Lee Enterprises, a prominent U.S. local newspaper publisher, became the target of a cyberattack that compromised their operations. The incident, attributed to the Qilin ransomware operation, involved the use of bogus online file converter sites disseminating malware and ransomware. This method enabled unauthorized access to the company's network, leading to potential theft of sensitive information, including Social Security numbers, user credentials, and financial account details. The FBI's Denver office has highlighted the global reach of this malicious scheme and has emphasized the importance of cybersecurity awareness to prevent such breaches.
Source: https://www.scworld.com/brief/fbi-online-file-converters-leveraged-for-malware-distribution
TPRM report: https://scoringcyber.rankiteo.com/company/lee-enterprises
"id": "lee603032425",
"linkid": "lee-enterprises",
"type": "Ransomware",
"date": "3/2025",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Media',
'location': 'United States',
'name': 'Lee Enterprises',
'type': 'Newspaper publisher'}],
'attack_vector': 'Bogus online file converter sites disseminating malware and '
'ransomware',
'data_breach': {'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Social Security numbers',
'User credentials',
'Financial account details']},
'description': 'Lee Enterprises, a prominent U.S. local newspaper publisher, '
'became the target of a cyberattack that compromised their '
'operations. The incident, attributed to the Qilin ransomware '
'operation, involved the use of bogus online file converter '
'sites disseminating malware and ransomware. This method '
"enabled unauthorized access to the company's network, leading "
'to potential theft of sensitive information, including Social '
'Security numbers, user credentials, and financial account '
"details. The FBI's Denver office has highlighted the global "
'reach of this malicious scheme and has emphasized the '
'importance of cybersecurity awareness to prevent such '
'breaches.',
'impact': {'data_compromised': ['Social Security numbers',
'User credentials',
'Financial account details']},
'initial_access_broker': {'entry_point': 'Bogus online file converter sites'},
'motivation': ['Data theft', 'Ransom'],
'ransomware': {'ransomware_strain': 'Qilin'},
'references': [{'source': "FBI's Denver office"}],
'response': {'law_enforcement_notified': "FBI's Denver office"},
'threat_actor': 'Qilin ransomware operation',
'title': 'Lee Enterprises Cyberattack',
'type': 'Ransomware'}