Lee Enterprises blames cyberattack for encrypting critical systems as US newspaper outages drag on

Ransomware

  • Lee Enterprises filed a new report with the SEC
  • It confirmed suffering a ransomware attack and having files encrypted
  • As outage drags on, the investigation continues

The recent cyberattack on newspaper firm Lee Enterprises has turned out to be a ransomware attack, after all.

The company confirmed the news in a recent 8-K report filed with the US Securities and Exchange Commission (SEC), sharing more details about the attack, confirming that it was a ransomware strike.

“Preliminary investigations indicate that threat actors unlawfully accessed the company’s network, encrypted critical applications, and exfiltrated certain files,” it was said in the filing. “The company is actively conducting forensic analysis to determine whether sensitive data or personally identifiable information (PII) was compromised. At this time, no conclusive evidence has been identified, but the investigation remains ongoing.”

Advanced evasion techniques

The news comes roughly a week after it filed a 10-Q form with the SEC saying it suffered a cyberattack which forced it to pull parts of its IT infrastructure offline.

“On February 3, 2025, the company experienced a technology outage due to a cyber incident affecting certain business applications, resulting in an operational disruption,” it was said in the filing. “The company is actively investigating the incident, implementing recovery measures, and assessing the potential impact on its operations, financial condition, and internal controls.”

The incident impacted Lee’s operations, including distribution of products, billing, collections, and vendor payments, the company further stressed.

Distribution of print publications across its portfolio of products experienced delays, and online operations are partially limited. It still said that it now distributes all core products in “normal cadence”, although weekly and ancillary products have not yet been restored.

Some of the affected publications include the Winston-Salem Journal, Albany Democrat-Herald, Corvallis Gazette-Times, and others. A full list of affected outlets can be found on this link.

Via TechCrunch

You might also like

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Read more
Red padlock open on electric circuits network dark red background
Newspaper printing across US hit after Lee Enterprises says “cybersecurity event” disrupted operations
ransomware avast
Engineering giant ENGlobal confirms hackers hit internal data
Image of laptop infected with malware
Ransomware criminals are now sending their demands...by snail mail?
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
59 organizations reportedly victim to breaches caused by Cleo software bug
ID theft
Tata Technologies confirms ransomware attack, says investigation still ongoing
Lock on Laptop Screen
Clop ransomware lists Cleo cyberattack victims
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras