Desk live·
ForensicPost
Ransomware/Aftermath/File 22-1220

Guardian Ransomware Exposed UK Staff Data and Closed Its London Office for Six Weeks

The Guardian was hit on 20 December 2022, most likely through a phishing message. UK staff data was taken, readers’ was not, and the London office stayed shut into February — with the organisation’s own journalists covering it.

Constructed geometry · not a chart of case data
JurisdictionUnited KingdomLondonthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetThe Guardian
ActorUnattributed
D. Kennedy10 min readConfidence: high3 sources reviewed

The Guardian was hit by ransomware on 20 December 2022, described by the organisation as a highly sophisticated attack involving unauthorised third-party access to parts of its network, most likely triggered by a successful phishing attempt in which someone was induced to download malware.

The personal data of UK staff was accessed. The organisation stated that readers’ and subscribers’ data was not, and that data belonging to Guardian US and Guardian Australia staff was believed unaffected. The London office remained closed into early February. The Information Commissioner’s Office and police were informed, and staff were told there was no evidence of data appearing online.

The Subject And The Reporter Were The Same Organisation

A news organisation covering its own compromise is in an unusual position: it holds the information, it has the means to publish, and it has every commercial reason not to.

The Guardian published, and we have recorded that as the exception it is. The desk’s standing complaint at 26-0802 is that 251 files establish no entry route because organisations do not say. Here the entry route — a phishing message that led to malware — was stated, along with what was and was not affected.

Staff Data, Again

The people whose records were taken were employees. Readers were spared, and the organisation said so early, which was the right priority for its audience and not for the people actually affected.

We have recorded employee data as the consistent casualty at 23-1219, where a game studio’s staff had passports published, and at 23-0808. For a newspaper the exposure has a further edge: a journalist’s employment record is not the same as a retailer’s payroll file, and no notification addresses that.

Six Weeks Without A Building

The office stayed shut into February while the newspaper continued publishing. That is a fortnight of incident and a month of consequence.

We have recorded physical and operational fallout at 22-1104, where a government worked from personal email, and at 23-0625. A closed office is not a data harm and it is not nothing, and it appears in no regime the desk reads.

How we reported this

Compiled from contemporaneous reporting, including the organisation’s own coverage and the statements its chief executive and editor-in-chief sent to staff, listed below. No ransomware operation is named — none was authoritatively identified. No count of affected staff was published and none is asserted. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. The Guardian confirms criminals accessed staff data in ransomware attackThe Record
  2. Guardian confirms Christmas 2022 cyber attack was ransomwareComputer Weekly
  3. The Guardian Confirms UK Members’ Data Was Accessed in Ransomware AttackInfosecurity Magazine
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary