Estée Lauder has disclosed a significant data breach involving the theft of sensitive employee information after attackers exploited a critical vulnerability in its Oracle E-Business Suite HR system.
Key Points
- Unauthorized parties accessed the Oracle E-Business Suite system on or around August 9, 2025, through a vulnerability identified as CVE-2025-61882.
- Stolen data includes Social Security numbers, passport details, bank account information, health records, and employment history.
- The breach is linked to a mass-exploitation campaign by the Cl0p extortion gang, which targeted Oracle systems globally throughout August 2025.
- Estée Lauder is providing 24 months of free identity monitoring services through Kroll to affected individuals until the October 31, 2026, deadline.
- Oracle released security patches for the affected software versions, ranging from 12.2.3 to 12.2.14, on October 4, 2025.