The Washington Post
ent_42d98468191cc08fdc5731cc
Disclosures
10
State AG · 8 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
9,720
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- The Washington Post
- Normalized
- the washington post— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (10)newest first
- 🦫Oregon State AGas victim2026-07-14
The Washington Post reported a data breach to the Oregon Attorney General. The breach was reported on 2026-07-14. The breach occurred during 9/29/2025. The breach was discovered on 9/29/2025. 323 individuals were affected. Notice was sent on 7/10/2026.
- ⭐Texas State AGas victim2026-07-14
The Washington Post based in Washington, District of Columbia, a business – retail or merchant entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-06-10 and reported on 2026-07-14. 862 Texas residents were affected. 36,358 individuals affected in total. Types of information involved: Name of individual;Social Security Number Information;Government-issued ID number (e.g. passport, state ID card);Financial Information (e.g. account number, credit or debit card number);Health Insurance Information. Consumers were notified via U.S. Mail.
- 🐻California State AGas victim2026-07-13
The Washington Post experienced a data security incident due to a previously unknown vulnerability in Oracle E-Business Suite software. Unauthorized access occurred between July 10, 2025, and August 22, 2025. The Post was contacted by a bad actor in October 2025, leading to an investigation. Affected data includes names and other personal information. The Post secured systems, applied patches, and is offering identity protection services.
- 🍁Vermont State AGas victim2026-07-13
The Washington Post reported a data breach to the Vermont Attorney General. The breach was reported to the AGO on 2026-07-13. The reporting organization type is Other Commercial. 172 Vermont residents were affected. Categories of data breached: Social Security Numbers, Financial Account Codes, Credit and Debit Account Info.
- 🏎️Indiana State AGas victim2025-11-12
The Washington Post reported a data breach to the Indiana Attorney General. The breach occurred on 2025-07-10 and was reported on 2025-11-12. 45 Indiana residents were affected. 9,720 individuals affected in total.
- 🦬Montana State AGas victim2025-11-12
Washington Post reported a data breach to the Montana Attorney General. The breach was reported on 2025-11-12. The breach occurred from 07/10/2025 to 08/22/2025. 33 Montana residents were affected.
- ⛰️New Hampshire State AGas victim2025-11-12
The Washington Post notified the New Hampshire Attorney General of a data security incident involving a previously unknown vulnerability in its Oracle E-Business Suite. Unauthorized access occurred between July 10 and August 22, 2025. The Post confirmed on October 27, 2025, that personal information of current and former employees and contractors was accessed, including names, SSNs, and bank account numbers. 16 New Hampshire residents were notified on November 12, 2025. The Post applied patches and offered identity protection services.
- 🍁Vermont State AGas victim2025-11-12
The Washington Post disclosed a data breach affecting customer data (names, SSNs) due to exploitation of a zero-day vulnerability in Oracle E-Business Suite. The incident occurred between July 10 and August 22, 2025. The Post engaged forensic experts, secured systems, applied patches, and offered identity protection services. 9,562 Rhode Island residents were notified.
- 🦞Maine State AGas victim2025-11-12
The Washington Post reported a data breach to the Maine Attorney General, indicating that an external system breach (hacking) occurred on July 10, 2025. The breach was discovered on October 27, 2025. The incident affected 31 Maine residents. Affected individuals were notified on November 12, 2025, and offered 12 months of identity protection services from IDX.
- 🐻California State AGas victim2025-11-12
The Washington Post experienced a data breach due to a previously unknown vulnerability in Oracle E-Business Suite software. Between July 10 and August 22, 2025, unauthorized actors accessed and acquired data including names and Social Security numbers. The incident was discovered on October 27, 2025. The Post engaged forensic experts, secured systems, applied patches, and offered identity protection services to approximately 9,562 affected individuals.