Data leak
The Washington Post Oracle E-Business Suite ERP Breach
Primary Source βIncident Details
The Washington Post disclosed in November 2025 that a breach of its Oracle E-Business Suite ERP system had exposed sensitive personal and financial data for approximately 10,000 current and former employees and contractors. The exploitation involved CVE-2025-61882, a critical Oracle EBS vulnerability. Exposed data included full legal names, bank account numbers, Social Security numbers, tax identification numbers, and other payroll-related identifiers. The Washington Post is the same Oracle EBS vulnerability class that was exploited against University of Phoenix in August 2025 (Clop) and several other organizations in the Oracle EBS exploitation wave of 2025.
Technical Details
- Initial Attack Vector
- Attackers exploited a vulnerability in Oracle E-Business Suite (ERP system) used by The Washington Post for HR and payroll management, exfiltrating employee and contractor personal and financial data
- Vendor / Product
- Oracle E-Business Suite (EBS)
- CVE / GHSA References
- CVE-2025-61882
Timeline
- 2025-10-01 Breach occurred
- 2025-11-15 Publicly disclosed
- 2025-11-15 Customers notified