News Corp says attackers behind a data breach the company disclosed in February 2022 gained access in February 2020, stealing some personal data including SSNs
Mass media and publishing giant News Corporation (News Corp) says that attackers behind a breach disclosed in 2022 first gained access …
Context & Ripple Effects
When News Corp disclosed the intrusion in a January 2022 filing describing a hack discovered on January 20, the picture was email and document access affecting some staff, with an expert flagging a likely link to China. The new disclosure rewrites that timeline: attackers were inside since February 2020 — roughly two years before discovery — and took personal data including Social Security numbers.
That puts News Corp alongside other publishers hit in the same window: The Guardian separately confirmed a December 2022 ransomware attack touching UK staff data, possibly via phishing. It also joins a broader run of long-dwell breaches ending in mass exposure of SSNs, like the National Public Data leak.
First-order effects
- Affected current and former News Corp staff now face identity-theft risk from stolen SSNs on top of the previously disclosed email exposure, forcing the company into expanded notification and credit-monitoring obligations beyond the original January 2022 disclosure.
- News Corp's security posture and incident-response timeline become the story: admitting two years of undetected access invites questions about why detection failed for so long after the initial discovery.
Second-order effects
- Rivals and peers hit in adjacent incidents — The Guardian with its December 2022 ransomware attack, background-check firms sitting on SSN troves — face renewed scrutiny of their own dwell times and what personal data their breaches exposed.
- Publishers' growing data-licensing relationships with AI companies raise the stakes of these disclosures, since buyers and partners now weigh an outlet's security record alongside its content.
Third-order effects
- If long-dwell breaches keep surfacing years after the fact — as with News Corp's 2020 entry point and NYC Health + Hospitals' multi-month access — pressure will build on regulators to tighten breach-disclosure timelines and penalize detection lag, not just the breach itself.
- SSNs stolen in one publisher breach compound the pooled exposure from leaks like National Public Data's, pushing organizations toward minimizing collection of government identifiers in the first place.
The trend: Enterprise breach disclosures are shifting from 'we were hacked' toward forensic reckonings with multi-year dwell times, exposing how long attackers can operate undetected before anyone notices.