Cyberattack halted printing and publishing across Lee Enterprises newspapers
- Organization
- Lee Enterprises
- Exploit
- Ransomware
- Industry
- Media
Lee Enterprises, a newspaper publisher that runs roughly 350 print and digital outlets across 72 markets in 25 states, told customers on February 3, 2025 that a data centre hosting critical applications had gone offline. The company later confirmed the outage was the result of a cybersecurity event and filed a disclosure with the US Securities and Exchange Commission on February 7.
The disruption reached newsrooms directly. Journalists at Lee titles lost access to the page-building and publishing software used to assemble editions, and several papers printed smaller issues with altered layouts. The St. Louis Post-Dispatch said it did not miss a publication day, though most editions that week were affected. Other titles, including the Winston-Salem Journal, the Albany Democrat-Herald and the Corvallis Gazette-Times, saw print editions delayed, and subscriber account pages and e-edition access carried maintenance notices for weeks.
In a subsequent SEC filing, Lee said threat actors had unlawfully accessed its network, encrypted critical applications and exfiltrated certain files. The company said forensic analysis was still under way to establish whether personal or sensitive information had been taken. Executives declined to say publicly whether a ransom had been demanded, citing the ongoing investigation.
Lee notified law enforcement, engaged outside forensic specialists and warned investors that the incident was reasonably likely to have a material effect on its financial results. Distribution, billing, collections and vendor payments were all affected. As of mid-February 2025 the company expected outages to continue for several more weeks.
Updates
-
Lee Enterprises told the Maine attorney general that 39,779 people had their names and Social Security numbers stolen, the first victim count it put on the February intrusion. Notification letters went out on 3 June 2025.
-
Lee Enterprises said the personal information of 39,779 people, including names and Social Security numbers, may have been accessed, and offered 12 months of credit monitoring. The Qilin ransomware group had claimed the attack in March 2025.