Skip to content
Zero-dayContained

Estée Lauder data breach via Oracle E-Business Suite (Cl0p campaign)

Cosmetics group Estée Lauder disclosed that attackers exploiting an Oracle E-Business Suite flaw accessed its HR system in August 2025, exposing Social Security numbers, passport and bank details, health data and employment records.

Part of campaigncl0p mass exploitation
Victim
The Estée Lauder Companies Inc.
Threat actorCl0p
CVECVE-2025-61882

On 21 July 2026, The Estée Lauder Companies disclosed a data breach stemming from unauthorized access to its Oracle E-Business Suite (EBS) system, which the company uses for human-resources management. The intrusion dated back to 9 August 2025, but the company only began investigating it on 19 June 2026, almost ten months later.

The disclosure tied the incident to CVE-2025-61882, a flaw in Oracle EBS versions 12.2.3 to 12.2.14 that let unauthenticated attackers with network access execute code remotely over HTTP. Google and Mandiant researchers had confirmed in October 2025 that the Cl0p extortion gang exploited multiple Oracle EBS vulnerabilities in a mass data-theft campaign beginning in August 2025, before Oracle shipped its fix on 4 October 2025.

What was exposed

According to the notification, the compromised information included names, postal and email addresses, dates of birth, Social Security numbers, passport numbers, bank account numbers, health information and employment records such as performance evaluations and payroll history. The company did not publish a total count of affected individuals. Estée Lauder said it brought in outside cybersecurity experts, notified law enforcement, added safeguards to the system and offered 24 months of free identity monitoring through Kroll, with an enrollment deadline of 31 October 2026.

Why it matters

The case shows the long tail of Cl0p's mass-exploitation model: a single pre-authentication bug in a widely deployed business application yields data from many victims at once, and individual disclosures keep surfacing a year later. Because HR systems hold the richest identity data a company keeps, an ERP flaw can expose employees' financial and government identifiers even when no customer-facing system is touched.

Timeline

  1. An unauthorized party accesses Estée Lauder's Oracle E-Business Suite environment used for HR management.

  2. Oracle releases fixes for CVE-2025-61882, the E-Business Suite flaw exploited by Cl0p in its mass data-theft campaign.

  3. Estée Lauder opens an investigation into the compromise.

  4. The company discloses the breach, including in a notification filed with California's Attorney General, and offers 24 months of identity monitoring through Kroll.

Sources

  1. helpnetsecurity.comhttps://www.helpnetsecurity.com/2026/07/21/estee-lauder-data-breach-oracle-ebs/
  2. gurufocus.comhttps://www.gurufocus.com/news/8972264/este-lauder-el-reports-data-security-incident-affecting-customer-information
  3. cloud.google.comhttps://cloud.google.com/blog/topics/threat-intelligence/oracle-ebusiness-suite-zero-day-exploitation

Related incidents