Skip to content

Kent District Library ransomware disrupts branches and services

Summary

Kent District Library logo

Kent District Library disclosed a ransomware event after a computer outage beginning April 24, 2026 closed all 22 branches and disrupted public access to computers, printing and other services. Most services were restored by July 9, but KDL still reported limited printing and unavailable gaming labs while recovery work continued.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

Data impacts

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

Operational impacts

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Facility closure

    One or more offices, schools, clinics, stores, plants, branches, or other facilities closed because of the incident.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

Incident narrative

Analyst assessment

Our April 27 report said Kent District Library’s computer systems went down, branches closed across Kent County, and the library later acknowledged a ransomware event affecting the operability of certain systems and services. Independent local reporting from WGVU News likewise reported that all 22 branches had been closed since April 24 and quoted KDL’s public characterization of the incident as ransomware.

Separately, DysruptionHub assesses with high confidence that Kent District Library experienced a confirmed ransomware incident beginning publicly on April 24, 2026. That assessment rests on KDL’s own ransomware acknowledgment and subsequent recovery statements. KDL’s recovery status page confirms that the incident was not a short-lived outage: by July 9, public computers and Wi-Fi were available at all branches, normal patron notifications and holds processing had resumed, and most printing, copying, scanning and faxing services had returned, but gaming labs remained unavailable, printing was still unavailable at the Kelloggsville Branch, printing volumes were limited, and restoration work continued.

Operational significance

The incident materially disrupted a countywide public library system. KDL’s 2024 community reporting describes the organization as a public library system serving more than 439,000 residents across 27 municipalities in Kent County through 20 branch libraries, an Express Library and a Bookmobile. The ransomware event initially forced systemwide branch closures and subsequently constrained access to public computers, printers, copiers and gaming labs even after branches began reopening.

The operational effect was broader than a website or isolated application failure. It restricted physical access to library facilities during the initial closure and later reduced services relied on for internet access, computing, printing, copying and other public functions. Online resources such as Libby, hoopla and Kanopy remained available during the early disruption, which limits the scope of the outage but does not negate the documented loss of in-branch services.

Confidence and uncertainty

Confidence is high that ransomware caused the disruption because KDL publicly described the incident as a ransomware event. The specific ransomware payload, intrusion vector and technical path into the environment remain undisclosed in the reviewed public record.

An external threat-intelligence report published May 11 said the Interlock ransomware group claimed responsibility for the attack and threatened release of sensitive financial and personal data. That is treated as a threat-actor claim rather than confirmed attribution. KDL has not publicly attributed the incident to Interlock in the reviewed sources, and the actor claim does not independently establish what data was actually obtained.

KDL’s July status page said its integrated library system, which manages patron records and borrowing, was not impacted. The library said its investigation was focused on non-ILS data and remained ongoing, and that it would notify affected parties if personal information was determined to have been affected. Data impact therefore remains unresolved despite the external actor claim.

Current status

KDL’s July 9 update documented substantial restoration but also continuing operational limitations. By August 8, 30 days had elapsed since that latest supported impact observation, and no newer operational update was found. The incident is therefore presumed resolved under the registry’s lifecycle standard, but it is not positively resolved because KDL has not published a final restoration statement.

Analytic gaps

The reviewed sources do not establish the initial access vector, exploited vulnerability, compromised credentials, malware deployment sequence, attacker dwell time, encryption scope, ransom demand, payment status, exact systems encrypted, volume or categories of any exfiltrated data, or a final restoration date. Interlock’s claimed responsibility has not been independently confirmed by KDL, and KDL’s investigation into possible effects on non-ILS information was still ongoing in the latest recovery statement reviewed.

Threat actor and claim

Listed as: Kent District LibrarySource: otherPublished:

Claim details

External threat-intelligence reporting says Interlock claimed responsibility on May 11, 2026 and threatened release of allegedly stolen data; KDL has not publicly confirmed the attribution in reviewed sources.

Organizations involved

Impacted locations

  • Ada Township, Michigan

    Amy Van Andel Library (Ada), 7215 Headley Street SE, Ada. WGVU reported the systemwide closure of all 22 branches beginning April 24.

  • Alpine Township, Michigan

    Alpine Township Branch, 5255 Alpine Ave. NW, Comstock Park. WGVU reported the systemwide closure of all 22 branches beginning April 24.

  • Bowne Township, Michigan

    Alto Branch, 6071 Linfield Ave. SE, Alto. WGVU reported the systemwide closure of all 22 branches beginning April 24.

  • Byron Township, Michigan

    Byron Township Branch, 8191 Byron Center Ave. SW, Byron Center. WGVU reported the systemwide closure of all 22 branches beginning April 24.

  • Caledonia Township, Michigan

    Caledonia Township Branch, 6260 92nd St. SE, Caledonia. WGVU reported the systemwide closure of all 22 branches beginning April 24.

  • Cascade Township, Michigan

    Cascade Township Branch, 2870 Jacksmith Ave. SE, Grand Rapids. WGVU reported the systemwide closure of all 22 branches beginning April 24.

  • East Grand Rapids, Michigan

    East Grand Rapids Branch, 746 Lakeside Drive SE. WGVU reported the systemwide closure of all 22 branches beginning April 24.

  • Gaines Township, Michigan

    Gaines Township Branch, 421 68th St. SE, Grand Rapids. WGVU reported the systemwide closure of all 22 branches beginning April 24.

  • Grandville, Michigan

    Grandville Branch, 4055 Maple St. SW. WGVU reported the systemwide closure of all 22 branches beginning April 24.

  • Grattan Township, Michigan

    Medium Confidence

    Grattan Township Express Library, 12050 Old Belding Road, Belding. KDL lists this self-service location in its current network; the systemwide outage and closure reporting did not distinguish the Express Library from the 20 public branches.

  • Kent City, Michigan

    Tyrone Township Branch, 43 S. Main St., Kent City. WGVU reported the systemwide closure of all 22 branches beginning April 24.

  • Kentwood, Michigan

    Kentwood (Richard L. Root) Branch, 4950 Breton SE. WGVU reported the systemwide closure of all 22 branches beginning April 24.

  • Lowell, Michigan

    Englehardt (Lowell) Branch, 200 N. Monroe St. WGVU reported the systemwide closure of all 22 branches beginning April 24.

  • Plainfield Township, Michigan

    Represents Comstock Park Branch, 3943 W. River Dr. NE; Plainfield Township Branch, 2650 5 Mile Rd. NE; and KDL Service and Meeting Center, 814 West River Center Drive NE. The two public branches were within the reported systemwide closure; the administrative and IT center is included as the system support site affected by the ransomware response.

  • Rockford, Michigan

    Krause Branch in Rockford. KDL currently lists the temporary location at 220 N. Monroe St.; the incident relationship is to Rockford, where the affected branch operated before and after its relocation.

  • Sand Lake, Michigan

    Nelson Township Branch, 88 Eighth St., Sand Lake. WGVU reported the systemwide closure of all 22 branches beginning April 24.

  • Spencer Township, Michigan

    Spencer Township Branch, 14960 Meddler Ave., Gowen. WGVU reported the systemwide closure of all 22 branches beginning April 24.

  • Walker, Michigan

    Walker Branch in Walker. KDL currently lists the temporary location at 445 Standale Plaza NW; the incident relationship is to Walker, where the affected branch operated before and after its relocation.

  • Wyoming, Michigan

    Represents Kelloggsville Branch, 4787 Division Ave. S, and Wyoming Branch, 3350 Michael Ave. SW. Both public branches fall within WGVU's reported systemwide closure; KDL still documented service limitations at Kelloggsville on July 9.

Sources

Ransomware closes Kent District Library branches in Michigan

DysruptionHub reported that Kent District Library said a ransomware event caused a computer outage that closed branches across Kent County. The report documented an April 24 start to the outage, initial branch closures, and limited reopening plans in which public computers, printers, copiers and gaming labs remained unavailable.

Cyber attack shuts down Kent District Libraries

WGVU reported that all 22 Kent District Library branches had been closed since April 24 after a network outage. It quoted KDL saying it was investigating a recently discovered ransomware event affecting the operability of certain systems and services and was working with forensic and cybersecurity specialists.

Interlock Ransomware Group Targets Kent District Library

DeXpose reported that on May 11 the Interlock ransomware group claimed responsibility for the Kent District Library attack and threatened to release allegedly stolen sensitive financial and personal data. This is treated as external threat-actor reporting, not victim-confirmed attribution or confirmed data theft.

Reopening - Current Service Status at KDL

KDL’s July 9 status said public computers and Wi-Fi were available at all branches and normal holds processing had resumed, but gaming labs remained unavailable, printing remained unavailable at Kelloggsville, printing was limited, and restoration work continued. KDL also said its integrated library system was not impacted and its investigation into non-ILS data remained ongoing.

See something that needs correction?

Signed-in members can report an error, update, or missing source.