News Corp breach notices reportedly said attackers accessed business email and documents from February 2020 through January 2022, and that personal information may have been exposed. The disclosures added detail to the company’s February 2022 announcement; they did not establish that every listed data type applied to every person or provide a total number of people affected.
What changed between News Corp’s two disclosures?
| Disclosure | What was reported | What it established |
|---|---|---|
| February 2022 | News Corp said it discovered persistent cyberattack activity in January 2022 affecting a system, that some data was taken, and that the activity was believed contained. Its February 4 employee communication identified a limited number of business email accounts and documents at headquarters, News Technology Services, Dow Jones, News UK, and the New York Post. The company said systems housing customer and financial data were not affected to its knowledge. | The company’s initial account described the incident and its then-current understanding. It did not establish that no personal information was present in the affected accounts or documents. |
| February 2023 | SecurityWeek reported that notices to potentially affected people described access to business email and document storage from February 2020 through January 2022, through a system used by several News Corp businesses. The report described a limited number of personnel accounts. | The later notice reporting gave a longer access window and listed personal-information categories that may have been in the affected material. It did not provide a verified count of affected people. |
The two accounts concern different stages of the investigation. The earlier statement that customer and financial data systems were not affected to the company’s knowledge should not be read as a guarantee that no personal information appeared in email or documents. SecurityWeek’s report of the later notices is the basis for the expanded details below; the notices themselves are not independently reviewed here. SecurityWeek’s February 27, 2023 report and CBS News’ reporting on the February 2022 disclosure describe the two stages.
What information may have been compromised?
According to SecurityWeek’s account of the notices, information potentially present in affected email accounts and documents could include:
- Names and dates of birth
- Social Security numbers
- Passport or driver’s license numbers
- Financial account information
- Health insurance details
- Medical information
The notice reportedly said the categories varied by individual: not every type of information applied to every person. The reporting does not provide a complete account-level inventory, so a recipient’s own notice is the best guide to which information may relate to them.
#1 Best Overall
Were customer or financial data systems affected?
In its February 2022 account, News Corp said systems housing customer and financial data were not affected to its knowledge. That statement was qualified by the company’s knowledge at the time. The later notice reporting described potential personal information within business email and document content; it does not, by itself, show that the separate customer and financial systems were accessed.
What should someone who received a notice do?
News Corp reportedly said it was unaware of identity theft or fraud reports connected to the incident and offered impacted individuals 24 months of free identity protection and credit monitoring. SecurityWeek reported both the company’s statement and the offer.
- Read the notice you received to identify which information categories it says may apply to you.
- Use the enrollment instructions and contact details in that notice to confirm the reported 24-month offer and any eligibility or deadline terms.
- Keep an eye on financial accounts and credit activity, especially if your notice lists financial or identity-document information. Contact your financial institution or the relevant authority if you see activity you do not recognize.
What is known about who was behind the activity?
Mandiant assessed that the activity had a China nexus and was likely connected to espionage intended to collect intelligence to benefit China’s interests. David Wong, identified by CBS News as Mandiant’s vice president of consulting, said: “Mandiant assesses that those behind this activity have a China nexus, and we believe they are likely involved in espionage activities to collect intelligence to benefit China’s interests.” This is Mandiant’s assessment, not proof in the cited reporting that the Chinese government directed the operation. CBS News reported Mandiant’s assessment.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →

