Supply chain
β Supply Chain
The Washington Post Third-Party Breach (November 2025)
Primary Source βIncident Details
In 2025, The Washington Post experienced a data security incident via a third-party vendor relationship. The
compromised third-party vendor was Oracle E-Business Suite. Source reporting:
https://www.bleepingcomputer.com/news/security/washington-post-data-breach-impacts-nearly-10k-employees-contractors/
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Oracle E-Business Suite
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2025-11-01 Breach occurred
- 2025-11-01 Publicly disclosed