ANYWHERE REAL ESTATE INC.
bd_0b26181366c05d6f · schema v1 · pii pii-v2
Full breach record for ANYWHERE REAL ESTATE INC. →Anywhere Real Estate Inc. disclosed a cybersecurity incident on November 24, 2025, involving its Oracle E-Business Suite. An unauthorized third party exploited a zero-day vulnerability to access the system and exfiltrate personal information, including names, addresses, SSNs, and job details, of current and former employees and franchisees. Anywhere engaged third-party experts, remediated the vulnerability, and offered 24 months of credit monitoring via Experian.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 24, 2025
Discovered
Jan 30, 2026
Filed
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Sitecl0pbd_53d22febe8c4f9b12025-11-21 · +70dVerified by operator
Regulatory filings (7) · sorted by filing gap
- Indiana State AGbd_6e8577f724c2167c2026-01-30Verified
- Vermont State AGbd_74fecc5ce2bbbae02026-01-30Verified by operator
- Texas State AGbd_63752cabdb1479ad2026-02-02 · +3dVerified
- Massachusetts State AGbd_4900ec23e349cdff2026-02-06 · +7dVerified by operator
Show 3 more filings ↓Show fewer ↑up to 7d gap
- California State AGbd_7d4fcc93451bf6052026-02-06 · +7dVerified
- Maine State AGbd_aa6181e5363ae53e2026-02-06 · +7dVerified by operator
- New Hampshire State AGbd_b57dabb5db6fd28a2026-02-06 · +7dVerified by operator
Filing propagation · 8 filings · 8 states
View merged incident ↗Pattern: first filing Jan 30 (IN), last Feb 6 (NH) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.