British Library Cyber Attack: A 'Worst Incident in British History'
British Library Cyber Attack: A 'Worst Incident in British History'

Rhysida, a hacker gang thought to be Russian, had likely been infiltrating the British Library's digital systems for months before the attack became public on 28 October 2023, according to Enrico Mariconti, a lecturer in security and crime science at UCL. The group breached the library's virtual private network, gaining access to employees' passport scans and work contracts.

The hackers demanded a ransom of 20 bitcoins, around £600,000, for the stolen data. After the British Library refused to pay, Rhysida published nearly 500,000 files on the dark web, describing the data as 'exclusive, unique and impressive'. The attack left the library without Wi-Fi, computer access, and even phone lines, with many services still down three months later.

Ciaran Martin, former CEO of the National Cyber Security Centre, called it 'one of the worst cyber incidents in British history'. The library's vast collection of 170 million items remains largely inaccessible. The attack highlights the shift from solo hackers to organised crime rackets, with ransomware-as-a-service groups like Rhysida offering their services to anyone willing to pay.

Wide Pickt banner — collaborative shopping lists app for Telegram, phone mockup with grocery list

Mariconti believes the attack may have been a 'showcase' operation to advertise Rhysida's capabilities to potential clients. The British Library, while critically important, does not pose an immediate threat to public safety if breached, reducing government incentive to improve its IT security. The incident underscores the arms race between sophisticated hacker groups and the UK's weak cyber defences.

Pickt after-article banner — collaborative shopping lists app with family illustration