DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Lee Enterprises Data Breach Affected 39,779 People After February 2025 Attack

Lee Enterprises’ February 3, 2025 attack affected 39,779 people—mostly current and former employees. Names and Social Security numbers were among the information involved, and Lee offered 12 months of IDX identity protection.
From TheFinanceBase Team4 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Lee Enterprises’ February 3, 2025 cybersecurity attack ultimately affected 39,779 people, a figure often rounded to 40,000. The affected population was primarily current and former employees. Lee said the information involved included names or other personal identifiers and Social Security numbers, and it offered 12 months of identity-theft protection and credit monitoring through IDX.

What happened to Lee Enterprises?

On February 3, 2025, attackers gained access to Lee Enterprises’ network, encrypted critical applications and exfiltrated files, according to the company’s Form 8-K disclosure. Lee described the event as a cybersecurity attack and activated its incident-response plan, hired outside cybersecurity specialists and notified law enforcement. The company’s filing is available at Lee’s investor-relations site.

Contemporaneous reporting described the incident as ransomware-related. The Qilin ransomware group claimed responsibility, but the sources available do not establish that claim as conclusive forensic attribution.

How many people were affected?

A breach notice filed with the Maine attorney general identifies 39,779 affected individuals. That is the precise number to use rather than the rounded “40,000” headline. The notice lists 13 Maine residents and characterizes the incident as external hacking. Most affected people were current or former Lee employees, not newspaper subscribers generally.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Maine filing lists May 28, 2025, as the date Lee discovered the personal-data breach and June 3, 2025, as the date consumer notices were sent. The notice is available through the Maine attorney general.

What information was involved?

The reported information included names or other personal identifiers and Social Security numbers. That description applies to the affected population collectively; it does not establish that every person had every listed data element exposed. The available filings do not establish exposure of driver’s-license numbers, financial-account details, medical records, passwords or dates of birth.

Unauthorized access or exfiltration means information may have been accessed or taken. It is not proof that every affected person experienced identity theft or fraud. The sources reviewed do not document confirmed misuse for each affected individual.

How did the attack disrupt Lee’s newspapers?

Lee reported disruption to systems supporting print-publication distribution, online operations, billing, collections and vendor payments. Reporting also described delayed payments for some freelancers and contractors.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

By February 12, 2025, Lee said its core products had returned to their normal distribution cadence. Weekly and ancillary products were still disrupted at that point; Lee said those products represented approximately 5% of operating revenue.

Timeline of the incident

Date Event
February 3, 2025 Cybersecurity attack and systems outage.
February 12, 2025 Core products were back to normal distribution; weekly and ancillary products remained affected.
February 14, 2025 Lee filed a Form 8-K describing network access, application encryption and file exfiltration.
May 28, 2025 Maine’s notice lists this as the personal-data breach discovery date.
June 3, 2025 Written notifications were sent to affected consumers.
June 12, 2025 Sarah Fetes filed the first reported employee data-breach complaint.
August 11, 2025 A consolidated complaint added five additional named plaintiffs.
February 11, 2026 Lee’s Form 10-Q described ongoing review, litigation and cumulative cyber-incident cash-flow losses.

What protection did Lee offer?

Lee said it sent written notices and offered affected individuals 12 months of identity-theft protection and credit monitoring through IDX. Monitoring can help identify certain suspicious activity; it does not prevent identity theft.

Steps for people who received a notice

  1. Verify that the notice came through an official Lee or settlement channel before entering personal information.
  2. Enroll in the IDX service if the enrollment period remains open and retain the notice and confirmation.
  3. Review credit reports and account statements for unfamiliar accounts, inquiries or transactions.
  4. Consider a fraud alert or a credit freeze with each of the three nationwide credit-reporting companies.
  5. Treat unexpected calls, emails or texts about the breach as possible phishing. Do not provide a Social Security number, password or payment to an unsolicited contact.
  6. Keep records of suspicious activity, communications and identity-theft-related expenses.

What lawsuits and settlement disclosures followed?

Sarah Fetes filed a complaint on June 12, 2025. A consolidated complaint filed August 11, 2025, named six plaintiffs and alleged that Lee failed to properly secure personally identifiable information.

In its February 11, 2026 Form 10-Q, Lee said the parties had reached a tentative settlement subject to court approval and objections. The filing anticipated final approval by August 2026, but that prediction is not proof that approval occurred. A final status requires a later court docket or official settlement-administrator notice. Lee’s filing is at Lee’s investor-relations site.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What did the breach cost Lee?

Lee separates expenses, cash-flow effects, insurance claims and reimbursements rather than reporting one definitive “cost.” Its February 2026 filing reported:

Measure Reported amount and qualification
Cyber-incident-related cash-flow losses $10.5 million through the February 11, 2026 filing.
Expenses recognized Approximately $3.7 million for the year ended September 28, 2025.
Insurance claims filed $6.8 million for business-interruption-related and other expenses.
Cyber-insurance deductible $500,000.
Insurance reimbursements At least $2 million received by the end of fiscal 2025, plus an additional $2 million in business-interruption reimbursements during the quarter ended December 28, 2025.

Insurance recoveries reduce unreimbursed losses but are not the same as eliminating the incident’s operational or financial impact.

What is known—and not known—about misuse?

The filings establish unauthorized access, file exfiltration and potential exposure of personal information. They do not establish that every affected person suffered identity theft, that all listed data elements were taken for every person, or that the information was fraudulently used. Readers should respond to warning signs while avoiding claims that misuse occurred without separate evidence.

The Bottom Line

Lee Enterprises’ February 3, 2025 ransomware-related incident was both an operational outage and a personal-data breach. The precise affected count is 39,779, primarily current and former employees; names and Social Security numbers were among the information involved. Lee offered one year of IDX monitoring, while the extent of confirmed misuse and the final status of the proposed settlement require separate verification.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.