Estée Lauder discloses data breach tied to Oracle EBS vulnerability – Help Net Security

July 21, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: helpnetsecurity.com

Threat Risk: High
Victim: Estée Lauder
Incident: Unauthorized access to Oracle E-Business Suite resulting in a massive data breach.
Impact: Theft of highly sensitive PII, including Social Security numbers, bank accounts, and health information.
Attacker: Cl0p extortion gang
Analysis: The breach stemmed from the exploitation of CVE-2025-61882, a zero-day RCE vulnerability in Oracle E-Business Suite. The timing and attack vector strongly suggest the involvement of the Cl0p extortion group, known for targeting large-scale enterprise software. This incident underscores the severe risk posed by unpatched ERP systems managing sensitive HR data.
Recommendations: Immediately update Oracle E-Business Suite to a version that mitigates CVE-2025-61882.; Implement strict network segmentation and access controls for HR and payroll management systems.; Establish enhanced monitoring for unauthorized HTTP requests targeting enterprise application suites.
Source: Help Net Security

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *