On 28 October 2023 it became clear that the British Library had been hit by ransomware attributed to Rhysida, compromising most of its online systems. Forensic analysis indicated the attackers had gained access at least three days earlier and conducted reconnaissance.
The Library subsequently published a detailed report on the causes, the nature of the attack and its recovery. It identified the likely entry as a terminal server used for remote access by trusted partners, and the absence of multi-factor authentication on that server as a contributing factor. Among the lessons it drew was the necessity of network segmentation, on the reasoning that no perimeter can be made entirely secure.
This Is The File That Answers The Audit
We have recorded at 26-0802 that 251 of its files establish no entry route, because the affected organisation did not say and no outside party could. That audit is the desk’s standing complaint about its own source material.
The British Library published the route, the missing control, the reconnaissance period and its own judgement about what it had got wrong. It did this having gained nothing commercially and having exposed itself to criticism, and we should be explicit that this is the standard the rest of the record fails to meet.
The Catalogue Is The Collection
A national library’s catalogue is not a website. It is the index by which physical holdings are located, requested and retrieved, and without it the items still exist and cannot practically be found.
We have argued at 24-1231 and 22-0224 that availability harm is uncounted, and this is an unusually pure case: nothing was destroyed, and the use of a national collection was suspended for researchers who had planned work around it. No breach regime has a field for a thesis delayed by a year.
Trusted Partner Access, Without The Second Factor
The route was a remote access path built for external collaborators — legitimate, necessary, and outside the population most identity controls are designed around.
We have recorded the same gap at 22-0120, where an outsourced support desk held the account that mattered, and at 23-0907. Partner access is granted by one team, inherited by another, and reviewed by nobody, and we keep finding it at the start of the sequence.
Compiled from the British Library’s published incident report and contemporaneous reporting and analysis of it, listed below. This desk has not independently verified the forensic conclusions and relies on the organisation’s own account, which is the point of the file. No figure for affected individuals or for total cost is carried here. Graded high. Corrections: corrections@forensicpost.com.
- Details and Lessons Learned From the Ransomware Attack on the British LibrarySecurityWeek
- Full transparency: 10 lessons from the cyber attack on the British LibraryIMD
- The 2023 Rhysida Ransomware Attack on the British Library: Prioritisation, Expertise, and Funding IssuesInformation Technology and Libraries