HackingVulnerability ExploitZero-DaySupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHighContained
The Washington Post
bd_e7ea69efe7606efd · schema v1 · pii pii-v1
Full breach record for The Washington Post →The Washington Post experienced a data breach due to a previously unknown vulnerability in Oracle E-Business Suite software. Between July 10 and August 22, 2025, unauthorized actors accessed and acquired data including names and Social Security numbers. The incident was discovered on October 27, 2025. The Post engaged forensic experts, secured systems, applied patches, and offered identity protection services to approximately 9,562 affected individuals.
California clockDiscovered Oct 27, 2025 → Notified Nov 12, 202516d ✓ CA 60-day OK16 days discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_209d44025d2c2a3dIndiana State AGfiled 2025-11-12Verified
- bd_2d05f81698405b0cMontana State AGfiled 2025-11-12Candidate
- bd_b0c26abd0a0c427fNew Hampshire State AGfiled 2025-11-12Verified
- bd_e1b9a8ee412f24c7Vermont State AGfiled 2025-11-12Verified
Show 1 more filing ↓Show fewer ↑
- bd_e3496677ede773b5Maine State AGfiled 2025-11-12Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-614128
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 12, 2025
- Raw hash
- ddd39c4793e6f6c4d3df326d3770fb2a2b1a23fb830121c3ba4538dc891f4ea4
Reporting entity
- Name
- The Washington Postnorm: the washington post
Victim entity
- Name
- The Washington Postnorm: the washington post
Incident
- Discovered
- Oct 27, 2025
- Materiality determined
- —
- Notification sent
- Nov 12, 2025
- Affected individuals
- 9,562
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unknown
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 16 days(16 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 16d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 27, 2025→ Notified: Nov 12, 202516d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.