Mediaworks Hungary, one of the country’s larger publishing groups, was reported in May 2026 to have suffered an intrusion involving roughly 15 million files, described at around 8.5 terabytes, including internal records.
We write about breached organisations every week. It is worth stating plainly what a breach means when the organisation is a newsroom, because the sensitive material is not primarily the newsroom’s own.
Source Protection Is An Infrastructure Problem
A publisher’s systems hold the residue of reporting: message threads, call records, draft documents, expense claims that place a reporter in a city on a date. Individually these are administrative. Assembled, they can identify a confidential source who was promised they would never be identifiable.
That promise is not primarily a legal or ethical undertaking. It is an operational one, and it is kept or broken by mail retention settings, device management and archive policy — decisions usually made without anyone framing them as source protection.
We hold ourselves to this too. It is the reason this desk publishes its retention practice, and the reason our tips guidance asks people to use a personal device on a network their employer does not run.
Graded low. The volume figures are not corroborated and the intrusion route is not established.
Compiled from public reporting, listed below. Volume figures are unverified. We are not describing the contents of any listed material. Corrections: corrections@forensicpost.com.
- List of recent data breaches in 2026Bright Defense