Estée Lauder Confirms Cyberattack Affecting Personal Information
ID: 945fbaf6-3874-5a72-bfd1-90e661926bb3
STIX ID: report--945fbaf6-3874-5a72-bfd1-90e661926bb3
Feed Name: The Cyber Express
Estée Lauder disclosed that an unauthorized party exploited a vulnerability in Oracle E-Business Suite (timeline consistent with CVE-2025-61882) to access HR systems on or around August 9, 2025, resulting in theft of sensitive PII and financial data; the incident, attributed to the Clop ransomware group and part of a broader campaign affecting multiple organizations, was identified and scoped by the company in June 2026, and Estée Lauder is offering 24 months of identity monitoring to affected individuals.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
