintech

Fundraising

gadget

punt

Google

Government & Policy

ironware

Instagram

Layoffs

Media & Entertainment

Meta

Microsoft

Privacy

Robotics

security system

societal

Space

Startups

TikTok

transferral

speculation

More from TechCrunch

event

Startup Battlefield

StrictlyVC

Podcasts

Videos

Partner Content

TechCrunch Brand Studio

Crunchboard

Contact Us

The British Library , the interior library of the United Kingdom and one of the world ’s largest libraries , has confirmed that aransomware attackled to the stealing of internal datum .

In late October , the British Library first disclose it was experiencing an unspecified cybersecurity incident that induce a “ major technology outage ” across its sites in London and Yorkshire , which downed its website , earphone demarcation , and on - site services , such as visitor Wi - Fi and electronic payments .

Two week on , and the British Library outage is still ongoing . However , the organization has now sustain the disruption is the result of a ransomware attack launched “ by a group known for such criminal activity . ” The British Library said that some inner data point has leaked online , which “ seems to be from our internal HR files . ”

We ’re keep to experience a major engineering science outage as a solution of a cyber - plan of attack , affecting our website , on-line systems and services , and some onsite services too . We expect restore many services in the next few weeks , but some disruption may persist for longer.…pic.twitter.com/Wdj7VfkWXa

— British Library ( @britishlibrary)November 20 , 2023

This confirmation come hours after the British Library was listed on the dark-skinned web leakage site of the Rhysida ransomware crew . The listing , see by TechCrunch , claimed responsibleness for the cyberattack and threatens to release datum stolen from the British Libraryunless it ante up a ransom demand . The gang call for more than $ 740,000 worth of bitcoin at the time of composition .

Join us at TechCrunch Sessions: AI

Exhibit at TechCrunch Sessions: AI

The Rhysida ransomware mob has n’t said how much or what types of data it has steal from the British Library , but sample of the data apportion by the crew appear to include utilization documents and recommendation scans .

Rhysida was last weekthe subject of a joint CISA and FBI advisory , which warned that the group leverages external - face remote services , such as VPNs , to compromise organizations across the education , IT and government sectors . The advisory also warned that Rhysida , which was first note in May , part overlaps withthe Vice Society ransomware gang , a cut group known for ransomware extortion attacks on health care and educational organizations .

“ Notably , concord to the ransomware chemical group ’s data leak site , Vice Society has not posted a dupe since July 2023 , which is around the prison term Rhysida begin cover victims on its website , ” Sophos research worker Colin Cowie and Morgan Demboski wrote in arecent analytic thinking of Rhysida .

It ’s not uncommon for ransomware gangs todisband , rebrand or create new malware variants , often as a manner toevade regime sanctionsoravoid arrest by natural law enforcement .

In a assertion on Monday shared on X ( formerly Twitter ) , the British Library enounce it has “ no grounds ” that the data point of its customers was compromised but is recommending that user transfer their passwords as a “ precautionary measure , ” peculiarly if customers use the same word across multiple service .

It ’s not experience if the British Library has the expert way to see if client datum was taken .

The British Library has not yet said how it was compromise , how much employee data was stolen , or whether it has received communications or a ransom money demand from the hackers . The British Library did not respond to TechCrunch ’s interrogative sentence , though it ’s not clear-cut if the organization has access to email services . The library ’s website remains offline at the prison term of publication .

The British Library say in its latest financial statement that it could take workweek , or possibly even longer , for it to recover from the ransomware attack . “ We expect doctor many services in the next few week , but some commotion may persist for foresighted , ” the statement said .

“ In the meanwhile , we ’ve taken targeted protective measures to ensure the integrity of our systems , and we ’re continuing to investigate the onrush with the sustenance of [ National Cyber Security Centre ] , the Metropolitan Police and cybersecurity specialist . ”

Why the public sphere is an easy mark for ransomware