logo

Estée Lauder discloses data breach tied to Oracle EBS vulnerability

ID: ede05823-9d20-5335-8328-b42c8bdca33b

STIX ID: report--ede05823-9d20-5335-8328-b42c8bdca33b

Feed Name: Help Net Security

Threat Score
80/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

Author: Sinisa Markovic

...
...

Estée Lauder disclosed that an unauthorized party exploited a vulnerability in Oracle E-Business Suite (CVE-2025-61882) to access HR systems around August 9, 2025, resulting in exfiltration of sensitive personal data (names, SSNs, passport and bank numbers, health and employment records); the activity aligns with a broader mass-exploitation campaign tied to the Cl0p extortion gang, Oracle released fixes on October 4, 2025, and Estée Lauder engaged external cyber teams, notified law enforcement, and offered 24 months of identity monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.