HackingVulnerability ExploitZero-DayData ExfiltratedIDENTITY_BASICLowContained
COX ENTERPRISES, INC.
bd_76c8778cb9fa2c6d · schema v1 · pii pii-v1
Full breach record for COX ENTERPRISES, INC. →Cox Enterprises, Inc. disclosed a data breach involving Oracle E-Business Suite. Cybercriminals exploited a zero-day vulnerability between Aug 9-14, 2025. The incident resulted in the unauthorized access and potential copying of personal information, including names. Cox engaged forensic experts, applied security patches, and notified law enforcement. Affected individuals were offered credit monitoring services. The breach was discovered on Sept 29, 2025.
Vermont clock⏱ VT AG >14 bday7 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_a35479fbdcf86c9aIndiana State AGfiled 2025-11-20Verified
- bd_c14447cb7482b2fdMaine State AGfiled 2025-11-20Candidate
- bd_d243eedeb344b5f2California State AGfiled 2025-11-20Verified
- bd_244cea98a033cd5cTexas State AGfiled 2025-11-21(1d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 5d gap
- bd_8766c6dda720b44aNew Hampshire State AGfiled 2025-11-21(1d gap)Verified
- bd_7369119a392f4428Montana State AGfiled 2025-11-25(5d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-11-20-cox-enterprises-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 20, 2025
- Raw hash
- c76ef9d37ac41012f7c1b8aac263c77515c1699c310c63303ca921154ca45355
Reporting entity
- Name
- COX ENTERPRISES, INC.norm: cox enterprises
Victim entity
- Name
- COX ENTERPRISES, INC.norm: cox enterprises
Incident
- Discovered
- Sep 29, 2025
- Materiality determined
- Oct 31, 2025
- Notification sent
- Nov 20, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(52 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.