The Guardian newspaper believes "IT incident" caused by ransomware
It's the second case of a major Western media organisation being targeted by a cyber attack this year
UK newspaper the Guardian has confirmed that it believes it has suffered a ransomware attack causing disruption to the business.
A spokesperson for the publisher said “there has been a serious incident which has affected our IT network and systems in the last 24 hours,” in a statement to IT Pro.
The incident was first detected on late Tuesday evening, with some of its internal systems and behind-the-scenes services affected. Staff have been ordered to work from home.
Editorial output persists across its website globally and the company is “confident” that its print issue will still reach newsstands on Thursday morning.
It remains unclear which ransomware group has launched the attack on the publisher. Cyber security expert Graham Cluley indicated that Guardian staff have also been told to avoid connecting to the publisher’s virtual private network (VPN).
The newspaper’s spokesperson said it will keep staff and any other who may be affected informed on the progress of the incident.
Asked about estimated recovery times, the Guardian’s spokesperson did not respond.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
Ransomware attacks are typically financially motivated and have steadily increased in volume every year since the method became popular following the WannaCry incident in 2017.
However, cyber attacks on news organisations in recent times have been more focused on sending a political statement rather than for the purposes of extorting targets financially.
The ongoing conflict in Ukraine has seen distributed denial of service (DDoS) attacks surge in both regions. They have been directed at a variety of targets such as government agencies, as well as media organisations.
Hacktivist group Anonymous famously claimed to hijack a number of Russian broadcast networks earlier this year in a bid to highlight state-controlled media failing to cover Russia’s true intentions with its invasion of Ukraine.
The March 2022 attacks saw the white hat hackers briefly control news feeds, displaying footage of Ukrainian warzones.
News Corp was also targeted by alleged Chinese state-sponsored hackers in February for the purposes of espionage and data theft.
The umbrella company houses high-profile publishers such as The Times, The Sun, and The Wall Street Journal.
Cyber security company Mandiant investigated the incident on behalf of New Corp and concluded that a persistent attack on one of its cloud systems saw the theft of data to benefit China’s interests.

Connor Jones has been at the forefront of global cyber security news coverage for the past few years, breaking developments on major stories such as LockBit’s ransomware attack on Royal Mail International, and many others. He has also made sporadic appearances on the ITPro Podcast discussing topics from home desk setups all the way to hacking systems using prosthetic limbs. He has a master’s degree in Magazine Journalism from the University of Sheffield, and has previously written for the likes of Red Bull Esports and UNILAD tech during his career that started in 2015.
-
The OpenAI and Anthropic containment breaches are a bit spooky, but also quite sillyOpinion An AI leaving notes to future versions of itself is pure sci-fi; forgetting to lock down an environment is prosaic
-
Bringing data to the heart of AISponsored AI is changing our approach to data, find out how HPE Alletra Storage can help your business
-
Companies are still paying ransoms to cyber criminals despite official adviceNews A Proofpoint survey found evolving ransomware techniques and the use of AI is exacerbating the situation for victims
-
This one cyber crime group accounted for nearly a fifth of all ransomware attacks in JuneNews The Gentlemen, a ransomware a service operator, now accounts for 17% of published attacks
-
Working with the enemy: Ransomware negotiator-turned cyber criminal jailed after working with hackers to extort clientsNews Angelo Martino was supposed to be negotiating on behalf of victims, but was secretly working for ransomware operators
-
Hackers are posing as Interpol to target small businesses – here's what you need to knowNews Small businesses are warned to think twice before clicking on links
-
‘Every hour ransomware goes undetected drastically increases its potential blast radius’: Hackers are breaching networks and laying low for longer – and nearly half of firms don’t realize until data is stolenNews An ExtraHop survey found more intrusions are going undetected, leading to longer dwell times
-
Ransomware cartels are fragmenting into volatile splinter groups, warns Met Police cyber chiefNews Commoditized "cyber crime bazaars" and AI data mining are forcing law enforcement to rewrite its playbook
-
New ransomware threat group, The Gentlemen, has become one of the most active ransomware operators, accounting for 10% of all attacksNews NTT researchers warn that the RaaS group is leveraging SystemBC malware to establish covert tunnelling, evade detection, and support rapid lateral movement across enterprise environments
-
Instructure chose to a pay ransom following the Canvas cyber attack – research shows more than half of security leaders would follow suitAnalysis Opting to pay ransoms creates huge risks for enterprises – you’re relying on the word of criminals