Keskiviikkona 16.9.2026 klo 14.20 alkaen Koha-kirjastojärjestelmiin kohdistui laaja palvelunestohyökkäys.

Koha-kirjastojärjestelmää käytetään useissa Suomen kirjastoissa ja kirjastokimpoissa, myös Lumme-kirjastoissa. Hyökkäys oli peräisin useasta eri maasta, ja hyökkäys kohdistui yhteen tiettyyn maahan. Kirjastot eivät olleet hyökkäyksen lopullinen kohde, vaan välikätenä käytetty osapuoli. Hyökkäys saatiin hallintaan torstaina 17.9. aamulla noin kello 10.

Tämänhetkisen tiedon mukaan ei ole syytä epäillä, että järjestelmiin tallennetut tiedot olisivat vaarantuneet millään tavalla. Kyseessä oli palvelun häirintä sekä järjestelmiemme käyttö muiden järjestelmien häirintään.

Hyökkäyksen jälkihoito ei tässä vaiheessa edellytä mitään toimenpiteitä kirjastoilta eikä asiakkailta.

Tilanteen tarkempi jälkiselvittely jatkuu edelleen.

***

Starting at 14:20 on Wednesday, September 16, 2026, Koha library systems were subjected to a large-scale denial-of-service attack.

The Koha library system is used by numerous libraries and library consortia in Finland, including the Lumme libraries. The attack originated from multiple countries and targeted one specific country. The libraries were not the ultimate target of the attack but were used as an intermediary. The attack was brought under control by approximately 10:00 a.m. on Thursday, September 17.

Based on current information, there is no reason to suspect that data stored in the systems has been compromised in any way. The incident involved the disruption of service and the use of our systems to disrupt other systems.

At this stage, the aftermath of the attack does not require any action from libraries or customers.

A more detailed post-incident analysis is ongoing.