Clustered 4 filings across 4 jurisdictions · filing window Jul 13, 2026 → Jul 14, 2026. View entity profile → Other incidents for this victim →
incident inc_b01bca98f3034491 · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Identity (basic) · Government ID · Financial account
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
CA OR TX VT
all State AG
Earliest sighting first · deep chronology in Litigation Timeline
Jul 10, 2025 → Aug 22, 2025
When the intrusion reportedly occurred, per the linked filings
Sep 29, 2025
Reported by OREGON AG filing
Oct 1, 2025
Reported by CALIFORNIA AG filing
Jun 10, 2026
Reported by TEXAS AG filing
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
The Washington Post experienced a data security incident due to a previously unknown vulnerability in Oracle E-Business Suite software. Unauthorized access occurred between July 10, 2025, and August 22, 2025. The Post was contacted by a bad actor in October 2025, leading to an investigation. Affected data includes names and other personal information. The Post secured systems, applied patches, and is offering identity protection services.
The Washington Post reported a data breach to the Vermont Attorney General. The breach was reported to the AGO on 2026-07-13. The reporting organization type is Other Commercial. 172 Vermont residents were affected. Categories of data breached: Social Security Numbers, Financial Account Codes, Credit and Debit Account Info.
The Washington Post reported a data breach to the Oregon Attorney General. The breach was reported on 2026-07-14. The breach occurred during 9/29/2025. The breach was discovered on 9/29/2025. 323 individuals were affected. Notice was sent on 7/10/2026.
Affected (this filing): 323
The Washington Post based in Washington, District of Columbia, a business – retail or merchant entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-06-10 and reported on 2026-07-14. 862 Texas residents were affected. 36,358 individuals affected in total. Types of information involved: Name of individual;Social Security Number Information;Government-issued ID number (e.g. passport, state ID card);Financial Information (e.g. account number, credit or debit card number);Health Insurance Information. Consumers were notified via U.S. Mail.
Affected (this filing): 862