Business Context and Reporting Period
Company: LEE ENTERPRISES, Inc.
Filing Type: Form 8-K (Current Report)
Date of Report: February 12, 2025
Event Date: February 3, 2025
Context: The Company reported a material cybersecurity incident involving a systems outage caused by a cyberattack. The incident disrupted operations including product distribution, billing, collections, and vendor payments.
Key Financial Metrics
The filing does not provide specific revenue, profit, cash flow, margin, debt, or liquidity figures for the reporting period. The document focuses on the operational and potential financial impact of the cybersecurity event.
- Revenue Impact: Weekly and ancillary products, representing approximately 5% of total operating revenue, have not been restored as of February 12, 2025.
- Financial Impact: The full scope is unknown, but the incident is reasonably likely to have a material impact on financial condition or results of operations.
- Insurance: The Company maintains a comprehensive cybersecurity insurance policy covering incident response, forensic investigations, business interruption, and regulatory fines, subject to limits and deductibles.
Material Changes and Operational Status
As of February 12, 2025, the Company has restored core products to normal distribution cadence. However, weekly and ancillary products remain offline. The attack involved unauthorized network access, encryption of critical applications, and exfiltration of certain files. Forensic analysis is ongoing to determine if sensitive data or personally identifiable information (PII) was compromised; no conclusive evidence has been identified to date.
Guidance, Outlook, and Risks
Outlook: The Company anticipates a phased recovery over the next several weeks. Temporary measures, such as manual transaction processing and alternative distribution channels, are in place to maintain critical functions.
Guidance: Updated financial guidance will be provided once a full assessment of the incident is completed.
Risks: Potential material financial impact, ongoing operational disruptions, regulatory notifications, and potential data breach liabilities. The investigation into data exfiltration remains active.
Investor Verification Checklist
- Confirm the final determination regarding the compromise of sensitive data or PII.
- Monitor the timeline for the full restoration of weekly and ancillary products (5% of revenue).
- Review the specific terms, limits, and deductibles of the cybersecurity insurance policy.
- Track regulatory notifications and any resulting fines or legal actions.
- Watch for updated financial guidance once the forensic assessment is complete.