Krum Public Library in Texas said computer access, printing and Wi-Fi were temporarily down after a May 14 ransomware attack, with checkout limited to five items.
The outage affected basic public library technology services before the city disclosed that the incident was ransomware. Krum is a Denton County city in the Dallas-Fort Worth area with an estimated 2025 population of 6,808.
Krum Public Library posted May 15 that “computer access, printing capability, and WiFi” were temporarily down and that checkout would be limited to five items, according to a library Facebook post.

The disruption came one day after the library said it detected unusual activity on its computer network May 14. In a June 3 public notification, the city said the library had confirmed it was the victim of a “sophisticated ransomware attack” carried out by cybercriminal threat actors.
The library also said in an FAQ that the attackers demanded an extortion payment and could retaliate by publishing data they claimed to have stolen. The library said it believed resources were better spent preventing another incident.
After publication, the NightSpire ransomware group listed Krum Public Library on its leak site, claiming to sell 50 GB of data allegedly taken from the library. The listing described the data as financial documents, HR data and supervisor information and was dated May 15. DysruptionHub viewed the listing, but could not independently verify the group’s claims or whether the data came from the library. Krum Public Library had not responded to an emailed request for comment by the time of publication.

The city said the attack was limited to the library environment and did not affect the broader city network or other city operations or services. The library said its network was secured and there has been no further unauthorized access.
The library said it did not permanently lose critical data because of backup technology and support from the city’s IT team and a managed services provider. A forensic investigation found that some files on the library network were accessed without authorization, and officials said they are reviewing those files to determine whether sensitive personal information was involved.
Krum officials said no Social Security numbers or personal financial account information belonging to employees, patrons or others were affected. The library said it was not aware of fraud or misuse tied to the incident and would notify potentially affected people if the file review identifies sensitive personal information.
The city said it notified federal law enforcement, including the FBI and Department of Homeland Security. The library said it was establishing a dedicated phone line for residents, employees and others with questions about the incident.
The Krum incident follows other cyber disruptions at public libraries. Fort Bend County Libraries in Texas said a February 2025 cybersecurity incident affected some services, including catalog and e-library access, and the county later approved nearly $2.6 million in cybersecurity contracts. Kent District Library in Michigan said an April 2026 ransomware event affected some systems and services, temporarily leaving public computers, printing and other branch technology unavailable or limited.
No threat actor was named in Krum’s notice. After publication, NightSpire claimed responsibility on its leak site, but officials have not confirmed a threat actor, said what systems were encrypted, disclosed how long the technology outage lasted or said whether any data has been published. The city said the library network is secure and broader city services were not affected.