The Qilin ransomware group targeted Lee Enterprises, causing a substantial data breach. The attackers exfiltrated 350GB, including financial records, journalist payments, and tactics, leading to publication disruptions and subscriber access issues across Lee Enterprises' 79 newspapers. The attack compromised critical applications and encrypted data, severely affecting the company's operations and potentially its reputation. Forensic analysis is underway to assess the extent of sensitive or personally identifiable information compromised. The threat of data leakage looms with a set date for public disclosure.
TPRM report: https://scoringcyber.rankiteo.com/company/lee-enterprises
"id": "lee000030425",
"linkid": "lee-enterprises",
"type": "Ransomware",
"date": "3/2025",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization’s existence"
{'affected_entities': [{'industry': 'Media',
'name': 'Lee Enterprises',
'type': 'Company'}],
'data_breach': {'data_encryption': 'encrypted data',
'data_exfiltration': '350GB',
'type_of_data_compromised': ['financial records',
'journalist payments',
'tactics',
'personally identifiable '
'information']},
'description': 'The Qilin ransomware group targeted Lee Enterprises, causing '
'a substantial data breach. The attackers exfiltrated 350GB, '
'including financial records, journalist payments, and '
'tactics, leading to publication disruptions and subscriber '
"access issues across Lee Enterprises' 79 newspapers. The "
'attack compromised critical applications and encrypted data, '
"severely affecting the company's operations and potentially "
'its reputation. Forensic analysis is underway to assess the '
'extent of sensitive or personally identifiable information '
'compromised. The threat of data leakage looms with a set date '
'for public disclosure.',
'impact': {'brand_reputation_impact': 'potentially its reputation',
'data_compromised': ['financial records',
'journalist payments',
'tactics',
'personally identifiable information'],
'operational_impact': ['publication disruptions',
'subscriber access issues'],
'systems_affected': ['critical applications']},
'investigation_status': 'Forensic analysis is underway',
'ransomware': {'data_encryption': 'encrypted data',
'data_exfiltration': '350GB',
'ransomware_strain': 'Qilin'},
'threat_actor': 'Qilin ransomware group',
'title': 'Qilin Ransomware Attack on Lee Enterprises',
'type': 'Ransomware'}