In October 2023, the British Library, one of the largest libraries in the world, was breached by the Rhysida ransomware group. The attack encrypted systems across the organization, led to over 500,000 files being leaked, and set off a recovery effort that consumed a significant portion of the Library’s £17.5 million cash reserves. With no clear end date, this is a story of what could happen when all of an organization’s tech debt comes due at once. What sets this case apart is that the Library chose to publish a detailed and candid post-incident review. That transparency makes this case study possible.
Background and Context
Founded in 1973 and headquartered in London, the British Library is one of the world’s largest research libraries, holding over 170 million items and serving millions of people each year. The library serves academic researchers, historians, journalists, legal professionals, and genealogists, many of whom depend on remote access to digitized collections and an online catalogue. When those systems went down, researchers lost access to materials that, in some cases, exist nowhere else. For those working on time-sensitive projects - doctoral candidates, legal teams, and journalists on deadline - there was no equivalent substitute.

Narrative
In February 2020, the Library installed a Terminal Services server to allow remote access for IT administrator access. When the pandemic spread in the following months, remote usage expanded beyond its original scope. While Multi-Factor Authentication (MFA) was rolled out that same year, on-premise systems like the Terminal Services server were explicitly excluded due to concerns about cost and practicality.
In February 2020, the Library installed a Terminal Services server to allow remote access for IT administrator access. When the pandemic spread in the following months, remote usage expanded beyond its original scope. MFA was rolled out across cloud-based applications like Microsoft 365, but on-premises systems were left out of scope for MFA due to concerns about cost and practicality.
“…for reasons of practicality, cost and impact on ongoing Library programmes, it was decided at this time that connectivity to the British Library domain (including machine log-on access and access to on-premise servers) would be out of scope for MFA implementation…”
Rhysida, a ransomware-as-a-service (RaaS) group that emerged in mid-2023 claimed responsibility for the attack. This gang, new at the time, initially targeted hospitals, government agencies, and cultural institutions. Organizations with sensitive data and limited security resources tended to be their focus, and the British Library fit this profile.
The intrusion was discovered on October 28th, but forensic analysis determined attackers had likely been present on the network for days before detection. A precise entry date could not be established due to the destructive nature of the attack.
Once in the network, attackers moved laterally, ran keyword searches for terms like “passport” and “confidential,” and copied 22 databases before exfiltrating roughly 600GB of data. They then encrypted systems and issued a ransom demand of 20 bitcoin (~£600,000 at the time of attack). When it became clear that the Library would not pay, Rhysida listed the stolen files for auction on its dark web Data Leak Site (DLS). No buyer came forward, and 90% of the data was released to the public in late November 2023.
Impact
With an 2023 budget of £151.8 million and cash reserves of £17.5 million, it seems like the breach would be well in-hand with direct costs of only £2 million. The broader impact fell heavily on the researchers, academics, and students who relied on the Library’s services. When the Library published its incident review in March 2024, it projected that infrastructure rebuild would be complete by mid-April 2024.
The real impact is far more visible in the Library’s annual reports. The annual report that covers 2023 mentions the breach 63 times and dominates the report’s narrative. The following year’s report demonstrates that recovery is still well underway with 53 mentions. The most recent report (Annual Report 2025/26) suggests the pain is lessening with only 21 mentions, but it is still clear that some library systems have remained offline for years following the 2023 attack. Extensive tech debt is named as the primary reason recovery is taking so long.
“our reliance on legacy infrastructure is the primary contributor to the length of time that the Library will require to recover from the attack.”
The personal data of readers and visitors were published on Rhysida’s leak site, including names, email addresses, and in many cases, addresses and phone numbers. No financial data is believed to have been present in the stolen data.
The attack also paused hiring, delayed projects, and disrupted Library operations in significant ways. For example, the library spent nearly £1 million less on books as a result. As we publish this report, recovery continues.
Legacy and Takeaways
The Library’s transparency is commendable, though the report remains vague and withholds many details about the attacker’s methods and the impacted systems. The clearest explanation for this was an anticipated report from the UK’s ICO (Information Commissioner’s Office).
“The Library understand that the ICO will publish its findings on the incident in due course and the Library will abide by the recommendations of that report.” (from the Library’s 2023/2024 annual report)
However, in April 2024, the ICO announced that no report would be forthcoming, leaving the Library’s more sparse report as the sole account of the incident.
“Having carefully considered this particular case, the Information Commissioner decided that, due to our current priorities, further investigation would not be the most effective use of our resources. “
Though the report was limited, the UK’s National Cyber Security Centre (NCSC) publicly praised the report and held it up as an example for other organizations. If there is a silver lining, it is that the report admits that addressing tech debt and cultural challenges might have been impossible without the disruption of this attack.
On tech debt:
“Following the October 2023 attack, the Library has an opportunity to transform its use and management of technology across the organisation, to wholly adopt and embed best practice security mandates, and to implement fit for purpose policies and processes that will enable us to fully realise the benefits of our technology.”
On culture:
“The substantial disruption of the attack creates an opportunity to implement a significant number of changes to policy, processes, and technology that will address structural issues in ways that would previously have been too disruptive to countenance.”
As of 2026, no members of Rhysida have been publicly arrested or charged in connection with the British Library attack. Attribution in ransomware cases rarely translates quickly into prosecution, and Rhysida is no exception. The group remains active, with over 250 companies on their DLS today.
The Cyber Essentials Plus accreditation the Library had earned in 2019 had lapsed following changes to the standard in 2022, and the program to renew it was still underway at the time of the attack. Had that process had been completed, the lack of MFA on the Terminal Services server could have been remediated. More broadly, the decision to exclude on-premise systems from the MFA rollout was a documented choice made on the grounds of cost and practicality. The cost of closing that gap in 2020 could have been a fraction of the £27 million recovery effort that followed.
In conclusion, the British Library cyber incident serves as a reminder that organizations should not only consider how secure their infrastructure is, but also how recoverable it is.
Appendix A: Notable control failures and insights
While not a control, per se, tech debt hampered recovery far beyond what any organization would find acceptable and is the most significant takeaway for this breach1
Onsite backups were not immutable
Early indicators of the attack were detected, but staff wasn’t sufficiently trained to respond appropriately. For example: upon report of malicious activity on the Library network, the IT Security Manager performed a vulnerability scan an action that makes little sense given the situation.
Insufficient logging and protection of logs2
Lack of MFA on internet-exposed systems3
Lack of understanding of threat modeling and attack paths/methods - CIS standards and copy/paste prevention were implemented to mitigate a lack of MFA.
Inconsistent state of controls: MFA was deployed in cloud, but not on-prem; security software on laptops/desktops prevented ransomware, but different security software on servers failed to stop the same malware.
Acceptable use policy permitted employees to use Library resources to store personal data (which was included in the stolen data)
Entire network drives were exfiltrated without detection, using existing backup software
No payment data was compromised, due to controls in place to satisfy PCI DSS requirements4
All cloud-based systems were unaffected
Physical security systems were segmented and unaffected, allowing the Library to remain open to the public; public-facing and fundraising events were unaffected as well
Many systems were impossible to recover, due to their age and unsupported status
A program was established to recruit experienced cybersecurity professionals
Particular attention is to be given to change management, business continuity, and formal testing and exercise regimes
Cyber Essentials Plus accreditation was achieved in 2019, but lapsed in 2022 due to the standard and the Library’s aging infrastructure
A flat network gave attackers wider access than they otherwise might have had
Manual ETL data processes were exposed
“More than half of the risks and actions recorded on the Library’s risk registers have been impacted by the cyber-attack”
Page 15 of the 18-page report additionally lists the British Library’s own 11-point plan to implement more secure and resilient infrastructure.
Appendix B - The Library’s Lessons Learned
Page 17-18 of the Library’s report includes their key lessons learned. Of these sixteen lessons, we’ve pulled out seven that we think are both the most impactful and practical5.
Fully implement MFA
Enhance intrusion response processes
Practice comprehensive business continuity plans
Manage systems lifecycles to eliminate tech debt
Prioritize recovery alongside security
Regularly train all staff in evolving risks
Collaborate with sector peers
“…while we have secure copies of all our digital collections – both born-digital and digitised content, and the metadata that describes it – we have been hampered by the lack of viable infrastructure on which to restore it.”
“The investigation by our specialist cyber security advisers concluded that it is not possible to be certain of the exact point of entry to the Library’s network, due to both the severe damage caused to our server estate by the attack and anti-forensic measures taken by the attackers.”
“this terminal server was protected by firewalls and virus software, but access was not subject to Multi-Factor Authentication (MFA)”
Payments are outsourced and Library systems are regularly scanned for payment data. It is promptly removed if discovered.
Lessons like zero trust all the things and be aware of cybersecurity trends weren’t terribly actionable in our opinion



