Lee Enterprises discloses a material cybersecurity incident
What the filing says
On February 3, 2025, Lee Enterprises, Inc. ("Lee" or the "Company") experienced a systems outage caused by a cybersecurity attack. Upon discovery, Lee activated its incident response team, comprised of internal personnel and external cybersecurity experts retained to assist in addressing the incident. Preliminary investigations indicate that threat actors unlawfully accessed the Company's network, encrypted critical applications, and exfiltrated certain files.
Timeline
- Amended filing · Mar 6, 00:00 UTC
8-K/A: As previously disclosed in the Original Form 8-K, the Company experienced a system outage on February 3, 2025, caused by a cybersecurity attack by threat actors who unlawfully accessed the Company's network, encrypted critical applications, and exfiltrated certain files (the "Incident"). As of the date of this filing and because of the Company's remediation and other activities, the threat has been contained and the Company is working closely with third-party security vendors to restore automation of its business processes impacted by the Incident. Currently all products are being produced and distributed, although some limitations remain including limited depth of products due to tightened
Sources: vendors' own status pages, published postmortems and SEC 8-K Item 1.05 filings, read daily. Times as reported. Logos via logo.dev; trademarks belong to their owners.