Cyber Incident Victim: Daviess County Public Library
Date:
May 2019
Location:
United States of America
Summary
A ransomware attack forced the closure of Daviess County Public Library, requiring staff to undertake restoration efforts across multiple days. Systems were compromised, prompting workers to restore backups, conduct inventory checks, and repair damages while updating patron accounts affected by the incident. The library also worked to determine the status of materials checked out or returned during the disruption caused by the attack.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
The Daviess County Public Library in Kentucky experienced a ransomware attack on or around Sunday, May 5, 2019, which disrupted library operations and forced a multi-day closure. The attack compromised library systems, preventing normal access to patron accounts and transaction records. By May 7, library staff initiated a three-day recovery effort focused on restoring functionality while the facility remained closed to the public through at least Thursday, May 9. Director Erin Waller confirmed the activation of backup systems to rebuild infrastructure, though the attack created significant operational gaps requiring manual reconciliation. Staff prioritized inventory assessments to identify materials checked out or returned during the disruption period starting from the attack date.

The incident necessitated comprehensive repairs to damaged systems alongside updates to patron account data that could not be processed during the outage. Library services were suspended entirely during the closure, directly impacting community access to resources and materials. Recovery efforts centered on verifying transactional records for accuracy, as the ransomware encryption likely prevented real-time tracking of loans and returns after the initial compromise. While backups enabled partial restoration, staff conducted manual audits to resolve discrepancies in circulation data accumulated between May 5 and the restoration period. The library’s response emphasized operational continuity through system repairs while addressing patron service interruptions caused by the forced closure. No further details regarding the ransomware variant, financial demands, or data exfiltration were disclosed in available reporting.
