Estée Lauder discloses data breach via Oracle E-Business flaw
Cosmetics giant Estée Lauder is notifying employees of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. [...]
AI Analysis
Technical Summary
This incident involves a data breach at Estée Lauder caused by exploitation of CVE-2025-61882, a critical vulnerability in Oracle E-Business Suite versions 12.2.3 through 12.2.14. The flaw allows attackers to bypass authentication and execute code remotely through the BI Publisher Integration component, compromising sensitive HR and business data. The breach was identified in June 2026 but occurred in August 2025, coinciding with a known mass exploitation campaign by the Clop ransomware group. Oracle issued an official patch on October 4, 2025. The breach exposed extensive personal information including social security numbers, passport numbers, financial and health information. Estée Lauder has notified affected individuals and is providing complimentary identity monitoring services.
Potential Impact
The breach resulted in unauthorized access to sensitive personal data of individuals, including full names, postal addresses, email addresses, dates of birth, social security numbers, passport numbers, financial account details, health information, and employment records. This exposure increases the risk of identity theft and fraud for affected individuals. The vulnerability exploited allows remote code execution and authentication bypass, potentially compromising the confidentiality and integrity of HR and business systems. The incident is part of a broader exploitation campaign affecting multiple high-profile organizations.
Mitigation Recommendations
Oracle released an official patch for CVE-2025-61882 on October 4, 2025, which addresses the authentication bypass and remote code execution vulnerability in Oracle E-Business Suite versions 12.2.3 through 12.2.14. Organizations using affected versions should apply this patch immediately if not already done. Estée Lauder is advising affected individuals to monitor for identity theft and fraud and is providing 24 months of complimentary identity monitoring services. No additional mitigation guidance is provided by the vendor advisory. Patch status is confirmed as fixed by Oracle's official update.
Estée Lauder discloses data breach via Oracle E-Business flaw
Description
Cosmetics giant Estée Lauder is notifying employees of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. [...]
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This incident involves a data breach at Estée Lauder caused by exploitation of CVE-2025-61882, a critical vulnerability in Oracle E-Business Suite versions 12.2.3 through 12.2.14. The flaw allows attackers to bypass authentication and execute code remotely through the BI Publisher Integration component, compromising sensitive HR and business data. The breach was identified in June 2026 but occurred in August 2025, coinciding with a known mass exploitation campaign by the Clop ransomware group. Oracle issued an official patch on October 4, 2025. The breach exposed extensive personal information including social security numbers, passport numbers, financial and health information. Estée Lauder has notified affected individuals and is providing complimentary identity monitoring services.
Potential Impact
The breach resulted in unauthorized access to sensitive personal data of individuals, including full names, postal addresses, email addresses, dates of birth, social security numbers, passport numbers, financial account details, health information, and employment records. This exposure increases the risk of identity theft and fraud for affected individuals. The vulnerability exploited allows remote code execution and authentication bypass, potentially compromising the confidentiality and integrity of HR and business systems. The incident is part of a broader exploitation campaign affecting multiple high-profile organizations.
Defensive Guidance
Oracle released an official patch for CVE-2025-61882 on October 4, 2025, which addresses the authentication bypass and remote code execution vulnerability in Oracle E-Business Suite versions 12.2.3 through 12.2.14. Organizations using affected versions should apply this patch immediately if not already done. Estée Lauder is advising affected individuals to monitor for identity theft and fraud and is providing 24 months of complimentary identity monitoring services. No additional mitigation guidance is provided by the vendor advisory. Patch status is confirmed as fixed by Oracle's official update.
Technical Details
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/est-e-lauder-discloses-data-breach-via-oracle-e-business-flaw/","fetched":true,"fetchedAt":"2026-07-20T23:11:49.089Z","wordCount":758}
- Classification
- {"confidence":0.88,"severitySource":"default","classifier":"rss-v2"}
Threat ID: 6a5eab352a4a8d5989eb3ebd
Added to database: 07/20/2026, 23:11:49 UTC
Last enriched: 07/20/2026, 23:11:58 UTC
Last updated: 09/03/2026, 20:11:41 UTC
Views: 188
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.