Estee Lauder data breach linked to Oracle E-Business Suite flaw

Cosmetics giant Estee Lauder notifies customers of a data breach tied to a Clop-exploited Oracle E-Business Suite vulnerability.

CSBadmin
1 Min Read

Cosmetics giant Estee Lauder has begun notifying customers of a data breach after attackers exploited a vulnerability in Oracle E-Business Suite, the system the company used for HR operations.

The intrusion occurred on August 9, 2025, but was not fully identified until June 19, 2026. Exposed data includes full names, addresses, Social Security numbers, passport numbers, financial account details, and health and employment records.

The vulnerability, tracked as CVE-2025-61882, affects Oracle E-Business Suite versions 12.2.3 through 12.2.14. It allows unauthenticated remote code execution through the BI Publisher Integration component. Oracle released patches on October 4, 2025, after the Clop ransomware gang exploited the flaw as a zero-day in a mass-extortion campaign.

Other victims of the same Clop campaign include Harvard, the University of Pennsylvania, Dartmouth, The Washington Post, and Logitech. Estee Lauder is offering 24 months of complimentary identity monitoring through Kroll for affected individuals.

The company was also hit by Clop in 2023 through a zero-day in the MOVEit Transfer platform.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.