Skip to content

NewspaperArchive Unauthorized Access and Encryption Incident

Summary

NewspaperArchive logo

NewspaperArchive said an unauthorized third party remotely accessed and encrypted systems hosting its historical-newspaper platform in February 2026, making the service unavailable to libraries and subscribers. Core search and download functions returned during a phased recovery, but some publications and personal accounts remained unavailable as of May 19.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Impacted location

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

Data impacts

  • Data encryption

    Data was rendered inaccessible through unauthorized encryption, including ransomware-related encryption.

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Complete service outage

    A primary service, system, platform, or operational capability became entirely unavailable.

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Website unavailable

    A public-facing website was unavailable, disabled, or inaccessible.

  • Application unavailable

    A specific application or software platform became unavailable or unusable.

  • Authentication disruption

    Users were unable to authenticate, sign in, access accounts, or use identity-dependent services.

  • Records access disruption

    Staff, customers, patients, students, residents, or other users could not access records or case information normally.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

  • Downstream organization impact

    The incident caused operational effects at customers, affiliates, subsidiaries, partners, tenants, or other dependent organizations.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that NewspaperArchive experienced a confirmed malicious cyber incident involving unauthorized remote access and encryption of systems supporting NewspaperArchive.com. A preserved company service-disruption notice said an unauthorized third party accessed the environment in February, encrypted some systems and disrupted site functionality.

The public evidence supports unauthorized access and encryption but does not establish ransomware. NewspaperArchive did not publicly identify a ransom demand, extortion communication, threat actor or responsibility claim, and our reporting found no public claim of responsibility. Encryption is therefore treated as an observed technical effect rather than proof that access restoration was conditioned on payment.

Operational significance

The attack made a commercial archive used by individual subscribers and institutional partners unavailable. NewspaperArchive said the service contains material from thousands of publications and cities; the outage prevented researchers and library patrons from normally searching and retrieving historical newspaper records, while partner libraries had to publish access notices or direct users to alternatives such as local microfilm.

The impact extended beyond the Provo-based provider because libraries across several states depended on the same hosted platform. St. Mary’s College of Maryland Library reported the database unavailable and later said searching, clipping, downloading and sharing had returned while browse functions, personal accounts and selected publications were still being restored. This supports both direct platform disruption and downstream effects at customer institutions without implying that the libraries’ own networks were compromised.

Current status

Recovery was phased rather than a single full restoration. Indiana University Libraries’ May 19 status said advanced search, clipping, downloading, sharing and browsing were available, but some publications and personal accounts remained unavailable and technical support continued working toward full restoration.

A May newsletter from the Rogue Valley Genealogical Society reported access fully restored for its own members, showing that service had returned in at least one customer context. That statement does not resolve Indiana University’s later feature-level limitations across the platform, so the broader incident is assessed as presumed resolved after the last documented impact rather than assigned a universal final all-clear.

Confidence and uncertainty

Confidence is high in malicious cyber involvement because the company attributed the disruption to unauthorized remote access and encryption. Confidence is also high that the outage materially affected library and subscriber access because multiple partner institutions published service notices and described phased restoration.

Ransomware confidence remains low. System encryption is consistent with ransomware activity, but the public record does not identify ransomware, a malware family, a ransom note, a demand, a negotiation, a payment or an extortion condition. NewspaperArchive also said it had no evidence at the time that personal information was affected and noted that a separate third party handled financial transactions and financial data; that preliminary assurance does not substitute for a final forensic conclusion.

Analytic gaps

The public record does not establish the exact intrusion date, initial access vector, exploited vulnerability, compromised account or host, credential use, malware family, dwell time, persistence, lateral movement, full encryption scope, backup impact or restoration method. It also does not identify a threat actor, ransom demand, payment, data theft, exfiltration, affected personal-information categories or record count.

A final provider report covering forensic findings, data impact and complete restoration was not located. The remaining uncertainty is whether feature and publication gaps documented May 19 were later cleared across all institutional and personal-account access paths, rather than only for particular customer environments.

Organizations involved

Impacted location

Sources

NewspaperArchive cyberattack in Utah disrupts library access across U.S.

DysruptionHub reported that NewspaperArchive disclosed unauthorized remote access and system encryption, with the resulting outage affecting partner libraries and subscribers across the United States.

Service Disruption – Newspaper Archive Database

The library said NewspaperArchive was unavailable in March. Its April 14 update said search, clipping, downloading and sharing were restored, while browse functions, personal accounts and selected publications still required recovery.

NewspaperArchive service disruption notice

NewspaperArchive said an unauthorized third party remotely accessed systems housing NewspaperArchive.com in February and encrypted some systems, disrupting site functionality while an external investigation proceeded.

Archive platform: Screenshot
The RVGS eNews, May 2026

The society said NewspaperArchive access had been fully restored for its members and was again available both remotely and at its library after a cyberattack-related outage.

Outages and Downtime

Indiana University Libraries said certain NewspaperARCHIVE functions were available after a major outage, but some publications and personal user accounts remained unavailable while support worked toward full restoration.

NewspaperArchive

Official profile information supporting the public description of NewspaperArchive.

See something that needs correction?

Signed-in members can report an error, update, or missing source.