HackingVulnerability ExploitZero-DaySupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICLowContained
COX ENTERPRISES, INC.
bd_d243eedeb344b5f2 · schema v1 · pii pii-v1
Full breach record for COX ENTERPRISES, INC. →Cox Enterprises, Inc. disclosed a cybersecurity incident where cybercriminals exploited a previously unknown 'zero-day' vulnerability in Oracle's E-Business Suite between August 9-14, 2025. Cox became aware of suspicious activity on September 29, 2025. The incident potentially affected personal information including names. Cox applied the security fix, engaged cybersecurity experts, contacted law enforcement, and is offering credit monitoring services.
California clockDiscovered Sep 29, 2025 → Notified Nov 20, 202552d ✓ CA 60-day OK7 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_76c8778cb9fa2c6dVermont State AGfiled 2025-11-20Verified
- bd_a35479fbdcf86c9aIndiana State AGfiled 2025-11-20Verified
- bd_c14447cb7482b2fdMaine State AGfiled 2025-11-20Candidate
- bd_244cea98a033cd5cTexas State AGfiled 2025-11-21(1d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 5d gap
- bd_8766c6dda720b44aNew Hampshire State AGfiled 2025-11-21(1d gap)Verified
- bd_7369119a392f4428Montana State AGfiled 2025-11-25(5d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-614528
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 20, 2025
- Raw hash
- dbfeb5051091f8f9d53da898dcdf0da2e84548fe01cea0b3b6a77409b3b5bcfb
Reporting entity
- Name
- COX ENTERPRISES, INC.norm: cox enterprises
Victim entity
- Name
- COX ENTERPRISES, INC.norm: cox enterprises
Incident
- Discovered
- Sep 29, 2025
- Materiality determined
- —
- Notification sent
- Nov 20, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unknown
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Third party
- via Oracle
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(52 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 52d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 29, 2025→ Notified: Nov 20, 202552d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.