Washington Post journalists targeted in suspected nation-state cyberattack

Washington Post journalists targeted in suspected nation-state cyberattack

A cyberattack on the well-known news outlet The Washington Post has compromised the email accounts of several of its journalists, with some evidence suggesting the breach may have been carried out by a foreign government, The Wall Street Journal reported.

According to an internal memo cited by the WSJ, Washington Post Executive Editor Matt Murray informed staff that the breach was discovered on Thursday and that a formal investigation is underway. The attack reportedly targeted journalists’ Microsoft accounts, potentially granting unauthorized access to sensitive work emails.

Sources familiar with the matter told the WSJ that reporters on the national security and economic policy teams, some of whom cover China, were among those affected.

The Washington Post has not yet issued a public statement or responded to requests for comment.

The incident follows a similar 2022 breach at News Corp, which owns the Wall Street Journal, where hackers compromised the email accounts of multiple journalists.

A recent Citizen Lab’s investigation revealed that at least two prominent European journalists were targeted by the Graphite spyware in early 2025. The spyware exploited a then-unknown zero-day vulnerability (CVE-2025-43200) in iOS 18.2.1, delivered via iMessage without any user interaction. The threat actor used an account, named in the research as ‘ATTACKER1,’ to send malicious messages that exploited CVE-2025-43200 for remote code execution. The vulnerability was patched in iOS 18.3.1 on February 10.


Back to the list

Latest Posts

Researchers caught embedding hidden AI prompts to sway research reviewers

Researchers caught embedding hidden AI prompts to sway research reviewers

The investigation analyzed English-language preprints published on the research platform arXiv and found concealed AI instructions in 17 papers.
7 July 2025
Brazilian programmer arrested for role in $185 million bank hack

Brazilian programmer arrested for role in $185 million bank hack

João Nazareno Roque, a junior back-end developer at C&M, was allegedly recruited by hackers in a bar in São Paulo.
7 July 2025
APT36 cyber-espionage campaign targeting Indian defense sector via BOSS Linux

APT36 cyber-espionage campaign targeting Indian defense sector via BOSS Linux

More recently, APT36 has shifted its focus to Linux-based environments.
7 July 2025