/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

News Corp says attackers behind a data breach the company disclosed in February 2022 gained access in February 2020, stealing some personal data including SSNs

Mass media and publishing giant News Corporation (News Corp) says that attackers behind a breach disclosed in 2022 first gained access …

BleepingComputer Sergiu Gatlan

Context & Ripple Effects

When News Corp disclosed the intrusion in a January 2022 filing describing a hack discovered on January 20, the picture was email and document access affecting some staff, with an expert flagging a likely link to China. The new disclosure rewrites that timeline: attackers were inside since February 2020 — roughly two years before discovery — and took personal data including Social Security numbers.

That puts News Corp alongside other publishers hit in the same window: The Guardian separately confirmed a December 2022 ransomware attack touching UK staff data, possibly via phishing. It also joins a broader run of long-dwell breaches ending in mass exposure of SSNs, like the National Public Data leak.

First-order effects

  • Affected current and former News Corp staff now face identity-theft risk from stolen SSNs on top of the previously disclosed email exposure, forcing the company into expanded notification and credit-monitoring obligations beyond the original January 2022 disclosure.
  • News Corp's security posture and incident-response timeline become the story: admitting two years of undetected access invites questions about why detection failed for so long after the initial discovery.

Second-order effects

  • Rivals and peers hit in adjacent incidents — The Guardian with its December 2022 ransomware attack, background-check firms sitting on SSN troves — face renewed scrutiny of their own dwell times and what personal data their breaches exposed.
  • Publishers' growing data-licensing relationships with AI companies raise the stakes of these disclosures, since buyers and partners now weigh an outlet's security record alongside its content.

Third-order effects

  • If long-dwell breaches keep surfacing years after the fact — as with News Corp's 2020 entry point and NYC Health + Hospitals' multi-month access — pressure will build on regulators to tighten breach-disclosure timelines and penalize detection lag, not just the breach itself.
  • SSNs stolen in one publisher breach compound the pooled exposure from leaks like National Public Data's, pushing organizations toward minimizing collection of government identifiers in the first place.

The trend: Enterprise breach disclosures are shifting from 'we were hacked' toward forensic reckonings with multi-year dwell times, exposing how long attackers can operate undetected before anyone notices.

Discussion

  • @acfou Dr Augustine Fou on x
    required disclosures are useful, as in this case. News Corp says state hackers were on its network for two years https://www.bleepingcomputer.com/ ...
  • @pohlprof Prof Dr Hartmut Pohl on x
    Hacker: Two years in the internal network before the detected attack . https://www.bleepingcomputer.com/ ...
  • @tresronours @tresronours on x
    Attackers were 2 years in the systems before breach got detected. “News Corp says state hackers were on its network for two years” What's you security posture ? Do you have proper detection (and response) in place. connected=hacked #cybersecurity https://www.bleepingcomputer.com/…
  • @cybernewslive @cybernewslive on x
    @newscorp: 2 YEARS + 1 YEAR to report #CNL #CyberNewsLive #Cyber #CyberSecurity #CyberSecurityNews #DDoS #Extortion #Ransom #Phishing #Malware https://www.bleepingcomputer.com/ ... https://twitter.com/...
  • @tempkenalt @tempkenalt on x
    the publishing conglomerate, including The Wall Street Journal, the New York Post, and its U.K. news operations. " Feb 2020 to Jan 2022, an unauthorized party gained access to certain business documents and emails https://www.bleepingcomputer.com/ ...
  • @ctin_global @ctin_global on x
    Here is a great example of why log review and audit is important | https://www.bleepingcomputer.com/ ...