Estée Lauder Discloses Data Breach Stemming from Oracle E-Business Suite Flaw
Cosmetics giant **Estée Lauder** has confirmed a data breach impacting personal information of certain individuals. The incident, which occurred in August 2025, exploited a vulnerability in the **Oracle E-Business Suite** used for HR operations, aligning with a broader campaign by the **Clop** ransomware gang.

**Estée Lauder**, the New York-based cosmetics powerhouse, is currently notifying customers and affected individuals about a significant data breach. The company traced an intrusion to August 9, 2025, where an unauthorized actor gained access to its **Oracle E-Business Suite (EBS)** system, used specifically for human resources (HR) management.
### The Vulnerability: CVE-2025-61882
While **Estée Lauder**'s notification does not explicitly name the vulnerability, the timeline strongly suggests exploitation of **CVE-2025-61882**. This flaw in **Oracle EBS** versions 12.2.3–12.2.14 allowed attackers to bypass authentication and execute code remotely via the BI Publisher Integration component. This access could potentially expose highly sensitive HR and business data.
Security researchers from **Google** and **Mandiant** initially warned of mass exploitation targeting this **Oracle EBS** zero-day in October 2025, attributing attacks to the **Clop** ransomware group. **Oracle** subsequently released patches for **CVE-2025-61882** on October 4, 2025. Cybersecurity firm **CrowdStrike** later confirmed that **Clop** had been actively exploiting the vulnerability since early August 2025.
### Compromised Data
The disclosed data, according to a sample notification letter, is extensive and highly sensitive. It includes:
* Full names
* Postal addresses
* Email addresses
* Dates of birth
* Social Security numbers (SSNs)
* Passport numbers
* Financial account information, including bank account numbers
* Health information
* Employment information, including payroll and performance reports
### Broader Impact and Previous Incidents
**Estée Lauder** is not an isolated incident. The **Clop** ransomware gang's campaign leveraging **CVE-2025-61882** has impacted numerous other prominent organizations. Notable victims include **Harvard**, the **University of Pennsylvania**, **Dartmouth**, the **University of Phoenix**, **The Washington Post**, **Logitech**, **GlobalLogic**, **Cox Enterprises**, and **American Airlines** subsidiary **Envoy Air**.
This is not **Estée Lauder**'s first encounter with **Clop**. In 2023, the cosmetics giant was also compromised when the threat actor exploited another zero-day in the **MOVEit Transfer** platform, a different internal software tool used by the company.
### Mitigation and User Guidance
**Estée Lauder** is advising all recipients of the breach notification letter to maintain heightened vigilance for any signs of identity theft or fraud. To support affected individuals, the company is providing 24 months of complimentary identity monitoring services through **Kroll**.