ANYWHERE REAL ESTATE INC.
bd_aa6181e5363ae53e · schema v1 · pii pii-v1
Full breach record for ANYWHERE REAL ESTATE INC. →Anywhere Real Estate Inc. reported a cybersecurity incident involving its Oracle E-Business Suite environment. An unauthorized third party exploited a zero-day Oracle vulnerability between August 13-22, 2025, to exfiltrate personal information of current and former employees, including SSNs and DOBs. The incident was discovered on November 24, 2025. The company engaged third-party experts, remediated the vulnerability, and offered 24 months of credit monitoring to the 17,429 affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
Aug 13, 2025
Begins
Nov 24, 2025
Discovered
Feb 6, 2026
Filed
vs. sector median
7 wks faster
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Sitecl0pbd_53d22febe8c4f9b12025-11-21 · +77dVerified by operator
Regulatory filings (7) · sorted by filing gap
- Massachusetts State AGbd_4900ec23e349cdff2026-02-06Verified by operator
- California State AGbd_7d4fcc93451bf6052026-02-06Verified
- New Hampshire State AGbd_b57dabb5db6fd28a2026-02-06Verified by operator
- Texas State AGbd_63752cabdb1479ad2026-02-02 · +4dVerified
Show 3 more filings ↓Show fewer ↑up to 7d gap
- Nebraska State AGbd_0b26181366c05d6f2026-01-30 · +7dVerified by operator
- Indiana State AGbd_6e8577f724c2167c2026-01-30 · +7dVerified
- Vermont State AGbd_74fecc5ce2bbbae02026-01-30 · +7dVerified by operator
Filing propagation · 8 filings · 8 states
View merged incident ↗Pattern: first filing Jan 30 (NE), last Feb 6 (ME) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.