Data leak

The Washington Post Oracle E-Business Suite ERP Breach

πŸ“… 2025-10-01 🏒 Oracle E-Business Suite (EBS) πŸ”Ž CVE-2025-61882
Primary Source β†—

Incident Details

The Washington Post disclosed in November 2025 that a breach of its Oracle E-Business Suite ERP system had exposed sensitive personal and financial data for approximately 10,000 current and former employees and contractors. The exploitation involved CVE-2025-61882, a critical Oracle EBS vulnerability. Exposed data included full legal names, bank account numbers, Social Security numbers, tax identification numbers, and other payroll-related identifiers. The Washington Post is the same Oracle EBS vulnerability class that was exploited against University of Phoenix in August 2025 (Clop) and several other organizations in the Oracle EBS exploitation wave of 2025.

Technical Details

Initial Attack Vector
Attackers exploited a vulnerability in Oracle E-Business Suite (ERP system) used by The Washington Post for HR and payroll management, exfiltrating employee and contractor personal and financial data
Vendor / Product
Oracle E-Business Suite (EBS)
CVE / GHSA References
CVE-2025-61882

Timeline

  1. 2025-10-01 Breach occurred
  2. 2025-11-15 Publicly disclosed
  3. 2025-11-15 Customers notified