HackingVulnerability ExploitZero-DaySupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICPIILowContained
The Washington Post
bd_78926bf02d97b8f8 · schema v1 · pii pii-v1
Full breach record for The Washington Post →The Washington Post experienced a data security incident due to a previously unknown vulnerability in Oracle E-Business Suite software. Unauthorized access occurred between July 10, 2025, and August 22, 2025. The Post was contacted by a bad actor in October 2025, leading to an investigation. Affected data includes names and other personal information. The Post secured systems, applied patches, and is offering identity protection services.
California clockDiscovered Oct 1, 2025 → Notified Jul 10, 2026282d ✗ CA 60-day late41 weeks discovery → filing
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_c1d11a5eb36e7edeVermont State AGfiled 2026-07-13Verified
- bd_0d97643c7c02e0a6Oregon State AGfiled 2026-07-14(1d gap)Verified
- bd_8e858a0885ff6516Texas State AGfiled 2026-07-14(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-626404
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 13, 2026
- Raw hash
- 498dcf1c8ddd451062a539d65fe20160d077a364850fd67375a4f67b41a7da1f
Reporting entity
- Name
- The Washington Postnorm: the washington post
Victim entity
- Name
- The Washington Postnorm: the washington post
Incident
- Discovered
- Oct 1, 2025
- Materiality determined
- —
- Notification sent
- Jul 10, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Unknown
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Third party
- via Oracle
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 41 weeks(285 days from discovery to filing)
- Compliance flags
- CA 60-day late · 282dCA AG copy ≤15d · 3d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 1, 2025→ Notified: Jul 10, 2026282d 60 days (analyst band, pre-2026 discoveries) CA 60-day late California Consumers notified: Jul 10, 2026→ AG copy submitted: Jul 13, 20263d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.