Skip to content

Estée Lauder: Data Breach via Oracle Vulnerability CVE-2025-61882

The Bottom Line: Ransomware gang Clop compromised Estée Lauder’s Oracle E-Business Suite through CVE-2025-61882 and stole employee and customer data at scale.

Estée Lauder confirms a data breach in which attackers exploited a critical vulnerability in Oracle E-Business Suite. The intrusion occurred on August 9, 2025, but was only discovered in June 2026.

US cosmetics conglomerate Estée Lauder is notifying affected individuals of a data breach affecting its systems. On August 9, 2025, attackers gained unauthorized access to the internal Oracle E-Business Suite used for personnel processes. Discovery did not occur until June 19, 2026, representing a window of approximately ten months. The incident affects a large corporation with 57,000 employees worldwide and $14.3 billion in annual revenue.

The attack resulted in theft of extensive data categories: full names, postal addresses, email addresses, dates of birth, Social Security numbers, passport numbers, financial and bank account information, health data, and employment data including salary and performance reports. The theft of these combinations enables identity theft at substantial scale and poses long-term risks for affected individuals, particularly through the availability of bank data and document numbers.

Ransomware gang Clop exploited the critical vulnerability CVE-2025-61882 in Oracle E-Business Suite versions 12.2.3 through 12.2.14 as a zero-day. The vulnerability enabled authentication bypass and malicious code execution via the BI Publisher integration. Oracle released security updates only on October 4, 2025. The ransomware gang leveraged this window between August and October for a widespread campaign that affected additional organizations including universities, logistics providers, and media companies alongside Estée Lauder.

This is not the first attack by this group on Estée Lauder: in 2023, Clop already compromised the company’s systems through a vulnerability in MOVEit Transfer. In response, Estée Lauder is offering affected individuals two years of free identity monitoring through service provider Kroll. For CISOs, this case is an indicator of the necessity to prioritize security updates for critical enterprise software within days rather than weeks, as well as to protect systems with broad data access (such as human resources software) with additional segmentation and monitoring.


Source: www.it-daily.net · Published July 21, 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: