HackingProfessional ServicesRetail & ConsumerRetailVulnerability ExploitData MishandlingZero-DayData ExfiltratedEmployee Data InvolvedDelayed DiscoveryPIIIDENTITY_BASICIDENTITY_GOVERNMENTEMPLOYMENTMediumResolved
ANYWHERE REAL ESTATE INC.
bd_aa6181e5363ae53e · schema v1 · pii pii-v1
Full breach record for ANYWHERE REAL ESTATE INC. →Anywhere Real Estate Inc. (formerly Realogy) discovered Nov 24, 2025 that an unauthorized third party exploited a zero-day Oracle E-Business Suite vulnerability (Aug 13-22, 2025), exfiltrating personal data of current/former employees across subsidiaries: names, addresses, DOB, SSNs, job details. 17,429 total affected; 69 Maine residents. Experian IdentityWorks (24 months) offered to all impacted.
Maine clockDiscovered Nov 24, 2025 → Filed with AG Feb 6, 202674d ⏱ ME AG >30d11 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
A leak claim by cl0p about this victim predates this filing by 77 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_53d22febe8c4f9b1Leak Sitecl0pfiled 2025-11-21(77d gap)Candidate
Regulatory filings (3) · sorted by filing gap
- bd_7d4fcc93451bf605California State AGfiled 2026-02-06Verified
- bd_63752cabdb1479adTexas State AGfiled 2026-02-02(4d gap)Verified
- bd_6e8577f724c2167cIndiana State AGfiled 2026-01-30(7d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/c286e6aa-68a7-47e6-8847-4ef8a9cba713.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 6, 2026
- Raw hash
- 04c54460d2bdd3436e1d25cb2bec9bb2f58d58dfbe1473dd92a25eed95b68ef7
Reporting entity
- Name
- ANYWHERE REAL ESTATE INC.norm: anywhere real estate
- Domain
- anywhere.re
- Industry
- Real Estate
Victim entity
- Name
- ANYWHERE REAL ESTATE INC.norm: anywhere real estate
- Domain
- anywhere.re
- Industry
- Real Estate
- Industry
- Professional ServicesllmRetail & Consumerllm
Incident
- Discovered
- Nov 24, 2025
- Materiality determined
- —
- Notification sent
- Jan 30, 2026
- Affected individuals
- 69
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENTEMPLOYMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(74 days from discovery to filing)
- Compliance flags
- ME AG >30d · 74dME resident >60d · 67dLeak >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Nov 24, 2025→ Filed with AG: Feb 6, 202674d 30 days (soft) ME AG >30d Maine Discovered: Nov 24, 2025→ Notified: Jan 30, 202667d 60 days (analyst band; statutory cap is 30 days) ME resident >60d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.