British Library ransomware attack could cost up to £7m

The cost of recovering the British Library’s ransomware-stricken IT systems could be up to £7m, it has emerged

Alex Scroxton

By

Published: 08 Jan 2024 13:45

The cost of rebuilding the British Library’s systems following the October Rhysida ransomware attack is likely to hit between £6m and £7m, dwarfing the £650,000 ransom demand and burning through approximately 40% of the organisation’s unallocated cash reserves.

According to the Financial Times, the British Library is liaising with the Department for Culture, Media and Sport (DCMS), the government department to which it ultimately reports, but has not officially asked for financial assistance.

The newspaper claimed that a DCMS insider had told it that the institution – which holds hundreds of millions of works – would be expected to draw on its own financial reserves.

“The final costs of recovering from the recent cyber attack are still not confirmed. The British Library and its government sponsor, DCMS, remain in close and regular contact,” said a British Library spokesperson.

“The library always maintains its own financial reserve to help address unexpected issues and no bids for additional funding have been made at this stage,” they said.

The attack, which unfolded at the end of October 2023, saw the British Library’s website, online systems and services and on-site services knocked offline, causing widespread operational disruption.

It was confirmed to be a ransomware attack in mid-November, and a few days later, the emergent Rhysida ransomware group claimed responsibility and leaked some of the organisation’s internal human resources documents and threatening to auction more data.

The scope of the breach affecting the British Library subsequently widened, and the organisation confirmed at the end of November that the data stolen – which totalled 573GB comprising almost 500,000 files – did include the personal information of readers and visitors.

Writing in December, the library’s chief executive Roly Keating said: “Although this kind of attack was something we had prepared for and rehearsed, and had taken steps to guard against, it was no less of a shock when it happened.

“It is our purpose to provide access to a collection of 170 million items – open to all and free at the point of use, for research, inspiration and enjoyment – and we found ourselves, that first weekend, at the receiving end of a smash-and-grab operation, and a crude attempt at extortion.

“The people responsible for this cyber attack stand against everything that libraries represent: openness, empowerment, and access to knowledge,” said Keating.

As the disruption continues into 2024, its effects are now also beginning to impact wider life in the UK, with academics and researchers unable to complete aspects of their work such as grant applications, and authors left out of pocket thanks to the forced suspension of public lending right (PLR) payments.

PLR payments are the funds – measured in pennies up to a maximum value of £6,600 – paid out to authors when their works are borrowed from any library in the UK. The scheme distributed more than £6m in 2023 to thousands of authors across the country.

Speaking to the Observer, Society of Authors chair Joanne Harris described the PLR as a “welcome annual windfall” and a “tangible piece of validation” for authors whose works do not hit the bestseller lists or are otherwise out of the public eye.

Author Damian Barr added that the PLR scheme made a “big difference” to writers, particularly in the face of declining advances and cash-strapped publishers.

Read more on Data breach incident management and recovery

Read More
Maribel Schroeder

Latest

Too Little, Too Late? Sony Music Fires Off Blanket Warning Against the AI Mining of Its Catalog

Too little, too late? Sony Music has fired off a blanket warning against the unauthorized training of AI systems on its song catalog and other IP. The overarching Sony Music Group today made that clear-cut announcement on behalf of Sony Music Entertainment (SME) as well as its various subsidiaries and Sony Music Publishing (SMP). Spanning

Pandora Hits Back at MLC Lawsuit Over Streaming Royalties: ‘Legally Incoherent’

Music In a strongly-worded response, Pandora says the royalties...

Newsletter

Don't miss

Too Little, Too Late? Sony Music Fires Off Blanket Warning Against the AI Mining of Its Catalog

Too little, too late? Sony Music has fired off a blanket warning against the unauthorized training of AI systems on its song catalog and other IP. The overarching Sony Music Group today made that clear-cut announcement on behalf of Sony Music Entertainment (SME) as well as its various subsidiaries and Sony Music Publishing (SMP). Spanning

Pandora Hits Back at MLC Lawsuit Over Streaming Royalties: ‘Legally Incoherent’

Music In a strongly-worded response, Pandora says the royalties...

News24 Business | For R350 a month, residents of informal settlements can use a waterless toilet

Qaqamba Matundu Share your Subscriber Article You have 5 articles to share every month. Send this story to a friend! Loading, please wait... Subscribers can listen to this article A waterless toilet provides clean and safe sanitation for informal residents (Ntando Mbhele/ Supplied). A waterless flushing toilet, to help communities that lack water and sanitation

Want to succeed in business? Find a problem to solve | Anthony Tan and Amane Dannouni

Update requirements Looking for ted.com? v95+ v58+ v13+ v96+ v82+ Looks like your browser is out of date For questions contact us at support@ted.com

News24 Business | Garth Theunissen | SENS needs fixing, but the JSE disagrees

Subscribers can listen to this article The JSE building in Sandton. (Fivepointsix/Getty) While the JSE has made efforts to simplify its listing requirements, little evidence of this can be seen in many an indecipherable regulatory announcement. Given the plethora of scandals involving JSE-listed companies in recent years, perhaps it's time to consider some plainer language