British Library: Finances remain healthy as ransomware recovery continues
- Reference: 1704719711
- News link: https://www.theregister.co.uk/2024/01/08/british_library_finances_remain_healthy/
- Source link:
The institution said in a statement today that the final costs remain "unconfirmed" and no additional bids for funding to support the rebuild have yet been made.
Reports at the weekend suggested the ransomware recovery costs were expected to run up to £7 million ($8.9 million), roughly ten times the original ransom sum, and could put a big dent in its cash reserves.
[1]
The Financial Times first [2]reported the now-disputed prediction of the library's recovery costs, a sum that would constitute around 40 percent of its rainy day funds.
[3]
[4]
Citing inaccuracies in wider reports, a British Library spokesperson told The Register : "The final costs of recovering from the recent cyber attack are still not confirmed. The British Library and its government sponsor, the Department for Culture, Media and Sport (DCMS), remain in close and regular contact. The Library always maintains its own financial reserve to help address unexpected issues and no bids for additional funding have been made at this stage."
The [5]October attack at the hands of Rhysida was hugely disruptive, forcing various systems at British Library sites in London and Yorkshire offline. It has resulted in a slow recovery - right now there is no end or estimated completion date in sight. Many services are still unavailable to library users as its staff work on rebuilding them.
[6]
Among the most notable absences is the library's online catalog, one of its flagship resources, which has remained offline since the start of the incident but is expected to return on 15 January as a reference-only version, CEO Sir Roly Keating confirmed.
It's just one of the services that are making a phased return amid ongoing work to build stop-gap workarounds that restore a level of operation to key library services, said Keating.
"Other interim services will include increased on-site access to our manuscripts and special collections, and a bespoke inter-library loan capability designed to serve key sectors such as health, higher education, and law," he [7]blogged .
[8]
"Each of these offerings will initially be somewhat different from our normal service, but together they will represent a crucial first stage on our road back to normality."
According to the British Library's [9]dedicated page for its cybersecurity incident, it expects a full recovery to take "several months" and points out that similar attacks elsewhere in the industry have taken longer than 12 months to fully remediate.
The Public Lending Right (PLR) service has also been affected as fallout continues from the cyber attack-related disruption, meaning some authors are not receiving the payments they are owed for their works being borrowed.
Run by the British Library, the PLR service pays authors 13p ($0.17) every time their work is borrowed, a sum that's capped at £6,600 ($8,386) annually.
The indefinite delays to payments are affecting only Irish recipients, with the Library unable to make December's payments or any in the near future, it confirmed last week.
"Once PLR services are restored, we'll send out statements and where payments are due, these will be made as soon as we can," the British Library said. "We know this may be worrying news and we're sorry if you have been affected by this delay.
"While we anticipate restoring many of our services in the next few weeks, some disruption may persist for several months. At this point, we're unable to say how long PLR services will be disrupted or whether UK PLR payments will be affected too."
The service disruption also means authors are currently unable to register for PLR payments at present, but the library expects to have a working registration system by June 30, the cutoff for registering for next year's payments.
Individuals are experiencing issues with logging into their PLR accounts and have been told some of their personal data, including names, email addresses, and postal addresses may have been copied from internal management databases.
According to The Authors' Licensing & Collecting Society (ALCS), the average earnings of a self-employed writer in the UK amounts to £7,000 ($8,900) a year, meaning the money earned via the PLR scheme could prove to be an impactful loss for some affected.
"We are making good progress towards issuing UK PLR payments before the end of March, in accordance with government legislation," a British Library spokesperson said today.
"We recognise the importance of these payments for authors, illustrators, translators, narrators, and all others who have contributed to books and are planning to issue a further update, with a finalized timeline, by the end of this month."
Months of disruption
The attack on the British Library started at the end of October after widespread issues impacted its St Pancras site in central London.
The website was downed, as were the on-site facilities including Wi-Fi, payments, reading rooms, staff email access, and order collection. Sir Keating recently described the incident as an "attack on knowledge."
A source told us at the time that its VMware ESXi servers were experiencing major issues as of October 28. The attack was later claimed by the Rhysida group – believed to be based in Russia.
It published 573 GB worth of stolen files belonging to the library, roughly 90 percent of the entire trove it stole. The group claimed the rest of the files had been sold in a private auction.
[10]UK government woefully unprepared for 'catastrophic' ransomware attack
[11]British Library begins contacting customers as Rhysida leaks data dump
[12]Cybersecurity snafu sends British Library back to the Dark Ages
[13]Mary Coombs, first woman commercial programmer, dies at 93
Before leaking the files, Rhysida originally advertised the sale of its entire haul with bids starting at 20 Bitcoin ($884,372 at today's exchange rate, around $760,000 at the time).
The British Library has said it is continuing to analyze the leaked files, a process which could take months, and will update individuals if investigators make any additional findings.
There is currently no evidence to suggest identity documents or financial information has been leaked, but [14]disclosure notices sent by the library to its customers in November suggested that "at a minimum" most had their names and email addresses stolen.
The Metropolitan Police and National Cybersecurity Centre (NCSC) said they would continue to support the library through its recovery and post-mortem of the incident. ®
Get our [15]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZZwqOrKKzWZPVXzUFf@u5AAAAEk&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://www.ft.com/content/4be5d468-0cc3-4881-a5fb-b5d0163de93e
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZZwqOrKKzWZPVXzUFf@u5AAAAEk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZZwqOrKKzWZPVXzUFf@u5AAAAEk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2023/10/31/british_library_it_outage/
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZZwqOrKKzWZPVXzUFf@u5AAAAEk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://blogs.bl.uk/living-knowledge/2023/12/knowledge-under-attack.html
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZZwqOrKKzWZPVXzUFf@u5AAAAEk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[9] https://www.bl.uk/cyber-incident/
[10] https://www.theregister.com/2023/12/14/uk_jcnss_ransomware_report/
[11] https://www.theregister.com/2023/11/29/british_library_begins_contacting_customers/
[12] https://www.theregister.com/2023/10/31/british_library_it_outage/
[13] https://www.theregister.com/2022/03/12/obit_mary_coombs/
[14] https://www.theregister.com/2023/11/29/british_library_begins_contacting_customers/
[15] https://whitepapers.theregister.com/
Re: Backups
I think so. Sounds like they are just rebuilding from the ground up. Including from-scratch rewrites of things like lending and booking !
Re: Backups
> Is this article saying that they didn't have backups?
Lots of verbiage that imparts nothing. What I want to know is, what does it run on.
Re: Backups
Anything, as long as it's patched this time ?
Re: Backups
You can have all the backups in the world - if you were compromised and then backed up, what do you think you're restoring apart from a known-compromised system?
Sounds far more like they are having to toothcomb everything they restore onto a fresh system, which can take forever for even a basic network.
Imagine I told you to reinstall all your servers without using backups (except for raw data) or your ready-made images? Or even connecting any server that hasn't been freshly-rebuilt.
Now think about things like SQL functions being compromised.
If you didn't notice you were open to compromise, don't know how you were compromised, and only know that the system you were backing up was definitely compromised, restoration is definitely not just a "click the button and cross your fingers" type of restore.
If anything, it's condemn every system you have immediately, back them up (what new data may or may not be required that hasn't made a backup yet?), wipe them out entirely, restore piecemeal and then try to rebuild every OS, service, database, configuration, integration, etc. from scratch without EVER letting the old machines back onto the new network directly.
Someone wasn't doing their job.
Ransomware shouldn't be this damaging. Insurance should cover the costs and there should be a full back up. You rip and replace hardware if you need to and reinstall. This time with patches and some security.
I have trouble understanding this.
As a (very) small-time sysadmin, I have trouble understanding why so many very large organisations are so hard-hit by ransomware attacks. Sure, the exfiltrated data is gone, nothing you can do about that. But what about service restoration? Is it really that hard to rebuild a server infrastructure and recover/restore data at least to a certain point?
I know, there's always the odd backup that didn't actually back up anything since the last twelve months, but that should be the exception. Am I the only one who believes in "If you haven't tested restoring, then you do not have a backup"? What's with multi-level, offline or write-once backups? Do they not have incident response and disaster recovery plans?
I would really love to learn more about the detailed problems they're battling. I can't just put all of this down to incompetence or negligence. Are modern infrastructures simply built in a way that makes recovery so hard? Are they all saving so hard that someone has to get the ten-year-old DR plans from the proverbial filing cabinet in a locked bathroom stall in the basement?
Re: I have trouble understanding this.
Much of this is down to cost.
Capability directly links to cost.
Let's say that you have stuff locally backed up to disk and it is still viable.
Do you delete everything that is encrypted and start again? You can but then you have to restore and validate everything to the point prior to encryption because some stuff will have survived will now not match stuff that was restored from a week ago. That in itself is a "crank-the-handle" exercise but you need the capacity to process and write the data.
Could you restore 500VMs and a few PB of data in 24 hours?
Highly unlikely.
Even if everything was in the cloud where you could expand resources to speed up the process there are still limits.
If there is an air-gapped copy in a cloud service or on tape then you are limited by what that solution can deliver. Bandwidth can be bought but then you need hardware to use it.
There will also be all the due diligence needed to make sure the source has been found and neutralised. It is no used restoring if it simply recurs because the source had not been sufficiently understood.
Re: I have trouble understanding this.
There's the problem of knowing how long malware has been lurking on a system before it went active. Are the backups actually clean or will the nasty stuff be restored to your Shiney (tm) new servers along with everything else?
Backups
Is this article saying that they didn't have backups?