Lee Enterprises said a cyberattack discovered on February 3, 2025, exposed personal information belonging to 39,779 people. The company’s initial filing described attackers encrypting critical applications and exfiltrating files; later notices identified names and Social Security numbers as information that may have been accessed. Settlement materials also say affected files may have contained medical information.
The incident is widely described as a ransomware attack, and the Qilin ransomware group reportedly claimed responsibility. However, Lee’s own SEC disclosure used the more cautious term “cybersecurity attack” and did not identify Qilin.
What happened to Lee Enterprises?
Lee Enterprises, a U.S. newspaper publisher, discovered unauthorized access to its network on February 3, 2025. According to its initial SEC filing, the attackers encrypted critical applications and exfiltrated files.
The disruption affected several business functions, including newspaper distribution, printing and digital operations, billing, collections and vendor payments. Lee said it activated its incident-response plan, hired outside cybersecurity specialists and notified law enforcement.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- Easily store and access 2TB to content on the go with the Seagate Portable Drive, a USB external hard drive
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
At first, Lee had not determined whether the accessed files contained sensitive personal information. That question was resolved only after a subsequent forensic investigation.
How many people were affected?
The exact number listed in a Maine attorney general filing is 39,779 people. “Nearly 40,000” is therefore a reasonable rounded description, but the incident did not affect exactly 40,000 people according to the regulatory notice.
The available records do not establish that all affected individuals were active Lee newspaper subscribers. The population appears to consist primarily of people whose personal information was stored in affected company systems, including current or former employees and other breach-notification recipients. A person should not assume they were included—or excluded—solely because they subscribed to a Lee publication.
When was the breach discovered?
There are several important dates:
- February 3, 2025: Lee discovered the cyberattack and operational disruption.
- May 28, 2025: The Maine filing lists this as the date Lee discovered the relevant personal information had been affected.
- June 3, 2025: Lee began sending written notices to affected individuals.
- June 4–5, 2025: Cybersecurity news outlets reported the personal-data breach publicly.
These dates should not be collapsed into a single event. Lee knew about the network intrusion in February, but its investigation into personal-data exposure continued for months.
Recommended Free Tools
Rank #2
- Easily store and access 5TB of content on the go with the Seagate portable drive, a USB external hard Drive
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
What information may have been exposed?
Reported and regulatory materials identify names and Social Security numbers among the information that may have been accessed or acquired without authorization. The official settlement FAQ says affected files may also have contained medical information.
That wording matters. The available notices do not establish that every affected person’s medical information was exposed, or that every listed data category was taken from every individual. Lee also said it had no evidence of misuse or attempted misuse of the potentially affected information at the time of the reported notices. That does not prove that misuse could not occur later.
Was the Lee incident definitely ransomware?
Lee’s SEC filing confirms the technical features commonly associated with a ransomware-and-extortion incident: attackers gained network access, encrypted critical applications and exfiltrated files.
Outside reporting from outlets including SecurityWeek and BleepingComputer described the event as ransomware. Those reports also said the Qilin ransomware group claimed responsibility and advertised stolen data.
Rank #3
- Easily store and access 1TB to content on the go with the Seagate Portable Drive, a USB external hard drive.Specific uses: Personal
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop. Reformatting may be required for Mac
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
The most precise description is that Lee’s filing confirmed encryption and data exfiltration, while outside reporting linked the attack to Qilin. The primary filing did not independently establish Qilin’s attribution.
What protection did Lee offer?
Lee offered affected individuals 12 months of credit monitoring and identity-protection services through IDX, according to the Maine filing.
Anyone who received a notice should use the activation instructions in that original letter or verify information through the official settlement website. Do not rely on unsolicited emails, text messages or social-media links claiming to provide Lee or IDX benefits. Breach-related phishing campaigns often imitate notification and claims pages.
The available materials do not establish whether the original IDX enrollment window remained open in September 2026. Readers should verify the current deadline directly rather than assuming enrollment is still available.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteRank #4
- Easily store and access 4TB of content on the go with the Seagate Portable Drive, a USB external hard drive.Specific uses: Personal
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
What lawsuit and settlement followed?
The case is Fetes et al. v. Lee Enterprises, Inc., No. 3:25-cv-00067-SMR-SBJ, in the U.S. District Court for the Southern District of Iowa. The lawsuit alleges that Lee failed to adequately protect personal information.
The settlement materials describe a class that includes people identified as affected by the incident, including individuals who received breach notices. Lee denies wrongdoing, and a settlement is not an admission of legal liability.
The settlement website listed a claim deadline of May 26, 2026, and a final approval hearing for June 30, 2026, at 10 a.m. Lee’s later SEC filing anticipated final approval by August 2026. The supplied records do not independently establish the court’s final ruling after that hearing, so readers should check the administrator’s current notice or the court docket for the latest status. Receiving a breach notice may establish potential class membership, but any payment depends on the settlement’s terms, valid claims, approval and any appeal process.
What affected people should do now
- Verify the notice. Confirm that communications came from Lee Enterprises or the official settlement administrator. Do not submit information through an unsolicited link.
- Use the IDX offer if available. Follow the instructions in the original Lee notice and confirm any deadline independently.
- Freeze your credit. A security freeze can restrict new-credit applications. Use the official pages for Equifax, Experian and TransUnion. A freeze is separate from Lee’s monitoring offer and is generally free.
- Review your credit reports. Get reports through AnnualCreditReport.com and look for unfamiliar accounts, inquiries or address changes. A clean report does not guarantee that no identity theft has occurred.
- Secure high-value accounts. Use unique passwords and multifactor authentication for email, payroll, banking, tax and health-benefit accounts. Protecting email is especially important because it can be used to reset other passwords.
- Watch for targeted fraud. Be alert for tax, employment, medical, account-takeover and Social Security-related scams. Never provide a verification code or password to an unsolicited caller.
- Report suspected identity theft. Use IdentityTheft.gov and contact the relevant bank, employer, insurer or financial institution promptly.
- Keep your records. Save the breach letter, settlement communications, claim confirmations and evidence of any losses. Do not pay an intermediary to freeze your credit or submit a claim.
Monitoring versus a credit freeze
Credit monitoring and a security freeze serve different purposes. Monitoring alerts you to certain changes, such as a new account or inquiry, after they appear in a reporting system. A freeze restricts prospective creditors from accessing your credit file for new-credit applications, subject to exceptions and the steps required by each bureau.
Best Value
- [Upgraded Version] - This external hard drive features a mirrored logo stripe combined with a striped anti-slip design, and the rounded corners of the casing make it easier to grip. The stripes also have a heat dissipation function, ensuring stable and fast data transfer.
- 【Ultra-thin and quiet】 - The motherboard adopts JMicron 578 noise-free solution, giving you a quiet working environment. Lightweight and portable size designed to fit in your pocket for easy portability.
- 【Ultra-Fast Data Transfers】 - Pairing this external hard drive with JMicron 578 solution USB 3.0 and USB 2.0 interfaces enables blazing-fast data transfer. It boasts theoretical read speeds of up to 125MB/s and write speeds of up to 103MB/s.
- 【Plug and Play】 - With no software to install, just plug it in and the drive is ready to use.The hard disk chip is wrapped with an aluminum anti-interference layer to increase heat dissipation and protect data.
- 【What You Get】 - 1 x Portable Hard Drive, 1 x USB 3.0 Cable, 1 x User Manual, Gift-type shell packaging ,Three-year manufacturer's warranty and free technical support services.
Neither measure prevents every form of fraud. A freeze may not stop someone from misusing information for a tax return, employment fraud, medical fraud or an existing-account takeover, which is why account security and ongoing review still matter.
What the incident means for subscribers and former employees
A former Lee employee can be affected even without a current relationship with the company if their information remained in Lee’s systems. Conversely, being a current newspaper subscriber alone does not establish that someone was included in the affected population.
The reliable way to determine individual status is to check for a direct breach notification and compare it with the official settlement-class description. Do not infer eligibility from a publication subscription, a social-media post or an unofficial claims website.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problems




