HackingVulnerability ExploitZero-DayData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
The Washington Post
bd_b0c26abd0a0c427f · schema v1 · pii pii-v1
Full breach record for The Washington Post →The Washington Post notified the New Hampshire Attorney General of a data security incident involving a previously unknown vulnerability in its Oracle E-Business Suite. Unauthorized access occurred between July 10 and August 22, 2025. The Post confirmed on October 27, 2025, that personal information of current and former employees and contractors was accessed, including names, SSNs, and bank account numbers. 16 New Hampshire residents were notified on November 12, 2025. The Post applied patches and offered identity protection services.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_209d44025d2c2a3dIndiana State AGfiled 2025-11-12Verified
- bd_2d05f81698405b0cMontana State AGfiled 2025-11-12Candidate
- bd_e1b9a8ee412f24c7Vermont State AGfiled 2025-11-12Verified
- bd_e3496677ede773b5Maine State AGfiled 2025-11-12Verified
Show 1 more filing ↓Show fewer ↑
- bd_e7ea69efe7606efdCalifornia State AGfiled 2025-11-12Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/washington-post-20251112.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 12, 2025
- Raw hash
- 1b65356980d28c7916db5e18ae3ef21c9d36af21842b1c5efb6e988d370c4ba1
Reporting entity
- Name
- The Washington Postnorm: the washington post
Victim entity
- Name
- The Washington Postnorm: the washington post
Incident
- Discovered
- Sep 29, 2025
- Materiality determined
- —
- Notification sent
- Nov 12, 2025
- Affected individuals
- 16
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(44 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.