homehome Home chatchat Notifications


Cybercriminals attack British Library and demand ransom

Cyber criminals demand $750,000 as ransom for the stolen data.

Mihai Andrei
November 27, 2023 @ 1:57 pm

share Share

The British Library. Image in Creative Commons.

The British Library has been attacked by cyber criminals on the 31st of October. This resulted in the library’s website going down and “some” data being leaked. Some of the library’s systems are paralyzed, some of its WiFi has been compromised, and the attackers now want to sell the leaked data to the highest bidder.

The great library heist

The British Library holds over 200 million items, including books, patents, and scholarly papers. The library also archives the UK’s web. Just last year, it collected 68 terabytes of web data. Everything is kept on a whopping 625 kilometers of shelves spread over 14 large floors — nine above ground and five below. The library is also an important attraction for tourists, locals, and scholars alike. Just a stone’s throw away from London’s central rail station, it draws over 11 million visitors every year.

But visitors to the British Library were greeted with an unusual message.

I visited the British Library on the weekend and was greeted by this announcement.

The British Library also posted a longer message on its Twitter page:

“We’re continuing to experience a major technology outage as a result of a cyber-attack. This is affecting our website, online systems and services, as well as some onsite services,” the announcement read.”

“Having confirmed that this was a ransomware attack, we’re aware that some data has been leaked. As a precaution, we recommend that if you have a password for British Library services that you use for other websites or services, that you change it on those accounts.”

Who did it?

The attack appears to be coordinated by Rhysida, a cyber-criminal group that originates in Russia. The group (named after a centipede) took responsibility for the attack and posted low-resolution photos of what appear to be contracts and passports of employees. ZME Science could not verify whether these were authentic. However, the British Library said it was “aware that some data has been leaked, which appears to be from files relating to our internal HR information”.

Rhysida said the data was “exclusive, unique and impressive” and they will sell it to a single buyer.

This extortion technique is not new. Rafe Pilling, a cybersecurity expert quoted by The Guardian, said that this is “a classic example of a double extortion ransomware attack.” Essentially, the attackers are using the threat of leaking or selling stolen data as leverage to extort a payment.

Just this year, Rhysida attacked cities in Portugal, the Chilean army, and the Kuwait Ministry of Finance using the same approach. British authorities are investigating the case but it is not clear whether the library is actually considering paying the ransom.

Rhysida may be new to the public, but authorities in the UK and other countries have been keeping an eye on the group since 2021. However, this year, the group appears to have ramped up its operations. Just two weeks ago, on November 15, the FBI and the US Cybersecurity & Infrastructure Security Agency issued a warning on the threat posed by Rhysida

“Threat actors leveraging Rhysida ransomware are known to impact ‘targets of opportunity’, including victims in the education, healthcare, manufacturing, information technology, and government sectors,” the statement read.

Cyber attacks are on the rise

Global cyberattacks increased by 38% in 2022, compared to 2021, and 2023 seems to keep a pretty similar trend. In fact, the global cyberattack number will likely continue to rise for the next few years. A third of all companies appear to have been targeted by such an attack.

There are many reasons why this happens. The proliferation of commercial cyber tools is on the rise. AI has turbo-fueled attacks, and even tools like ChatGPT can be useful for cybercriminals. Furthermore, many institutions and companies don’t protect their online data all that much, leaving an invitation for such an attack to happen.

To make matters even more shocking, ransomware attacks are sometimes successful. The average ransomware payments in the UK have nearly doubled to £1.2m over the past year. British authorities discourage against yielding to hacker demands, but paying the ransom is not strictly illegal. Given the high profile of the British Library, this could be an important precedent for future attacks.

The library estimates that over the next few weeks, most of its services will return to their normal state. What will happen to the leaked data (and if said stolen data is indeed authentic) remains unclear.

share Share

Archaeologists Find Neanderthal Stone Tool Technology in China

A surprising cache of stone tools unearthed in China closely resembles Neanderthal tech from Ice Age Europe.

A Software Engineer Created a PDF Bigger Than the Universe and Yes It's Real

Forget country-sized PDFs — someone just made one bigger than the universe.

The World's Tiniest Pacemaker is Smaller Than a Grain of Rice. It's Injected with a Syringe and Works using Light

This new pacemaker is so small doctors could inject it directly into your heart.

Scientists Just Made Cement 17x Tougher — By Looking at Seashells

Cement is a carbon monster — but scientists are taking a cue from seashells to make it tougher, safer, and greener.

Three Secret Russian Satellites Moved Strangely in Orbit and Then Dropped an Unidentified Object

We may be witnessing a glimpse into space warfare.

Researchers Say They’ve Solved One of the Most Annoying Flaws in AI Art

A new method that could finally fix the bizarre distortions in AI-generated images when they're anything but square.

The small town in Germany where both the car and the bicycle were invented

In the quiet German town of Mannheim, two radical inventions—the bicycle and the automobile—took their first wobbly rides and forever changed how the world moves.

Scientists Created a Chymeric Mouse Using Billion-Year-Old Genes That Predate Animals

A mouse was born using prehistoric genes and the results could transform regenerative medicine.

Americans Will Spend 6.5 Billion Hours on Filing Taxes This Year and It’s Costing Them Big

The hidden cost of filing taxes is worse than you think.

Underwater Tool Use: These Rainbow-Colored Fish Smash Shells With Rocks

Wrasse fish crack open shells with rocks in behavior once thought exclusive to mammals and birds.