News Corp says attackers behind a data breach the company disclosed in February 2022 gained access in February 2020, stealing some personal data including SSNs
Mass media and publishing giant News Corporation (News Corp) says that attackers behind a breach disclosed in 2022 first gained access …
Context & Ripple Effects
News Corp's breach story keeps getting longer. The January 2022 filing that first disclosed the hack framed it as an intrusion discovered on January 20 targeting some staff emails and documents, with an outside expert assessing it as likely China-linked. What came after matters too: weeks earlier, The Guardian confirmed its own December 2022 ransomware attack touching UK staff data, possibly via phishing — major publishers were being hit repeatedly, not once.
The new disclosure changes the shape of the incident rather than just adding detail: access reportedly began in February 2020, meaning attackers dwelt roughly two years before News Corp noticed, and the stolen data includes Social Security numbers — deeper than the email-and-documents framing of the original filing. That puts this in the same family as National Public Data's SSN-bearing breach, where stolen personnel identifiers resurface as identity-fraud raw material.
First-order effects
- Current and former News Corp staff whose SSNs were taken now face identity-theft exposure the company's 2022 email-breach notification never flagged, forcing expanded credit-monitoring offers and re-notification.
- News Corp's security team must re-scope forensics around a February 2020 entry point, since every system touched during the two-year dwell is now potentially in scope.
Second-order effects
- Publishers hit in the same window — The Guardian's ransomware attack among them — face sharper board and insurer questions about dwell time and HR-data segregation, since News Corp's revised timeline shows how badly initial scope assessments can undershoot.
Third-order effects
- If multi-year dwell times keep surfacing at major employers, regulators and cyber-insurers are likely to push harder on detection-time metrics and on limiting SSNs as an internal identifier — the same SSN-exposure problem National Public Data's leaked database made systemic.
The trend: Breach disclosures keep expanding backward in time as forensic work lengthens, so initial notifications increasingly understated the theft — turning first announcements into rolling revisions years later.