The Washington Post
ent_42d98468191cc08fdc5731cc
The Washington Post is a major American daily newspaper based in Washington, D.C., providing coverage of national and international news, politics, business, and culture.
AI-summarized from indexed web sources · Washington, D.C. · 2026-08-04 · source
Disclosures
16
State AG · Leak Site · 13 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
36,358
nationwide · State AG TX
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- The Washington Post
- Normalized
- the washington post— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- washingtonpost.com
Disclosure history (16)newest first
- Oregon State AGas victim2026-07-14
The Washington Post reported a data breach to the Oregon Attorney General. The breach was reported on 2026-07-14. The breach occurred during 9/29/2025. The breach was discovered on 9/29/2025. 323 individuals were affected. Notice was sent on 7/10/2026.
- Texas State AGas victim2026-07-14
The Washington Post based in Washington, District of Columbia, a business – retail or merchant entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-06-10 and reported on 2026-07-14. 862 Texas residents were affected. 36,358 individuals affected in total. Types of information involved: Name of individual;Social Security Number Information;Government-issued ID number (e.g. passport, state ID card);Financial Information (e.g. account number, credit or debit card number);Health Insurance Information. Consumers were notified via U.S. Mail.
- Washington State AGas victim2026-07-13
The Washington Post, a business sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2025-09-29 and filed notice on 2026-07-13. 514 Washington residents were affected. 287 days elapsed between awareness and notification. 81 days to identify the breach. 0 days to contain the breach.
- New Hampshire State AGas victim2026-07-13
The Washington Post experienced a data security incident resulting from a previously unknown vulnerability in Oracle E-Business Suite software. Unauthorized access occurred between July 10, 2025, and August 22, 2025. The Post discovered the issue in October 2025. This supplemental notice updates a prior notification, identifying an additional 102 New Hampshire residents affected. Compromised data included names, bank account numbers, routing numbers, health insurance information, employee IDs, and Social Security numbers. The Post engaged forensic experts, secured systems, applied patches, and offered identity protection services.
- California State AGas victim2026-07-13
The Washington Post experienced a data security incident due to a previously unknown vulnerability in Oracle E-Business Suite software. Unauthorized access occurred between July 10, 2025, and August 22, 2025. The Post was contacted by a bad actor in October 2025, leading to an investigation. Affected data includes names and other personal information. The Post secured systems, applied patches, and is offering identity protection services.
- Vermont State AGas victim2026-07-13
The Washington Post reported a data breach to the Vermont Attorney General. The breach was reported to the AGO on 2026-07-13. The reporting organization type is Other Commercial. 172 Vermont residents were affected. Categories of data breached: Social Security Numbers, Financial Account Codes, Credit and Debit Account Info.
- Illinois State AGas victim2026-07-01
THE WASHINGTON POST filed a data-breach notice with the Illinois Attorney General in July 2026 (case 26-07-1312). The register records the breach as discovered on June 10, 2026. Personal information types reported: financial account number, medical information, passport number, ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Indiana State AGas victim2025-11-12
The Washington Post reported a data breach to the Indiana Attorney General. The breach occurred on 2025-07-10 and was reported on 2025-11-12. 45 Indiana residents were affected. 9,720 individuals affected in total.
- Montana State AGas victim2025-11-12
The Washington Post notified Montana residents of a data breach involving a previously unknown vulnerability in Oracle E-Business Suite software. Unauthorized access occurred between July 10 and August 22, 2025, affecting names and Social Security numbers. The Post engaged forensic experts, secured systems, and applied patches. Complimentary identity protection services are offered.
- Nebraska State AGas victim2025-11-12
The Washington Post notified Nebraska AG that a previously unknown vulnerability in Oracle E-Business Suite was exploited between July 10 and August 22, 2025. The Post confirmed on October 27, 2025, that personal information (SSN, tax ID, bank account numbers) of 13 Nebraska residents was accessed. Remediation included patching and offering identity protection services.
- Massachusetts State AGas victim2025-11-12
The Washington Post reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-11-12. 1,256 Massachusetts residents were affected.
- New Hampshire State AGas victim2025-11-12
The Washington Post notified the New Hampshire Attorney General of a data security incident involving a previously unknown vulnerability in its Oracle E-Business Suite. Unauthorized access occurred between July 10 and August 22, 2025. The Post confirmed on October 27, 2025, that personal information of current and former employees and contractors was accessed, including names, SSNs, and bank account numbers. 16 New Hampshire residents were notified on November 12, 2025. The Post applied patches and offered identity protection services.
- Vermont State AGas victim2025-11-12
The Washington Post disclosed a data breach affecting customer data (names, SSNs) due to exploitation of a zero-day vulnerability in Oracle E-Business Suite. The incident occurred between July 10 and August 22, 2025. The Post engaged forensic experts, secured systems, applied patches, and offered identity protection services. 9,562 Rhode Island residents were notified.
- Maine State AGas victim2025-11-12
The Washington Post reported a data breach affecting 9,720 individuals (including 31 Maine residents). Unauthorized access to Oracle E-Business Suite occurred between July 10 and August 22, 2025, exploiting a previously unknown vulnerability. The breach was discovered on October 27, 2025. Affected data included names, SSNs, tax IDs, and bank account numbers. Notices were sent on November 12, 2025, offering 12 months of identity protection.
- California State AGas victim2025-11-12
The Washington Post experienced a data breach due to a previously unknown vulnerability in Oracle E-Business Suite software. Between July 10 and August 22, 2025, unauthorized actors accessed and acquired data including names and Social Security numbers. The incident was discovered on October 27, 2025. The Post engaged forensic experts, secured systems, applied patches, and offered identity protection services to approximately 9,562 affected individuals.
- GLOBALLeak Siteas victim2025-11-07
The WashingtonPost.com is the online edition of The Washington Post, a leading US daily newspaper. This platform provides news, analysis, commentary, and videos on politics, business, world, national and local news, sports, arts, lifestyle, and more. It offers both free and premium (subscription-based) content, and showcases investigative journalism, podcasts, and blogs.
Supply-chain cascadesreviewed and confirmed
- The Washington Post’s filing is one of at least 7 in the ORACLE CORPORATION supply-chain incident (2025).