logo

Estée Lauder discloses data breach via Oracle E-Business flaw

ID: 2c34ee43-ca22-527f-a371-9db271646bba

STIX ID: report--2c34ee43-ca22-527f-a371-9db271646bba

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

Author: Bill Toulas

...
...

Estée Lauder disclosed that an intrusion on or around August 9, 2025 exploited a flaw in Oracle E-Business Suite (aligned with CVE-2025-61882) to access HR data and obtain sensitive personal information (names, addresses, DOBs, SSNs, passport and bank details, health and employment records); the incident is tied to the Clop mass-exploitation campaign that affected numerous universities and companies and the firm is offering 24 months of identity monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.