COX ENTERPRISES, INC.
bd_839c9a8c3542409b · schema v1 · pii pii-v1
Full breach record for COX ENTERPRISES, INC. →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Cl0p on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
Cox Enterprises, Inc. is an American conglomerate based in Atlanta, Georgia. The company was founded by James M. Cox in 1898 and primarily specializes in broadband communications, automotive services, and digital media. The conglomerate comprises Cox Communications, Cox Automotive, and Cox Media Group. They are also involved in sustainability and social initiatives.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Oct 27, 2025
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- Nebraska State AGbd_40c9054d459138182025-11-20 · +24dVerified by operator
- Vermont State AGbd_76c8778cb9fa2c6d2025-11-20 · +24dVerified
- Massachusetts State AGbd_969a08a7f00f6f732025-11-20 · +24dVerified by operator
- Indiana State AGbd_a35479fbdcf86c9a2025-11-20 · +24dVerified
Show 5 more filings ↓Show fewer ↑up to 29d gap
- Maine State AGbd_c14447cb7482b2fd2025-11-20 · +24dVerified
- California State AGbd_d243eedeb344b5f22025-11-20 · +24dVerified
- Texas State AGbd_244cea98a033cd5c2025-11-21 · +25dVerified
- New Hampshire State AGbd_8766c6dda720b44a2025-11-21 · +25dVerified
- Montana State AGbd_7369119a392f44282025-11-25 · +29dVerified
Filing propagation · 10 filings · 9 states
View merged incident ↗Pattern: first filing Oct 27, last Nov 25 (MT) — a 29-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.