CSIDB logo
Incident

Daviess County Public Library

Incident posture

Attack window
May 2019
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-04 00:00

Linked entities

Victim
Daviess County Public Library
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
May 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A ransomware attack forced the closure of Daviess County Public Library, requiring staff to undertake restoration efforts across multiple days. Systems were compromised, prompting workers to restore backups, conduct inventory checks, and repair damages while updating patron accounts affected by the incident. The library also worked to determine the status of materials checked out or returned during the disruption caused by the attack.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The Daviess County Public Library in Kentucky experienced a ransomware attack on or around Sunday, May 5, 2019, which disrupted library operations and forced a multi-day closure. The attack compromised library systems, preventing normal access to patron accounts and transaction records. By May 7, library staff initiated a three-day recovery effort focused on restoring functionality while the facility remained closed to the public through at least Thursday, May 9. Director Erin Waller confirmed the activation of backup systems to rebuild infrastructure, though the attack created significant operational gaps requiring manual reconciliation. Staff prioritized inventory assessments to identify materials checked out or returned during the disruption period starting from the attack date.

The incident necessitated comprehensive repairs to damaged systems alongside updates to patron account data that could not be processed during the outage. Library services were suspended entirely during the closure, directly impacting community access to resources and materials. Recovery efforts centered on verifying transactional records for accuracy, as the ransomware encryption likely prevented real-time tracking of loans and returns after the initial compromise. While backups enabled partial restoration, staff conducted manual audits to resolve discrepancies in circulation data accumulated between May 5 and the restoration period. The library’s response emphasized operational continuity through system repairs while addressing patron service interruptions caused by the forced closure. No further details regarding the ransomware variant, financial demands, or data exfiltration were disclosed in available reporting.

Sources

Sources available to members: 1 source.

CSIDB