Skip to main content
Back to overview
Medium

Foreign-State Hack Suspected in Washington Post Journalist Email Breach

Major Cyber Attacks, Ransomware Attacks and Data Breaches of June 2025 United Natural Foods, North Face, Cartier, Zoom Car, Episource, WestJet, The Washington Post.

Key points

  • Targeted cyberattack discovered in mid-June 2025.
  • Microsoft email accounts of select journalists compromised.
  • Breach first flagged on June 12, 2025.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Ransomware

Malware, Hacking activity

03

Potential impact

Data Exposure

Confidentiality, Availability

Published
Jun 12, 2025
Updated
Jul 22, 2026
Confidence
Medium
Evidence
2 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Malware, Hacking activity

Watch ransomware, endpoint compromise and business interruption exposure.

  • Source type: possible insider or internal misuse

Business impact

Potential operational disruption
Impact area
Confidentiality, Availability
Likely asset
User or customer data

Mentioned entities

WashingtonpostData DisclosureForeign-State Hack SuspectedUnited Natural FoodsNorth FaceCartierZoom CarEpisourceWestJetThe Washington Post. What

Quick context

Questions about this signal

What happened in this signal?

Major Cyber Attacks, Ransomware Attacks and Data Breaches of June 2025 United Natural Foods, North Face, Cartier, Zoom Car, Episource, WestJet, The Washington Post. What do they have in common? Very little except that all of them fell victim to cyber crime or its damaging effects in June 2025. From unauthorised access to internal systems to major disruptions in operations and order fulfilment, the impact of the cyber incidents has been as damaging as ever. In many cases, millions of customer and employee accounts have been breached, exposing sensitive customer information. The writing on the wall is clear. Preparedness against cyber crime and building cyber resilience is an urgent priority for every business in the next six months of 2025. If you want your organisation to stand a chance against the devastating consequences of a cyber attack, you need to invest in more than just technology. The real differentiator lies in having a comprehensive Cyber Incident Response Plan backed by robust training. It's a business imperative now to proactively prepare through regular cyber tabletop exercises that simulate real-world attack scenarios. Stress-test your response capabilities across departments and rehearse these responses regularly. Only those organisations that combine the right tools with the right people, processes and preparation will be able to protect their brand, retain customer trust, and stay operational in the face of growing cyber threats. Vulnerabilities Discovered and Patches Released Advisories issued, reports, analysis etc. in June 2025 Durant (OK), Lorain County (OH), and Puerto Rico’s Justice Department Thousands impacted by cyber attacks on governments in Ohio, Oklahoma, Puerto Rico Ransomware attacks—likely linked to the RansomHub gang—have disrupted critical services for thousands across Durant (OK), Lorain County (OH), and Puerto Rico’s Justice Department, crippling courts, communications, and digital services as officials scramble to restore operations. Newspaper giant Lee Enterprises says nearly 40,000 Social Security numbers leaked in ransomware attack A ransomware attack by Qilin on newspaper giant Lee Enterprises exposed nearly 40,000 Social Security numbers, disrupted publishing operations nationwide, and caused $2 million in recovery costs along with significant revenue losses. Kettering Health confirms attack by Interlock ransomware group as health record system is restored Ohio’s Kettering Health confirmed a ransomware attack by the Interlock gang that disrupted internal systems, phone lines, and electronic health records across 14 hospitals, forcing procedure cancellations and ambulance diversions, with data including financial records reportedly stolen. Tax resolution firm Optima Tax Relief hit by ransomware, data leaked U.S. tax resolution firm Optima Tax Relief was hit by a double-extortion Chaos ransomware attack—resulting in 69 GB of sensitive corporate and client data, including tax documents, being stolen, encrypted, and leaked online by the threat actors. Sensata Technologies says personal data stolen by ransomware gang A ransomware attack in early April by an unknown threat group infiltrated Sensata Technologies’ network (March 28–April 6), encrypting systems and stealing personal and sensitive data—including SSNs, driver’s licenses, financial and medical information—for over 15,000 employees and dependents, now prompting identity monitoring offers South Korea's major ticketing platform Yes24 Ransomware attack on ticketing platform upends South Korean entertainment industry A ransomware attack by an unknown threat actor on South Korea's major ticketing platform Yes24 has disrupted online bookings, e-book access, and community forums for over four days, forcing cancellations and postponements of K-pop concerts and musicals, triggering a privacy investigation over potential customer data breaches, and echoing similar high-impact attacks on U.S. ticketing platforms like StubHub and Ticketmaster. Nearly 3,000 North Face website customer accounts breached as retail incidents continue A credential stuffing attack on The North Face exposed sensitive customer data—including names, addresses, and purchase history—of nearly 3,000 users, as part of a broader campaign likely linked to the Scattered Spider ransomware group.

When was this signal reported?

Shadow Tier lists Jun 12, 2025 as the signal date.

Which organization is connected to this signal?

Washingtonpost is the organization connected to this public signal.

Explore Washingtonpost
Which attack pattern is relevant?

This signal is connected to current ransomware incidents based on its reported incident context.

Explore current ransomware incidents
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence