Ex-Employee Sues Washington Post Over Oracle EBS-Related Data Breach
好,我现在需要帮用户总结一篇文章的内容,控制在100字以内。首先,我得仔细阅读文章,抓住主要信息。 文章讲的是《华盛顿邮报》的数据泄露事件,导致近1万名员工和前员工的个人信息被暴露。一个前员工Jun Hee Kim提起了集体诉讼,指控邮报没有采取足够的网络安全措施。数据泄露是因为Oracle EBS软件中的零日漏洞被利用,导致大量个人信息被盗,包括银行账户、社保号等。邮报已经应用了补丁,并提供身份保护服务。 接下来,我需要把这些信息浓缩到100字以内。要包括:数据泄露事件、受影响人数、集体诉讼的原因、漏洞来源、受影响的数据类型以及邮报的应对措施。 可能的结构是:《华盛顿邮报》因数据泄露被起诉,近1万人受影响,涉及Oracle软件漏洞,导致个人信息被盗,邮报已修复并提供保护服务。 这样既涵盖了主要事件和原因,又简洁明了。 </think> 《华盛顿邮报》因数据泄露被起诉,近万名员工及前员工信息遭窃,源于Oracle软件漏洞,受害者要求赔偿并加强安全措施。 2025-12-8 05:16:50 Author: securityboulevard.com(查看原文) 阅读量:60 收藏

An ex-Washington Post employee reportedly is suing the news organization in the wake of a data breach the exposed the personal data of almost 10,000 current and former workers, saying the company failed to put adequate protections in place.

According to Politico, Jun Hee Kim, who worked at the Post in 2018 and 2019, filed a class action lawsuit that includes the 9.720 people potentially victimized by the hack, which includes not only employees but also independent contractors and contributors, who reportedly included former National Security Adviser John Bolton.

Kim reportedly in the lawsuit claims the data breach at the storied news outlet was the result of the Post failing to “implement adequate and reasonable cybersecurity procedures and protocols.” He also says he and other victims have suffered financially due to their data being stolen and that they want the Post to compensate them for identity theft and monitoring services.

He also is demanding that the news organization hardened its data security.

Growing List of Victims

The Post, which has more than 3,000 employees and about 2.5 million digital subscribers – is among a growing number of victims – with some estimates closing in on 100 companies – stemming from a threat group’s exploitations of a zero-day critical vulnerability (tracked as CVE-2025-61882) and other security flaws in Oracle’s E-Business Suite (EBS), a collection of enterprise software used to manage business functions like financials, human resources, supply chain, and customer relationship management (CRM).

Security researchers, including those from Google Threat Intelligence Group and Google’s Mandiant business, in October wrote in a report that the notorious Cl0p ransomware group was taking credit for the attacks on the Oracle EBS software and was sending extortion emails to corporate executives.

The vulnerabilities have allowed bad actors to access the accounts of EBS customers. CVE-2025-61882 can be exploited remotely without the need for authentication, according to Oracle, which issued fixes.

Vulnerabilities Detected

The Post reported its data breach last month, joining a list of victims that include higher education institutions like Harvard University and Dartmouth College and corporations, such as Logitech, Hitachi subsidiary GlobalLogic, Broadcom, Mazda, and Humana.

In notices sent out in November to victims, the Post wrote that it was contacted by a threat actor on September 29 claiming to have gained access to its Oracle EBS applications. An investigation by the news organizations and “experts” detected a “previously unknown and widespread vulnerability” in its Oracle EBS software that allowed for unauthorized access.

The investigation found that the bad actor stole personal data between July 10 and August 22, and the Post confirmed October 27 that personal information of employees – both current and former – and contractors was stolen. The data varies by victim, but could include names, bank account numbers and associated routing numbers, Social Security numbers, and tax ID numbers.

Fixes Applied

The Post applied the fixes issued by Oracle and is providing victims with complementary ID protection services via data breach response and consumer privacy services firm IDX.

Kim, the former Post employee, is being represented by Migliaccio & Rathod LLP, one of a number of law firms – another being data breach specialist Strauss Borrelli PLLC – that launched an investigation into the data breach and a search for possible victims days after the newspaper notified the state of Maine about the breach and began sending out notices to impacted individuals.

Recent Articles By Author


文章来源: https://securityboulevard.com/2025/12/ex-employee-sues-washington-post-over-oracle-ebs-related-data-breach/
如有侵权请联系:admin#unsafe.sh