Lee Enterprises Faces Three Invasion-of-Privacy Lawsuits Amidst $9.5 Million Payout to Subscribers

Lee Enterprises, the Iowa-based owner of the St. Louis Post-Dispatch, is facing three invasion-of-privacy lawsuits from current or former employees, amidst a $9.5 million payout to subscribers alleging privacy violations. The lawsuits claim that the company's negligence and failure to secure employee data led to a cyberattack in February 2025, which compromised the private information of 39,779 individuals. The plaintiffs are seeking class-action status and damages on behalf of thousands of current and former Lee employees whose personal information was accessed by cybercriminals.

Key Takeaways:

  • Lee Enterprises has agreed to pay $9.5 million to subscribers alleging privacy violations and is facing three invasion-of-privacy lawsuits from current or former employees.
  • The three new lawsuits allege that Lee's negligence and failure to secure employee data led to a cyberattack in February 2025, which compromised the private information of 39,779 individuals.
  • The plaintiffs are seeking class-action status and damages on behalf of thousands of current and former Lee employees whose personal information was accessed by cybercriminals.
  • The data breach is alleged to have been caused by Lee's failure to properly secure and encrypt the files and file servers containing employee private information and by failing to train employees on standard cybersecurity practices.
  • The Qilin ransomware group has claimed credit for the attack and alleged that it gained access to 350 gigabytes of data, including contracts, financial spreadsheets, non-disclosure agreements, and other confidential files.
  • The lawsuits also mention a previous data breach in 2020, in which Iranian cybercriminals allegedly gained access to Lee's systems as part of a campaign to spread disinformation related to the 2020 presidential election.

Statistics:

  • $9.5 million: the amount paid by Lee Enterprises to subscribers alleging privacy violations.
  • 39,779: the number of individuals whose private information was compromised in the February 2025 cyberattack.
  • 350 gigabytes: the amount of data allegedly accessed by the Qilin ransomware group.
  • 2025: the year the data breach occurred.
  • 2020: the year a previous data breach occurred, in which Iranian cybercriminals allegedly gained access to Lee's systems.

Sources:

  • (https://www.justice.gov/archives/opa/pr/two-iranian-nationals-charged-cyber-enabled-disinformation-and-threat-campaign-designed)
  • (https://www.wsj.com/politics/national-security/iranian-hackers-broke-into-newspaper-publisher-lee-enterprises-ahead-of-2020-election-11637359741)
  • (https://iowacapitaldispatch.com/2022/12/22/lawsuit-accuses-iowa-newspaper-publisher-of-online-privacy-violations/)
  • (https://www.leeenterprises.com/investor-relations/sec-filings/2025-03-17-10k-2024-annual-report.pdf)