Data Breaches

Ransomware Group Takes Credit for Lee Enterprises Attack

The Qilin ransomware gang claims to have stolen 350 Gb of files from Lee Enterprises in the attack that caused newspaper disruptions.

Wired data leak

A ransomware gang has taken credit for the recent attack on Lee Enterprises, which caused disruptions at dozens of local newspapers.

The cyberattack came to light in early February, when the American media company, which owns roughly 350 weekly and specialty publications across 25 states, revealed that the incident had impacted business applications and resulted in operational disruptions. 

The attack reportedly impacted at least 75 newspapers across the US, including the distribution of print publications and online operations. 

The company later clarified that the attackers encrypted files and exfiltrated information from its systems, which indicated that it had been targeted in a ransomware attack.

On February 27, the Qilin ransomware group announced that it was behind the attack on Lee Enterprises in a post on its Tor-based leak website. This indicates that Lee Enterprises has refused to pay a ransom or negotiations have stalled. 

The hackers claimed to have obtained 350 Gb of files from Lee Enterprises systems, including “investor records, financial arrangements that raise questions, payments to journalists and publishers, funding for tailored news stories, and approaches to obtaining insider information”.

Advertisement. Scroll to continue reading.

The cybercriminals are threatening to leak the stolen data on March 5 unless a ransom is paid. To demonstrate their claims, they have published samples of the stolen data, including screenshots of passport and driver’s license scans, corporate documents, and spreadsheets. 

Qilin is a Russia-linked ransomware-as-a-service that appears to have been around since October 2022. It has targeted a wide range of organizations, including London hospitals, which were forced to cancel operations and appointments due to the attack. 

Qilin has to date published the names of roughly 300 victims on its leak website. The actual number of targeted organizations is likely significantly higher considering that many victims decide to pay a ransom — only those that refuse to pay up are named on leak sites. 

Related: Philadelphia Inquirer Hit by Cyberattack Causing Newspaper’s Largest Disruption in Decades

Related: Media Giant News Corp Discloses New Details of Data Breach

Related: New York Times Responds to Source Code Leak

Related Content

Data Breaches

The hack-and-leak group FulcrumSec claims to have stolen 1.3TB of data from the pharmaceutical giant.

Ransomware

Mackay Sugar was targeted in a cyberattack carried out by a threat group known as The Gentlemen.

Cybercrime

Oleksii Oleksiyovych Lytvynenko admitted to working on the development of a loader for the Conti gang.

Data Breaches

The pharmaceutical giant says the attackers gained access to personal data stored on the compromised systems. 

Data Breaches

French officials say roughly 73,000 government accounts were affected, while the threat actor claims to have stolen messages and user data from the sovereign...

Data Breaches

The extortion group threatens to leak 297 GB of data allegedly stolen from the Council of Europe, including employee personal information.

Data Breaches

Someone posted fake VRChat and Discord data breach reports on the system, prompting the Maine AG to take action.

Data Breaches

The ShinyHunters hacker group has taken credit for the attack, leaking more than 450,000 email addresses and other information.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version