NewspaperArchive

NewspaperArchive said an unauthorized third party remotely accessed and encrypted systems hosting its historical-newspaper platform in February 2026, making the service unavailable to libraries and subscribers. Core search and download functions returned during a phased recovery, but some publications and personal accounts remained unavailable as of May 19.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Unauthorized access to systems, accounts, networks, or data.
Data was rendered inaccessible through unauthorized encryption, including ransomware-related encryption.
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
A primary service, system, platform, or operational capability became entirely unavailable.
A service, system, platform, or operational capability remained available only in part or with significant limitations.
A public-facing website was unavailable, disabled, or inaccessible.
A specific application or software platform became unavailable or unusable.
Users were unable to authenticate, sign in, access accounts, or use identity-dependent services.
Staff, customers, patients, students, residents, or other users could not access records or case information normally.
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
The incident caused operational effects at customers, affiliates, subsidiaries, partners, tenants, or other dependent organizations.
DysruptionHub assesses with high confidence that NewspaperArchive experienced a confirmed malicious cyber incident involving unauthorized remote access and encryption of systems supporting NewspaperArchive.com. A preserved company service-disruption notice said an unauthorized third party accessed the environment in February, encrypted some systems and disrupted site functionality.
The public evidence supports unauthorized access and encryption but does not establish ransomware. NewspaperArchive did not publicly identify a ransom demand, extortion communication, threat actor or responsibility claim, and our reporting found no public claim of responsibility. Encryption is therefore treated as an observed technical effect rather than proof that access restoration was conditioned on payment.
The attack made a commercial archive used by individual subscribers and institutional partners unavailable. NewspaperArchive said the service contains material from thousands of publications and cities; the outage prevented researchers and library patrons from normally searching and retrieving historical newspaper records, while partner libraries had to publish access notices or direct users to alternatives such as local microfilm.
The impact extended beyond the Provo-based provider because libraries across several states depended on the same hosted platform. St. Mary’s College of Maryland Library reported the database unavailable and later said searching, clipping, downloading and sharing had returned while browse functions, personal accounts and selected publications were still being restored. This supports both direct platform disruption and downstream effects at customer institutions without implying that the libraries’ own networks were compromised.
Recovery was phased rather than a single full restoration. Indiana University Libraries’ May 19 status said advanced search, clipping, downloading, sharing and browsing were available, but some publications and personal accounts remained unavailable and technical support continued working toward full restoration.
A May newsletter from the Rogue Valley Genealogical Society reported access fully restored for its own members, showing that service had returned in at least one customer context. That statement does not resolve Indiana University’s later feature-level limitations across the platform, so the broader incident is assessed as presumed resolved after the last documented impact rather than assigned a universal final all-clear.
Confidence is high in malicious cyber involvement because the company attributed the disruption to unauthorized remote access and encryption. Confidence is also high that the outage materially affected library and subscriber access because multiple partner institutions published service notices and described phased restoration.
Ransomware confidence remains low. System encryption is consistent with ransomware activity, but the public record does not identify ransomware, a malware family, a ransom note, a demand, a negotiation, a payment or an extortion condition. NewspaperArchive also said it had no evidence at the time that personal information was affected and noted that a separate third party handled financial transactions and financial data; that preliminary assurance does not substitute for a final forensic conclusion.
The public record does not establish the exact intrusion date, initial access vector, exploited vulnerability, compromised account or host, credential use, malware family, dwell time, persistence, lateral movement, full encryption scope, backup impact or restoration method. It also does not identify a threat actor, ransom demand, payment, data theft, exfiltration, affected personal-information categories or record count.
A final provider report covering forensic findings, data impact and complete restoration was not located. The remaining uncertainty is whether feature and publication gaps documented May 19 were later cleared across all institutional and personal-account access paths, rather than only for particular customer environments.

DysruptionHub reported that NewspaperArchive disclosed unauthorized remote access and system encryption, with the resulting outage affecting partner libraries and subscribers across the United States.
The library said NewspaperArchive was unavailable in March. Its April 14 update said search, clipping, downloading and sharing were restored, while browse functions, personal accounts and selected publications still required recovery.
NewspaperArchive said an unauthorized third party remotely accessed systems housing NewspaperArchive.com in February and encrypted some systems, disrupting site functionality while an external investigation proceeded.
The society said NewspaperArchive access had been fully restored for its members and was again available both remotely and at its library after a cyberattack-related outage.
Indiana University Libraries said certain NewspaperARCHIVE functions were available after a major outage, but some publications and personal user accounts remained unavailable while support worked toward full restoration.
Official profile information supporting the public description of NewspaperArchive.
Signed-in members can report an error, update, or missing source.