Desk live·
ForensicPost
Ransomware/Availability/File 23-1028

British Library Published Its Own Breach Report Naming a Partner Server Without MFA

Rhysida reached the British Library through a terminal server used by trusted partners, without multi-factor authentication. The Library then did the thing almost nobody in this corpus does: it wrote the whole thing down and published it.

Constructed geometry · not a chart of case data
JurisdictionUnited KingdomLondonthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetBritish Library
ActorRhysida
S. Rosler12 min readConfidence: high3 sources reviewed

On 28 October 2023 it became clear that the British Library had been hit by ransomware attributed to Rhysida, compromising most of its online systems. Forensic analysis indicated the attackers had gained access at least three days earlier and conducted reconnaissance.

The Library subsequently published a detailed report on the causes, the nature of the attack and its recovery. It identified the likely entry as a terminal server used for remote access by trusted partners, and the absence of multi-factor authentication on that server as a contributing factor. Among the lessons it drew was the necessity of network segmentation, on the reasoning that no perimeter can be made entirely secure.

This Is The File That Answers The Audit

We have recorded at 26-0802 that 251 of its files establish no entry route, because the affected organisation did not say and no outside party could. That audit is the desk’s standing complaint about its own source material.

The British Library published the route, the missing control, the reconnaissance period and its own judgement about what it had got wrong. It did this having gained nothing commercially and having exposed itself to criticism, and we should be explicit that this is the standard the rest of the record fails to meet.

The Catalogue Is The Collection

A national library’s catalogue is not a website. It is the index by which physical holdings are located, requested and retrieved, and without it the items still exist and cannot practically be found.

We have argued at 24-1231 and 22-0224 that availability harm is uncounted, and this is an unusually pure case: nothing was destroyed, and the use of a national collection was suspended for researchers who had planned work around it. No breach regime has a field for a thesis delayed by a year.

Trusted Partner Access, Without The Second Factor

The route was a remote access path built for external collaborators — legitimate, necessary, and outside the population most identity controls are designed around.

We have recorded the same gap at 22-0120, where an outsourced support desk held the account that mattered, and at 23-0907. Partner access is granted by one team, inherited by another, and reviewed by nobody, and we keep finding it at the start of the sequence.

How we reported this

Compiled from the British Library’s published incident report and contemporaneous reporting and analysis of it, listed below. This desk has not independently verified the forensic conclusions and relies on the organisation’s own account, which is the point of the file. No figure for affected individuals or for total cost is carried here. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Details and Lessons Learned From the Ransomware Attack on the British LibrarySecurityWeek
  2. Full transparency: 10 lessons from the cyber attack on the British LibraryIMD
  3. The 2023 Rhysida Ransomware Attack on the British Library: Prioritisation, Expertise, and Funding IssuesInformation Technology and Libraries
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary