Cyber Incident Victim: Bartlett Public Library District
Date:
Nov 2019
Location:
United States of America
Summary
The Bartlett Public Library District experienced a ransomware attack that disabled its computer systems, encrypting data and causing loss of access to files and emails. No private information was compromised as the institution did not store sensitive details like credit card numbers or social security data. Following recovery efforts, all systems were restored to functionality, with patrons instructed to report any account issues to Circulation services. The library expressed gratitude for patience during the incident and apologized for inconveniences caused.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On November 30, 2019, the Bartlett Public Library District experienced a disruptive ransomware attack that disabled its computer systems. The malware encrypted the library’s data, rendering files and emails inaccessible to staff and patrons. This incident occurred on a Saturday, immediately halting normal operations dependent on digital resources. The library confirmed no sensitive patron information—such as credit card details, Social Security numbers, or driver’s license data—was compromised, as it did not store such records. Operational disruptions persisted for nearly two weeks, affecting public access to library services reliant on the compromised systems. The library did not disclose the specific ransomware variant or the initial attack vector.

Recovery efforts concluded by December 12, 2019, when all systems were restored to functionality. The library directed patrons to contact its Circulation department at a provided phone number if they encountered lingering account issues post-restoration. Public communications emphasized gratitude for community patience and apologized for inconveniences caused by the outage. No ransom payment details or data destruction claims were disclosed in the library’s statement. The incident underscored operational vulnerabilities but did not result in identifiable breaches of personal or financial information due to the institution’s limited data retention practices.
