Estée Lauder discloses data breach tied to Oracle EBS vulnerability
ID: ede05823-9d20-5335-8328-b42c8bdca33b
STIX ID: report--ede05823-9d20-5335-8328-b42c8bdca33b
Feed Name: Help Net Security
Estée Lauder disclosed that an unauthorized party exploited a vulnerability in Oracle E-Business Suite (CVE-2025-61882) to access HR systems around August 9, 2025, resulting in exfiltration of sensitive personal data (names, SSNs, passport and bank numbers, health and employment records); the activity aligns with a broader mass-exploitation campaign tied to the Cl0p extortion gang, Oracle released fixes on October 4, 2025, and Estée Lauder engaged external cyber teams, notified law enforcement, and offered 24 months of identity monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
