Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Estée Lauder discloses data breach via Oracle E-Business flaw

0
Medium
Exploitrce
Published: 07/20/2026 (07/20/2026, 22:39:30 UTC)
Source: Bleeping Computer

Description

Estée Lauder disclosed a data breach resulting from exploitation of a vulnerability in Oracle E-Business Suite used for HR operations. The breach occurred around August 9, 2025, allowing unauthorized access to personal information including names, addresses, SSNs, passport numbers, financial and health data. The exploited flaw corresponds to CVE-2025-61882, which enables authentication bypass and remote code execution via the BI Publisher Integration component. Oracle released a patch for this vulnerability on October 4, 2025. The breach is part of a wider campaign by the Clop ransomware group targeting multiple organizations. Estée Lauder is offering identity monitoring services to affected individuals.

Affected software

Affected versions
>=12.2.3 <=12.2.14

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/20/2026, 23:11:58 UTC

Technical Analysis

This incident involves a data breach at Estée Lauder caused by exploitation of CVE-2025-61882, a critical vulnerability in Oracle E-Business Suite versions 12.2.3 through 12.2.14. The flaw allows attackers to bypass authentication and execute code remotely through the BI Publisher Integration component, compromising sensitive HR and business data. The breach was identified in June 2026 but occurred in August 2025, coinciding with a known mass exploitation campaign by the Clop ransomware group. Oracle issued an official patch on October 4, 2025. The breach exposed extensive personal information including social security numbers, passport numbers, financial and health information. Estée Lauder has notified affected individuals and is providing complimentary identity monitoring services.

Potential Impact

The breach resulted in unauthorized access to sensitive personal data of individuals, including full names, postal addresses, email addresses, dates of birth, social security numbers, passport numbers, financial account details, health information, and employment records. This exposure increases the risk of identity theft and fraud for affected individuals. The vulnerability exploited allows remote code execution and authentication bypass, potentially compromising the confidentiality and integrity of HR and business systems. The incident is part of a broader exploitation campaign affecting multiple high-profile organizations.

Mitigation Recommendations

Oracle released an official patch for CVE-2025-61882 on October 4, 2025, which addresses the authentication bypass and remote code execution vulnerability in Oracle E-Business Suite versions 12.2.3 through 12.2.14. Organizations using affected versions should apply this patch immediately if not already done. Estée Lauder is advising affected individuals to monitor for identity theft and fraud and is providing 24 months of complimentary identity monitoring services. No additional mitigation guidance is provided by the vendor advisory. Patch status is confirmed as fixed by Oracle's official update.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.bleepingcomputer.com/news/security/est-e-lauder-discloses-data-breach-via-oracle-e-business-flaw/","fetched":true,"fetchedAt":"2026-07-20T23:11:49.089Z","wordCount":758}

Threat ID: 6a5eab352a4a8d5989eb3ebd

Added to database: 07/20/2026, 23:11:49 UTC

Last enriched: 07/20/2026, 23:11:58 UTC

Last updated: 07/21/2026, 09:59:01 UTC

Views: 18

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses