Filing: News Corp discovered a hack on January 20 that accessed emails and documents of some staff; an expert says the attack is likely linked to China
The attack, discovered on Jan. 20, affected publications including The Wall Street Journal, New York Post and the company's U.K. news operation
Context & Ripple Effects
News Corp’s incident joins a longer record of reported intrusions at major news organizations, including the FBI investigation into suspected intrusions at the New York Times and other outlets in 2016. The suspected national link differs, but the recurring target is the same: publishers’ internal systems.
The initial report concerned staff communications and documents across several News Corp titles. A later disclosure that the breach reached back to February 2020 and included some personal data broadens the significance from newsroom-system access to an employee-data exposure.
First-order effects
- Staff at The Wall Street Journal, New York Post and News Corp’s U.K. news operation had emails and documents in systems accessed by the attackers.
- News Corp’s later finding that some personal data, including Social Security numbers, was taken expands the affected material beyond the documents and emails identified in the initial disclosure.
Second-order effects
- For News Corp, the incident’s cross-publication scope means the exposure cannot be treated as a problem confined to one newsroom brand or to editorial files alone.
- The Guardian’s separate report of staff personal-data access after a ransomware attack reinforces that employee information is a shared security exposure for large publishers, alongside publication operations.
Third-order effects
- Reported intrusions at News Corp and other news organizations point to media companies as recurring targets for intelligence-oriented access, even where the alleged state affiliation differs by case.
- If this pattern persists, publisher cybersecurity will increasingly be organized around protecting shared staff identities, records and collaboration systems across multi-title groups rather than individual publication networks.
The trend: Major media groups are becoming recurring targets for intrusions that seek both newsroom materials and employee data across shared corporate systems.