HackingVulnerability ExploitZero-DayData ExfiltratedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTEMPLOYMENTMediumContained
ANYWHERE REAL ESTATE INC.
bd_7d4fcc93451bf605 · schema v1 · pii pii-v1
Full breach record for ANYWHERE REAL ESTATE INC. →Anywhere Real Estate Inc. disclosed a cybersecurity incident discovered on November 24, 2025. An unauthorized third party exploited a zero-day vulnerability in Oracle E-Business Suite to access and exfiltrate personal information of current and former employees, including names, addresses, dates of birth, Social Security numbers, and basic job details. The company remediated the vulnerability and is offering 24 months of credit monitoring.
California clockDiscovered Nov 24, 2025 → Notified Jan 30, 202667d ✗ CA 60-day late11 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_53d22febe8c4f9b1Leak Sitecl0pfiled 2025-11-21(77d gap)Candidate
Regulatory filings (3) · sorted by filing gap
- bd_aa6181e5363ae53eMaine State AGfiled 2026-02-06Verified by operator
- bd_63752cabdb1479adTexas State AGfiled 2026-02-02(4d gap)Verified
- bd_6e8577f724c2167cIndiana State AGfiled 2026-01-30(7d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-618362
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 6, 2026
- Raw hash
- 33000afb1f18dccf739026d5fa393ab8df66dbaea39a45898225ab48c95ab694
Reporting entity
- Name
- ANYWHERE REAL ESTATE INC.norm: anywhere real estate
- Domain
- anywhere.re
Victim entity
- Name
- ANYWHERE REAL ESTATE INC.norm: anywhere real estate
- Domain
- anywhere.re
Incident
- Discovered
- Nov 24, 2025
- Materiality determined
- —
- Notification sent
- Jan 30, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTEMPLOYMENT
- Attack vector
- Unknown
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(74 days from discovery to filing)
- Compliance flags
- CA 60-day late · 67dLeak >30dCA AG copy ≤15d · 7d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 24, 2025→ Notified: Jan 30, 202667d 60 days (analyst band, pre-2026 discoveries) CA 60-day late California Consumers notified: Jan 30, 2026→ AG copy submitted: Feb 6, 20267d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.