LEE ENTERPRISES, Inc

Feb 2025 · Graded Verified · Media and Entertainment · Government record

Incident summary

LEE ENTERPRISES, IncFeb 2025
$10.5M
Orders & sales lost
Business interruption
Lee Enterprises ran its 72 newspapers on shared core systems, so when ransomware encrypted them on February 3, 2025, distribution, billing, collections, and vendor payments stopped at once. The 350GB that left, by the attackers' count, held Social Security numbers and health details belonging mostly to Lee's own current and former employees, not its readers. Qilin claimed the theft and recovery ran about $2 million: one intrusion, and no internal boundary anywhere to slow it.
Attested: a published report credits an identifiable source for this figure.
Media and Entertainment
SEC 8-K, Item 1.05
Initial attack type not disclosed · Impact ransomware confirmed + data theft · Actor Qilin
Quantified 444 days after disclosure.
What the company has said it cost
The company’s own disclosed figure, as it changed over time. The loss on the record is this same figure, typed and categorized.
2026-05-08$10.5MVVerifiedSEC 10-Q ↗

About this record

This incident is on the public government record: an SEC 8-K filing or a state-regulator notification, graded Verified. Every figure links to the source it was read from; if we have read one wrong, tell us at info@hackerinahoodie.com. This index never sums figures across incidents. See the methodology.

Cite this incident

← The complete On the Government Record ledger ← Back to the index