Security

Cyber-crime

Data watchdog will leave British Library alone – further probes 'not worth our time'

No MFA? No problem – as long as you show you’ve learned your lesson


The UK's data protection overlord is not going to pursue any further investigation into the British Library's 2023 ransomware attack.

The Information Commissioner's Office (ICO) said it doesn't think its resources would be best spent on UK's national library, even though it was such a disaster due to MFA not being applied on an admin account.

Time to examine the anatomy of the British Library ransomware nightmare

READ MORE

"Having carefully considered this particular case, the Information Commissioner decided that, due to our current priorities, further investigation would not be the most effective use of our resources," a statement read.

"We have provided guidance to the British Library, which has reassured us about its commitment to continue to review and ensure that appropriate security measures are in place to protect people's data."

In the short post on the matter, the ICO – like many others in the cybersecurity community have done since the digital break in – lauded the British Library for its stellar approach to responsibly disclosing the ransomware attack.

From the start, the library issued regular, comprehensive updates about its recovery status, and in March 2024 it published a full review of the attack, outlining in depth the institution's IT weaknesses and the lessons it learned.

The ICO commended the British Library for its crisis comms, which major organizations are still struggling to emulate years later.

"Following the incident, the British Library published a cyber incident review in March 2024, which provided an overview of the cyber-attack and key lessons learnt to help other organisations that may experience similar incidents.  

"We commend the British Library for being open and transparent about its system vulnerabilities that contributed to the incident, the impact it has had, and the improvements made so far to protect people's personal information. "

The ICO's decision to leave the library in peace is taken at a time when internal resource constraints have contributed to performances that break the wrong records.

Earlier this month, the regulator revealed that it missed its complaint response targets by the biggest margin since it started tracking them, and due to current staffing levels, its performance is expected to decline further. 

Illustrating the size of the backlog, it said the goal is to respond to all complaints within 90 days, however, only 12.3 percent of complaints from the latest quarter were thoroughly assessed.

For context, the ICO has a lot on its plate. For a small-ish team operating out of a modest office in Wilmslow, a small English town in Cheshire East, it received more than 10,000 complaints during the most recent quarter, an increase of 746 compared to the three months prior.

The ICO confirmed it was hiring for various roles and "significant digital and process changes" were on the way, with the aim of easing the burden. ®

Send us news
7 Comments

Your ransomware nightmare just came true – now what?

Don't negotiate unless you must, and if so, drag it out as long as you can

Ransomware scum disrupted utility services with SimpleHelp attacks

Good news: The vendor patched the flaw in January. Bad news: Not everyone got the memo

Play ransomware crims exploit SimpleHelp flaw in double-extortion schemes

Recompiled binaries and phone threats used to boost the pressure

Crims defeat human intelligence with fake AI installers they poison with ransomware

Take care when downloading AI freebies, researcher tells The Register

Ransomware scum leak patient data after disrupting chemo treatments at Kettering

Literally adding insult to injury

Aussie businesses now have to fess up when they pay off ransomware crims

Move should help government track infections and plan new legislation

US medical org pays $50M+ to settle case after crims raided data and threatened to swat cancer patients

Cash splashed on damages, infrastructure improvements, and fraud monitoring

US infrastructure could crumble under cyberattack, ex-NSA advisor warns

PLUS: Doxxers jailed; Botnets bounce back; CISA questioned over app-vetting program closure; And more

Lumma infostealer takedown may have inflicted only a flesh wound as crew keeps pinching and selling data

PLUS: Ransomware gang using tech support scam; Czechia accuses China of infrastructure attack; And more!

DragonForce double-whammy: First hit an MSP, then use RMM software to push ransomware

SimpleHelp was the vector for the attack

Mysterious leaker GangExposed outs Conti kingpins in massive ransomware data dump

'It's a high-stakes intelligence war,' analyst explains

Data watchdog put cops on naughty step for lost CCTV footage

Greater Manchester Police reprimanded over hours of video that went AWOL