Cox Enterprises has notified customers that it was affected by a security incident tied to a zero-day vulnerability — a previously unknown flaw — in Oracle’s E-Business Suite, a platform the company used for some of its back-office operations. According to the letter, cybercriminals exploited this flaw between August 9 and August 14, 2025, in an attack that hit many companies using Oracle’s systems, not Cox alone. Cox says it became aware of suspicious activity on September 29, 2025, brought in outside cybersecurity experts, applied Oracle’s fix once available, and contacted law enforcement. On October 31, 2025, the company determined that some recipients’ personal information may have been involved. This falls under a broader pattern of attacks where a single flaw in shared software from a third-party vendor can ripple out to many organizations at once — a dynamic also seen in incidents like the ransomware attack claimed against WIS Logistics.
The letter is addressed to an individual recipient, and Cox has not published an aggregate number of people affected in the text provided here. The notice confirms that the recipient’s name was among the information involved, but it relies on placeholder text for any additional specific data categories, so the exact scope of information tied to this notice isn’t fully spelled out.
What information was exposed?
- Name
Cox is offering free credit monitoring and identity theft protection through IDX for either 12 or 24 months, depending on the individual letter. To enroll, visit https://app.idx.us/account-creation/protect or call 1-833-778-2773 and use the Enrollment Code included in your specific letter. You have until February 20, 2026 to enroll.
What should you do now?
- Enroll in the free IDX credit monitoring and identity theft protection before the February 20, 2026 deadline, using the code in your letter.
- Review your credit reports and bank or credit card statements for any activity you don’t recognize, and report anything suspicious right away.
- Order a free copy of your credit report at annualcreditreport.com and check the accounts and inquiries sections for anything unfamiliar.
- Consider placing a fraud alert or a security freeze on your credit file with Equifax, Experian, and TransUnion for extra protection against new accounts being opened in your name.
- Since only your name is confirmed in this notice, be cautious of unexpected calls, emails, or texts that reference this breach and ask for more personal details — legitimate follow-up will come through the contact channels Cox provided.
- For ongoing peace of mind, consider signing up for a service like Aura or LifeLock, which can alert you if your information appears elsewhere.
If you have questions, Cox Enterprises can be reached at 1-833-778-2773 (Monday through Friday, 9 am to 9 pm Eastern) or by mail at Cox Enterprises, Inc., Return Mail Processing Center, P.O. Box 1907, Suwanee, GA 30024.