The Guardian was hit by ransomware on 20 December 2022, described by the organisation as a highly sophisticated attack involving unauthorised third-party access to parts of its network, most likely triggered by a successful phishing attempt in which someone was induced to download malware.
The personal data of UK staff was accessed. The organisation stated that readers’ and subscribers’ data was not, and that data belonging to Guardian US and Guardian Australia staff was believed unaffected. The London office remained closed into early February. The Information Commissioner’s Office and police were informed, and staff were told there was no evidence of data appearing online.
The Subject And The Reporter Were The Same Organisation
A news organisation covering its own compromise is in an unusual position: it holds the information, it has the means to publish, and it has every commercial reason not to.
The Guardian published, and we have recorded that as the exception it is. The desk’s standing complaint at 26-0802 is that 251 files establish no entry route because organisations do not say. Here the entry route — a phishing message that led to malware — was stated, along with what was and was not affected.
Staff Data, Again
The people whose records were taken were employees. Readers were spared, and the organisation said so early, which was the right priority for its audience and not for the people actually affected.
We have recorded employee data as the consistent casualty at 23-1219, where a game studio’s staff had passports published, and at 23-0808. For a newspaper the exposure has a further edge: a journalist’s employment record is not the same as a retailer’s payroll file, and no notification addresses that.
Six Weeks Without A Building
The office stayed shut into February while the newspaper continued publishing. That is a fortnight of incident and a month of consequence.
We have recorded physical and operational fallout at 22-1104, where a government worked from personal email, and at 23-0625. A closed office is not a data harm and it is not nothing, and it appears in no regime the desk reads.
Compiled from contemporaneous reporting, including the organisation’s own coverage and the statements its chief executive and editor-in-chief sent to staff, listed below. No ransomware operation is named — none was authoritatively identified. No count of affected staff was published and none is asserted. Graded high. Corrections: corrections@forensicpost.com.