HackingVulnerability ExploitZero-DayData ExfiltratedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTCVE-2025-61882MediumContained
ANYWHERE REAL ESTATE INC.
bd_b57dabb5db6fd28a · schema v1 · pii pii-v1
Full breach record for ANYWHERE REAL ESTATE INC. →Anywhere Real Estate Inc. notified the New Hampshire Attorney General of a cybersecurity incident involving its Oracle E-Business Suite. An unauthorized third party exploited a zero-day vulnerability (CVE-2025-61882) on August 13, 2025, to access the system and exfiltrate employee data, including SSNs and names. The breach was discovered on November 24, 2025, affecting 151 New Hampshire residents. Notices were sent on January 30, 2026, offering 24 months of credit monitoring.
Leak gap clock⏱ Leak >30d11 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
A leak claim by cl0p about this victim predates this filing by 77 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_74fecc5ce2bbbae0Vermont State AGfiled 2026-01-30(7d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/anywhere-real-estate-20260206.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 6, 2026
- Raw hash
- 5b06162fa3e013d65829e0dca8267a51a9bb108a4df7ae9df95f64363e834124
Reporting entity
- Name
- ANYWHERE REAL ESTATE INC.norm: anywhere real estate
- Domain
- anywhere.re
Victim entity
- Name
- ANYWHERE REAL ESTATE INC.norm: anywhere real estate
- Domain
- anywhere.re
Incident
- Discovered
- Nov 24, 2025
- Materiality determined
- —
- Notification sent
- Jan 30, 2026
- Affected individuals
- 151
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Provided notice to New Hampshire Attorney General Consumer Protection & Antitrust Bureau
- Initial access
- exploit_public_facing
- CVE references
Compliance
- Time to disclose
- 11 weeks(74 days from discovery to filing)
- Compliance flags
- Leak >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.