Malware attack on Tribune Publishing's network disrupts the printing and distribution of Saturday editions of LA Times, WSJ, NYT, and other papers
disable their ability to print newspapers!” http://www.latimes.com/... Matt Pearce / @mattdpearce : Some new details on the Ryuk malware attack that crippled newspapers across the U.S., and the workarounds that production staff developed to try to get the newspapers out anyway: http://www.latimes.com/... http://twitter.com/... Matthew Kirschenbaum / @mkirschenbaum : “Cyberattack” on a printing plant. “The computer problem shut down a number of crucial software systems that store news stories, photographs and administrative information, and made it difficult to create the plates used to print the papers at The Times' downtown plant.” http://twitter.com/... Matt Pearce / @mattdpearce : A cyberattack that appears to have originated from outside the United States caused major printing and delivery disruptions at several newspapers across the country on Saturday, including the http://www.latimes.com/... Eric Geller / @ericgeller : Exercise healthy skepticism about the possible implications of this story. It relies on one anonymous source whose technical expertise is unclear. The Pam Dixon quote at the end is nonsense. It doesn't take a sophisticated hacker to DDoS a newspaper platform. http://twitter.com/... Brian Stelter / @brianstelter : Source tells @LATimes “we believe the intention of the attack was to disable infrastructure, more specifically servers, as opposed to looking to steal info” http://twitter.com/... Raju Narisetti / @raju : As a follow-up, it is worth looking into whether Tribune Publishing, the former Tronc, cut back on digital security investments in what has been a very tumultuous fiscal management of that company. Most of their newspapers weren't available in Europe because of GDPR, for instance https://twitter.com/... Zeynep Tufekci / @zeynep : Oh wow. Though I'd be wary of quick attribution. “Cyberattacks” don't have to be sophisticated of foreign to do real damage. Heck, sometimes they don't even have to be attacks. But definitely worth learning what happened as best we can. http://twitter.com/... See also Mediagazer
Context & Ripple Effects
The attack hit Tribune Publishing's shared production backbone, not one newsroom: the malware shut down the software that stores stories, photographs, and administrative data, making it impossible to create the printing plates its plants depend on — so even the Wall Street Journal and New York Times, which don't share an owner with the Los Angeles Times, lost their Saturday editions. Production staff improvised manual workarounds to get papers out anyway.
This is not the first time US news organizations have been in attackers' crosshairs: the FBI was already investigating suspected state-linked intrusions at the New York Times and other outlets back in 2016 (cyber intrusions of NYT and other news orgs), and the 2017 ransomware wave that took down Maersk, WPP, and Merck showed how fast such attacks cascade through shared corporate IT (the ransomware attack that spread across Britain, the US, and Europe).
First-order effects
- Saturday print editions of the LA Times, WSJ, NYT, and other Tribune-printed papers were delayed or disrupted, hitting circulation revenue and readers on the same day across multiple mastheads.
- Production staff had to rebuild plate-making and page-flow processes by hand, since the compromised systems stored exactly the assets — stories, photos, administrative data — the presses consume.
Second-order effects
- Publishers that outsource printing to Tribune's network now face a vendor-risk question they hadn't priced: a single infected plant can take down several rival mastheads at once, pushing them to demand segmentation or dual-print arrangements.
- The incident hands ammunition to ransomware crews like Ryuk's operators, who target exactly this kind of just-in-time physical operation where downtime converts directly into ransom leverage.
Third-order effects
- If the pattern holds — state-linked intrusions at news orgs in 2016, ransomware against industrial operators in 2017, and now a print-network outage — newspaper production will be treated as critical infrastructure, with air-gapped or segmented prepress systems becoming a compliance expectation rather than an option.
- Shared-service consolidation in publishing creates correlated failure: the more mastheads ride one production stack, the more attractive that stack becomes as a single point of compromise, which may push the industry back toward distributed printing capacity.
The trend: Physical-output industries running on shared software backbones — shipping, healthcare, and now newspaper printing — are becoming preferred ransomware targets because downtime is intolerable and recovery is expensive.