Menu
Browse

Cyber Incident Victim: Bartlett Public Library District

Date:

Nov 2019

Location:

United States of America

Summary

The Bartlett Public Library District experienced a ransomware attack that disabled its computer systems, encrypting data and causing loss of access to files and emails. No private information was compromised as the institution did not store sensitive details like credit card numbers or social security data. Following recovery efforts, all systems were restored to functionality, with patrons instructed to report any account issues to Circulation services. The library expressed gratitude for patience during the incident and apologized for inconveniences caused.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On November 30, 2019, the Bartlett Public Library District experienced a disruptive ransomware attack that disabled its computer systems. The malware encrypted the library’s data, rendering files and emails inaccessible to staff and patrons. This incident occurred on a Saturday, immediately halting normal operations dependent on digital resources. The library confirmed no sensitive patron information—such as credit card details, Social Security numbers, or driver’s license data—was compromised, as it did not store such records. Operational disruptions persisted for nearly two weeks, affecting public access to library services reliant on the compromised systems. The library did not disclose the specific ransomware variant or the initial attack vector.

Cyber Incident Image

Recovery efforts concluded by December 12, 2019, when all systems were restored to functionality. The library directed patrons to contact its Circulation department at a provided phone number if they encountered lingering account issues post-restoration. Public communications emphasized gratitude for community patience and apologized for inconveniences caused by the outage. No ransom payment details or data destruction claims were disclosed in the library’s statement. The incident underscored operational vulnerabilities but did not result in identifiable breaches of personal or financial information due to the institution’s limited data retention practices.

Sources
Sources available to members
1 source