AUTO-UPDATED

Estée Lauder discloses data breach tied to Oracle EBS vulnerability

Estée Lauder has disclosed a significant data breach involving the theft of sensitive employee information after attackers exploited a critical vulnerability in its Oracle E-Business Suite HR system.

Key Points

  • Unauthorized parties accessed the Oracle E-Business Suite system on or around August 9, 2025, through a vulnerability identified as CVE-2025-61882.
  • Stolen data includes Social Security numbers, passport details, bank account information, health records, and employment history.
  • The breach is linked to a mass-exploitation campaign by the Cl0p extortion gang, which targeted Oracle systems globally throughout August 2025.
  • Estée Lauder is providing 24 months of free identity monitoring services through Kroll to affected individuals until the October 31, 2026, deadline.
  • Oracle released security patches for the affected software versions, ranging from 12.2.3 to 12.2.14, on October 4, 2025.

Why it Matters

This incident highlights the severe risks posed by unpatched vulnerabilities in enterprise resource planning software used to manage sensitive human resources data. The exposure of highly personal information underscores the critical need for organizations to prioritize rapid patch management to prevent large-scale data exfiltration by sophisticated cybercriminal groups.
Help Net Security Published by Sinisa Markovic
Read original