Skip to main content
Back to overview
Medium

Qilin Ransomware Group Claims Attack on Lee Enterprises, Leaks Stolen Data

Lee Enterprises, a major U.S.

Key points

  • Ransomware attack by the Qilin group.
  • 350 GB of data stolen from the media company.
  • Compromised data included government ID scans, financial documents, and contracts.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Ransomware

Threat source not confirmed

03

Potential impact

Data Exposure

Availability

Published
Feb 27, 2025
Updated
Jun 26, 2026
Confidence
Medium
Evidence
1 source

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch ransomware, endpoint compromise and business interruption exposure.

Business impact

Potential operational disruption
Impact area
Availability

Mentioned entities

LeeQilin Ransomware Group Claims AttackLee EnterprisesU.SQilinRansomwareCompromised

Quick context

Questions about this signal

What happened in this signal?

Lee Enterprises, a major U.S. media company, was targeted by the Qilin ransomware group. Qilin claimed responsibility on February 27, 2025, for an attack that disrupted operations and stole 350 GB of data, including government ID scans, financial spreadsheets, contracts, and non-disclosure agreements. The group threatened to leak all data by March 5, 2025.

When was this signal reported?

Shadow Tier lists Feb 27, 2025 as the signal date.

Which organization is connected to this signal?

Lee is the organization connected to this public signal.

Explore Lee
Which attack pattern is relevant?

This signal is connected to current ransomware incidents based on its reported incident context.

Explore current ransomware incidents
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence