British Library in Cyber Attack
The British Library says that user data was hacked in a cyber attack and data offered for sale on the dark web. This is a serious data breach for Britain’s largest library.
The attack on the British Library has affected users and staff alike.
The attack took place on 28th October 2023 and the Rhysida ransomware group is claiming responsibility. The group has also threatened to sell the data on the Dark Web.
Users of the library have been advised to change their passwords. Therefore, this is particularly important if, like many, your password is used on other websites.
Announcement
The British Library, the UK’s largest, posted on X on Monday evening, saying: “Following last week’s confirmation that this was a ransomware attack. However, we now have evidence that indicates the attackers might have copied some user data. Additional data appears to have been published on the dark web.
“We will continue to work with cybersecurity specialists to examine what this material is and we will be contacting our users to advise them of the practical steps they may need to take.”
Employees
The Rhysida ransomware group said it was behind the cyber attack.
It’s a troubling time for the employees who may be more at risk of identity fraud. However, it also could have been far worse had the hackers gained entry to more sensitive data.
Ransomware
The Rhysida ransomware group said that it was responsible for the attack and shared an image to its leak site on the Dark Web. The site showed various documents, some of which appear to be employment contracts and passports.
The data is to be auctioned for 20 BitCoin, which is a little over £595,000! The cyber criminals’ offer of “exclusive, unique and impressive data” was due to end on 27th November. The data would be sold to a single party winner. There is no information on whether the data was actually sold.
The Rhysida Ransomware Group are also behind a recent attack on the Chilean army. They also attacked the Portuguese city of Gondomar and the University of West of Scotland.
Summary
In our day to day activities, we are always concerned about businesses storing passport data. Whilst the NCSC (National Cyber Security Centre) work hard to understand the breach, the question of data retention remains. A passport is generally used to confirm that someone is who they say they are. It also helps with a ‘right to work’ confirmation. However, once it has been established that the employee is who they claim to be, surely this data can be deleted if an appropriate person confirms the relevant checks have been carried out. Passport data is toxic, particularly if copied or lost.
Do you keep passport data? If you want to discuss compliance to regulations and keeping data safe, please call us on 03333 22 1011. You can get in touch here. Or you can book a call here.
You can find out more about us here.

Leave a Reply