DoorDash Confirms October 2025 Data Breach After Employee Social Engineering Attack
DoorDash reported a new data breach from October 2025, triggered when an employee was deceived through a social engineering scam. The attacker accessed and stole user contact information, including names, addresses, phone numbers, and emails for customers, Dashers, and merchants. DoorDash says no financial data or government ID numbers were taken, though the scope of impacted regions remains unclear. The company faced criticism for taking nearly three weeks to notify affected users, with some claiming the delay violates Canadian breach-notification requirements. This is DoorDash’s third major security incident, following breaches in 2019 and 2022. The company has since enhanced security controls, brought in forensic experts, and warned users to watch for phishing attempts.
Washington Post Data Breach Linked to Zero-Day Vulnerability in Oracle E-Business Suite
The Washington Post discovered on October 27,2025 and then disclosed that a data breach occurred after attackers exploited an unknown vulnerability in Oracle’s E-Business Suite software used by the company. A threat actor contacted the Post claiming access, prompting a forensic investigation that confirmed unauthorized entry between July 10 and August 22, 2025. The vulnerability, later identified by Oracle as widespread and affecting multiple customers, allowed attackers to access and extract data without detection. Compromised information included individuals’ names paired with Social Security numbers or tax ID numbers. The Post has since secured its systems, applied Oracle’s patches, and reviewed affected data to identify impacted individuals. It is offering complimentary identity protection services and guidance on how users can safeguard their personal information.
SitusAMC Data Breach Prompts JPMorgan, Citi, and Morgan Stanley to Assess Exposure
A cyberattack on mortgage technology vendor SitusAMC has prompted major US banks, including JPMorgan, Citi, and Morgan Stanley, to assess potential exposure of customer data. The breach, discovered on November 12 and confirmed later in the month, involved unauthorized access to corporate records and possibly sensitive mortgage-related customer information. While the FBI reports no operational disruption to banking services, investigators say attackers focused on data theft rather than ransomware. SitusAMC has contained the incident and implemented remediation steps such as credential resets, firewall updates, and tightened security controls. The breach highlights accelerating third-party risk in financial services, where vendor-related incidents have risen sharply over the past two years. Regulatory pressure is also increasing, with NYDFS, the SEC, and FINRA reinforcing that financial institutions remain fully accountable for cybersecurity when outsourcing critical functions.
Congressional Budget Office Hack Signals Escalating Threat to U.S. Government Agencies
The Congressional Budget Office confirmed it was breached by a suspected foreign threat actor, raising concerns that sensitive economic analyses, draft reports, and communications with congressional offices may have been exposed. Officials say the intrusion was detected early, but some lawmakers have reportedly stopped emailing the CBO out of caution. The agency has contained the incident, strengthened monitoring, and deployed new security controls while continuing its operations for Congress. The attack follows a broader pattern of government-targeted intrusions, including breaches at the U.S. Treasury and CFIUS attributed to the Chinese state-backed group Silk Typhoon. This context suggests the CBO hack may be part of an ongoing campaign against U.S. government institutions. The incident underscores the strategic value adversaries place on compromising nonpartisan analytical agencies that influence federal policymaking.
UPenn, Princeton, and Harvard Hit by Major Cyberattacks Targeting Donor and Alumni Data
The University of Pennsylvania disclosed a major cyberattack in which threat actors used stolen employee credentials to access Salesforce, SAP, Qlik, SharePoint, and Box systems, stealing 1.71 GB of internal documents and a donor database containing roughly 1.2 million detailed records. After losing wider access, the attackers still controlled Penn’s Salesforce Marketing Cloud and sent offensive mass emails to about 700,000 recipients. Princeton University separately confirmed a phishing-based breach that exposed biographical and contact information for alumni, donors, students, parents, faculty, and staff, although no financial data or Social Security numbers were stored in the compromised system. Princeton says the intruders were removed before they could reach other university systems.
Harvard University also reported that its Alumni Affairs and Development systems were compromised in a voice-phishing attack, exposing contact details, biographical data, event records, and donation information tied to alumni, donors, parents, and some students, faculty, and staff. Harvard emphasized that the affected systems did not contain Social Security numbers, payment data, or passwords, and it immediately revoked the attacker’s access while launching a forensic investigation with law enforcement and third-party experts. The university is simultaneously investigating a separate October incident linked to an Oracle E-Business Suite zero-day claimed by the Clop ransomware gang. Collectively, these Ivy League breaches illustrate a growing trend of threat actors targeting donor and alumni systems, where large volumes of high-value personal and engagement data are concentrated.