The British Library URL has been offline due to cyberattack for 10 days

A major ransomware attack has left the British Library’s website and many of its digital services offline for weeks, with recovery expected to take months and some user data already leaked onto the dark web. Commenters link the scale of the outage to long-term underinvestment in UK public-sector IT, weak backup and disaster-recovery practices, and a broader wave of cyberattacks hitting libraries and cultural institutions. The situation fuels wider debate over whether public bodies should ever be allowed to pay ransoms, how to fund and staff cybersecurity, and the risks of over-reliance on digital systems for critical archives.

Status and Scope of the Outage

  • British Library public website replaced by a “temporary holding page” describing a major cyberattack and long-term disruption.
  • Outage dates back to October and affects far more than the website: internal systems, personnel records, payments to authors, and digital services.
  • Attackers have released some user data on the dark web; the Library warns users to change reused passwords elsewhere, but its own password systems remain offline.
  • Partial physical services continue at buildings; exhibitions and in-person events largely still run.

Ransomware, Backups, and Recovery

  • Thread links the incident to a known ransomware group and notes a reported ransom demand (~£600k) that the Library was legally forbidden to pay.
  • Multiple comments question why organizations don’t “just restore from backups.”
  • Others explain:
    • Backups may be incomplete, too slow to restore, or themselves encrypted/corrupted.
    • Org‑wide restore can take months and isn’t often rehearsed (“black start” testing is rare).
    • Many backup architectures protect against hardware failure, not an attacker with privileged access.

Causes, Technology, and Targeting

  • Discussion suggests misconfiguration, under-resourced IT teams, and dependence on contractors as common denominators, rather than any single OS.
  • Netcraft data shows the public site on Linux; library systems (e.g., Aleph/Oracle on Unix) are mentioned. It’s unclear what exact systems were compromised.
  • Debate over whether ransomware is mainly a Windows problem; consensus is that all platforms are vulnerable, with Windows often targeted due to prevalence.

Libraries’ Role and Structural Underinvestment

  • Several comments argue UK heritage and library sectors suffer chronic underfunding, especially for cybersecurity.
  • Others note IT pay is “normal” by national standards but low relative to responsibility, and that bureaucracy promotes “talkers” over “doers.”
  • Broader critique that public libraries have become de facto social service hubs (internet, food, showers, drug first aid), stretching their mandate and resources.

Policy and Enforcement Ideas

  • Some argue ransom payments should always be illegal; others note life‑critical cases (e.g., hospitals) complicate this.
  • Calls for governments to aggressively trace and disrupt crypto ransom flows.
  • Side discussion on Ministry of Justice plans to digitize wills raises archival trade‑offs: cost vs. permanence of physical documents.