* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Wednesday, October 29, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    Caesars Entertainment (CZR) Reports Q3 Loss, Lags Revenue Estimates – Yahoo Finance

    Caesars Entertainment Stumbles in Q3, Falls Short of Revenue Goals

    Free Live Entertainment – Fremont Street Experience

    Enjoy Free Live Entertainment on Fremont Street Tonight!

    What to Know About ‘Good Morning America’s 50th Anniversary Episode – Wyoming News Now

    Celebrate the Milestone: Everything You Need to Know About Good Morning America’s 50th Anniversary Episode

    Dylan Efron suffers brutal nose injury in ‘DWTS’ rehearsals – Yahoo

    Dylan Efron Endures Painful Nose Injury During ‘DWTS’ Rehearsals

    Person shot, injured in parking lot of adult entertainment club in Gresham – KPTV

    Person Shot and Injured in Gresham Adult Entertainment Club Parking Lot

    Meet Belynda From ‘Married at First Sight’ Season 19: Age, Job, Instagram and More – Yahoo

    Meet Belynda from ‘Married at First Sight’ Season 19: Age, Career, Instagram & More Revealed!

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Nigeria’s government is using digital technology to repress citizens. A researcher explains how – The Conversation

    Nigeria’s government is using digital technology to repress citizens. A researcher explains how – The Conversation

    CPE Technology Berhad (KLSE:CPETECH) Has Affirmed Its Dividend Of MYR0.015 – Yahoo Finance

    CPE Technology Berhad (KLSE:CPETECH) Has Affirmed Its Dividend Of MYR0.015 – Yahoo Finance

    Researchers Discover New Bacterium That Turns Food Waste Into Energy – Technology Networks

    Scientists Unveil Breakthrough Bacterium That Transforms Food Waste Into Clean Energy

    Jim Cramer on GSI Technology: “That Thing is a Rocket Ship” – Yahoo Finance

    Jim Cramer Labels GSI Technology a “Rocket Ship” Poised for Takeoff

    The Anti-Tech Backlash Is Going to Grow Stronger – Jacobin

    The Anti-Tech Backlash Is Gaining Unstoppable Momentum

    Comments to EU Regarding the Draft Revised Technology Transfer Block Exemption Regulation and Technology Transfer Guidelines – Information Technology and Innovation Foundation

    Have Your Say: Share Your Thoughts on the Draft Revised Technology Transfer Block Exemption Regulation and Guidelines

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    Caesars Entertainment (CZR) Reports Q3 Loss, Lags Revenue Estimates – Yahoo Finance

    Caesars Entertainment Stumbles in Q3, Falls Short of Revenue Goals

    Free Live Entertainment – Fremont Street Experience

    Enjoy Free Live Entertainment on Fremont Street Tonight!

    What to Know About ‘Good Morning America’s 50th Anniversary Episode – Wyoming News Now

    Celebrate the Milestone: Everything You Need to Know About Good Morning America’s 50th Anniversary Episode

    Dylan Efron suffers brutal nose injury in ‘DWTS’ rehearsals – Yahoo

    Dylan Efron Endures Painful Nose Injury During ‘DWTS’ Rehearsals

    Person shot, injured in parking lot of adult entertainment club in Gresham – KPTV

    Person Shot and Injured in Gresham Adult Entertainment Club Parking Lot

    Meet Belynda From ‘Married at First Sight’ Season 19: Age, Job, Instagram and More – Yahoo

    Meet Belynda from ‘Married at First Sight’ Season 19: Age, Career, Instagram & More Revealed!

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Nigeria’s government is using digital technology to repress citizens. A researcher explains how – The Conversation

    Nigeria’s government is using digital technology to repress citizens. A researcher explains how – The Conversation

    CPE Technology Berhad (KLSE:CPETECH) Has Affirmed Its Dividend Of MYR0.015 – Yahoo Finance

    CPE Technology Berhad (KLSE:CPETECH) Has Affirmed Its Dividend Of MYR0.015 – Yahoo Finance

    Researchers Discover New Bacterium That Turns Food Waste Into Energy – Technology Networks

    Scientists Unveil Breakthrough Bacterium That Transforms Food Waste Into Clean Energy

    Jim Cramer on GSI Technology: “That Thing is a Rocket Ship” – Yahoo Finance

    Jim Cramer Labels GSI Technology a “Rocket Ship” Poised for Takeoff

    The Anti-Tech Backlash Is Going to Grow Stronger – Jacobin

    The Anti-Tech Backlash Is Gaining Unstoppable Momentum

    Comments to EU Regarding the Draft Revised Technology Transfer Block Exemption Regulation and Technology Transfer Guidelines – Information Technology and Innovation Foundation

    Have Your Say: Share Your Thoughts on the Draft Revised Technology Transfer Block Exemption Regulation and Guidelines

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

British Library opens up over ransomware attack to help others

March 14, 2024
in Technology
British Library opens up over ransomware attack to help others
Share on FacebookShare on Twitter


Alex Scroxton

By

Alex Scroxton,
Security Editor

Published: 13 Mar 2024 15:00

The British Library has published extensive details of its devastating experience at the hands of the Rhysida ransomware gang, revealing how the cyber criminals likely accessed its systems in the first place, the effects of the cyber attack, its response and the lessons it has learned.

The British Library’s systems were attacked by an affiliate of the Rhysida ransomware-as-a-service (RaaS) gang in the autumn of 2023, resulting in significant disruption to the organisation’s services, which has still not been fully resolved. The gang also stole 600GB of data, including details of service users, which was leaked when the British Library refused to engage.

Roly Keating, chief executive of the British Library, said the organisation hoped that opening up and opting for full transparency over the incident would help other organisations plan and protect themselves against similar cyber attacks.

“The threat of aggressive and disruptive cyber attacks is higher than it has ever been, and the organisations behind these attacks are increasingly advanced in their techniques and ruthless in their willingness to destroy whole technical systems,” he said.

“This is of especial importance for libraries and all those institutions who share our mission to collect and make accessible knowledge and culture in digital form, and preserve it for posterity. Though the motive of the attack on the British Library appears to have been purely monetary, it functioned as, effectively, an attack on access to knowledge.

“Wherever possible … we have tried to err on the side of openness, and not everything here makes comfortable reading for ourselves as an organisation,” said Keating. “We have significant lessons to learn.

“We are also conscious of our duty as data controllers and deeply regret the loss of control of some personal data, for which we apologise wholeheartedly to everyone affected,” he said. “If the outcome is increased resilience and protection against attack for the UK collections sector and others, then at least one good thing will have emerged from this deeply damaging criminal attack.”

Timeline of an attack

Such was the scale of the destruction they wrought, it may never be known precisely when the Rhysida gang gained access to its systems, but the British Library said that according to forensic analysis, it may have been on 25 October 2023, six days before it confirmed a cyber attack.

It revealed that its security manager received an alert about possible suspicious activity in the early hours of 26 October, but that this activity was blocked. The security manager escalated this for investigation, but no further malicious activity was found, and the account was then unblocked following a password reset. With the benefit of hindsight, this appears to have been Rhysida performing recon.

Rhysida’s exact entry point onto the network has also not been identified thanks to the damage they caused and the obfuscation they employed, but the first detected access was at the Terminal Services server, put in place in 2020 to enable external partners and IT support suppliers to access the network, which replaced an insecure remote access system in the early days of the Covid-19 pandemic. The investigators therefore believe Rhysida probably compromised a privileged account belonging to someone outside the British Library via a phishing or spear-phishing attack.

The British Library said it had been aware of the risk of something like that happening and had been in the process of reviewing and tightening its security provisions related to third-party access, but that this work had not been completed as of October 2023. Additionally, it had failed to apply multi-factor authentication (MFA) to the Terminal Services server – even though it had introduced MFA in 2020 across its wider estate, for reasons of cost and practicality, connectivity to its domain was out-of-scope of that project.

The British Library first learned it had been affected by a ransomware attack on the morning of Saturday 28 October, when a member of the IT team found they were unable to access the network. Over the subsequent hours, the incident was swiftly escalated and crisis management plans swung into action.

By that afternoon, the National Cyber Security Centre (NCSC) had been involved, and was assisting with incident handling and communications. It also learned that Jisc had identified unusual data traffic volumes leaving the Library’s estate at 1:30am on 28 October, likely the data exfiltration in progress.

A day later, on the afternoon of 29 October, it confirmed via X it was experiencing an outage, and two days later, on 31 October, it revealed this was the result of a cyber incident, at which point the incident began to pick up mainstream media coverage.

As to its engagement with Rhysida, the British Library confirmed in its report widespread speculation that it had not cooperated with its attackers.

“The Library has not made any payment to the criminal actors responsible for the attack, nor engaged with them in any way,” the report reads. “Ransomware gangs contemplating future attacks such as this on publicly funded institutions should be aware that the UK’s national policy, articulated by NCSC, is unambiguously clear that no such payments should be made.”

Effective crisis management

On the whole, the British Library said, its crisis-management plans performed well, with a practiced Gold/Silver command structure sliding into place, convening senior technical staff, external advisors, and the Library’s data protection officer and senior management, all of whom came together to coordinate the technical response, temporary workarounds where possible, and crisis communications.

Throughout the process, extensive support was provided both through the Department for Culture, Media and Sport (DCMS), and the NCSC, which helped the British Library keep readers, staff and stakeholders, including journalists, informed without sharing any detail that could help Rhysida. For internal comms, this meant resorting to cascading information through email or WhatsApp, while external updates came largely in the form of social media updates.

Once it was determined safe to do so, the British Library’s teams started contacting readers, supporters and others on its mailing lists, signposting NCSC guidance and incorporating user feedback to build more effective FAQs and keep its interim website updated. It was also able to keep a tight lid on what was told to whom when, and made sure all staff had sight of external comms prior to making them public.

It said proactive engagement with management and the Library’s trade unions also helped address staff concerns and effectively disseminate grassroots-level information and advice externally.

Rebuilding the British Library

With a diverse and complex technology estate and, as we have seen, a high number of legacy products, the British Library was always going to be faced with a complex reconstruction task in the case of a major event, and candidly, this appears to have been something the organisation was aware of before the attack, but it often lacked the funding or the impetus to do much about it.

It now believes the quirky nature of its IT estate contributed significantly to the severity of the attack, gifting Rhysida more access than they should have been able to have in a more modern design, among other things.

Making matters worse, besides the exfiltration of data and encryption of servers, Rhysida also destroyed servers to inhibit system recovery, and it was this stage of the attack that caused the most damage to the British Library, which now believes that although it will be possible to restore all of the data, it has no viable infrastructure to be able to do so – this system rebuild is expected to be completed in April 2024.

It admitted its vulnerability to such an attack had been exacerbated by reliance on old legacy applications that can’t now be fixed, either because they are completely obsolete, have been end-of-lifed, or cannot be run securely. Many systems need to be rebuilt from scratch.

But looking on the bright side, the British Library said it had a golden opportunity to transform how it uses and manages technology, adopting and embedding security best practice, and implementing policies and processes fit for a public organisation in the 2020s.

Indeed, it could go on to become a beacon of good practice for its peers. Among many other things, the British Library wants its new IT estate to incorporate best-practice network design, including segmentation and defence-in-depth approaches; a hybrid compute landscape; role-based access controls and least privilege policies; a more robust and resilient backup service with immutable, air-gapped and off-site copies; a holistic and integrated security suite covering the whole organisation, with managed security services for incident detection and response; MFA; improvements in incident, event and vulnerability management; and better IT lifecycle and software delivery governance.

As to things that readers will see, it also proposes to consolidate a number of key systems with more user-centric applications, centralising and replacing an old platform and legacy catalogues, reader registration, digital preservation and enquiries management. Multiple customer data systems will also be consolidated into a new data management and reporting architecture.

Lessons learned

Looking ahead, the British Library said there was still much work to be done, and new risks to be accounted for. Its change programme and new focus on cyber security will increase the need to foster an improved security culture internally, with management buy-in and ongoing support, for example.

Elsewhere, its already-stretched IT teams will need more capacity, and there are incumbent risks in moving more systems to the cloud, as it proposes to do.

Appropriate change management will need to be the watchword throughout the coming months, and this is set against a backdrop of increased risk from gangs such as Rhysida – having been a target once, many organisations frequently find other criminal groups take an interest.

The British Library said many of the other institutions overseen by DCMS and the wider cultural sector would likely have similar risks in terms of investment in security, legacy systems and overworked IT staff

“Investment, boldness and relentless focus are all needed to ensure that we are as secure as we can be against this threat, as the cost of investing in prevention is outweighed by the risk of failing to prevent,” the report reads. “Although the security measures we had in place on 28 October 2023 were extensive and had been accredited and stress-tested, with the benefit of hindsight, there is much we wish we had understood better or had prioritised differently.”

As such, the British Library has shared a list of early lessons that others may wish to incorporate into their thinking:

Enhance network monitoring on old networks. The British Library had a modern system in place but it couldn’t monitor or protect properly because the legacy network topology hindered its effectiveness;
Retain external expertise to improve resilience, speed of response and incident analysis capabilities early on;
Implement and enforce MFA across all systems, especially those used by suppliers;
Enhance intrusion response processes, conducting in-depth reviews after even the smallest signs of an intrusion;
Implement proper network segmentation. Had the British Library done this, Rhysida would likely have caused far less damage;
Implement and practice business continuity plans;
Try to think more holistically about risk, flagging any and all IT security risk to the appropriate levels. The British Library said it had been doing this well for out-of-appetite security risks, but had been missing a lot of low-level signals;
Keep on top of legacy systems and lifecycle management, and prioritise fixing issues that arise from legacy kit;
Enthusiastically invest in backups and recovery capabilities;
Clue the board in on risk to enable them to make better buying decisions, and ensure there is cyber-specific representation on the board;
Train staff properly, and regularly top up their knowledge;
Manage staff and user wellbeing;
Review acceptable personal use of IT. During the investigation, the British Library found Rhysida had been scanning the network specifically for keywords such as ‘passport’ or ‘personal’ to target personal items stored by staff, which was permitted at the time.
Collaborate and share information with others in your sector;
And finally, implement government standards and policies. The British Library in fact became Cyber Essentials Plus certified in 2019, but changes to the scheme in 2022 meant it dropped out of compliance because it needed to replace some legacy systems.

Read more on Data breach incident management and recovery


Leak of 26 billion records may prove to be ‘mother of all breaches’

AlexScroxton

By: Alex Scroxton


Neighbouring Kent councils hit by simultaneous cyber attacks

AlexScroxton

By: Alex Scroxton


British Library catalogues back online after ransomware attack

AlexScroxton

By: Alex Scroxton


British Library cyber attack explained: What you need to know

AlexScroxton

By: Alex Scroxton

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : Computer Weekly – https://www.computerweekly.com/news/366573453/British-Library-opens-up-over-ransomware-attack-to-help-others

Tags: Britishlibrarytechnology
Previous Post

Canucks become their own worst enemy in third period collapse

Next Post

Microsoft AI-powered cyber service to go live in April

Brad Paisley’s Incredible Connection to Historic 18-Inning Dodgers World Series Games – Bleacher Report

Brad Paisley’s Unbelievable Link to Epic 18-Inning Dodgers World Series Showdowns

October 29, 2025
Russia’s top banker warns Moscow is fighting the wrong economic battle – businessinsider.com

Russia’s Top Banker Sounds Alarm: Moscow Is Battling the Wrong Economic War

October 29, 2025
Caesars Entertainment (CZR) Reports Q3 Loss, Lags Revenue Estimates – Yahoo Finance

Caesars Entertainment Stumbles in Q3, Falls Short of Revenue Goals

October 29, 2025
New mental health support center opens in Brunswick – WGME

New Mental Health Support Center Opens Its Doors in Brunswick

October 29, 2025
Election 2025: Over 500,000 Coloradans have cast ballots – Colorado Politics

Over 500,000 Coloradans Have Already Cast Their Ballots for Election 2025

October 28, 2025
TwinEco: A unified framework for dynamic data-driven digital twins in ecology – ScienceDirect.com

TwinEco: Transforming Ecology Through Dynamic, Data-Driven Digital Twins

October 28, 2025
How to watch Tennessee high school girls soccer: Science Hill vs. Bearden, Oct. 28 – USA TODAY High School Sports

Don’t Miss the Exciting Tennessee High School Girls Soccer Showdown: Science Hill vs. Bearden on Oct. 28!

October 28, 2025
Scientists Just Mapped 2,600 Dreams – And Found Something Shocking – Yahoo

Scientists Map 2,600 Dreams and Uncover a Shocking Secret

October 28, 2025
Cat Learning “How To Get a Boyfriend” From Her Mom Is Adorably Hilarious – Yahoo

Cat’s Hilariously Adorable Journey Learning “How To Get a Boyfriend” From Her Mom

October 28, 2025
Nigeria’s government is using digital technology to repress citizens. A researcher explains how – The Conversation

Nigeria’s government is using digital technology to repress citizens. A researcher explains how – The Conversation

October 28, 2025

Categories

Archives

October 2025
M T W T F S S
 12345
6789101112
13141516171819
20212223242526
2728293031  
« Sep    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (890)
  • Economy (913)
  • Entertainment (21,784)
  • General (17,861)
  • Health (9,954)
  • Lifestyle (925)
  • News (22,149)
  • People (913)
  • Politics (923)
  • Science (16,123)
  • Sports (21,412)
  • Technology (15,892)
  • World (896)

Recent News

Brad Paisley’s Incredible Connection to Historic 18-Inning Dodgers World Series Games – Bleacher Report

Brad Paisley’s Unbelievable Link to Epic 18-Inning Dodgers World Series Showdowns

October 29, 2025
Russia’s top banker warns Moscow is fighting the wrong economic battle – businessinsider.com

Russia’s Top Banker Sounds Alarm: Moscow Is Battling the Wrong Economic War

October 29, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version