Estée Lauder says it was hit by data breach caused by Oracle E-Business issue | TechRadar

July 21, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: techradar.com

Threat Risk: High
Victim: Estée Lauder
Incident: Unauthorized access to an HR management platform resulting in a massive data breach.
Impact: Theft of highly sensitive personal, financial, and health data, including SSNs and bank account numbers.
Attacker: Unidentified threat actors
Analysis: Threat actors exploited CVE-2025-61882, a critical pre-authentication RCE vulnerability in the Oracle E-Business Suite, to access HR management systems. This incident was part of a wider campaign targeting over 100 organizations. The breach is particularly concerning due to the significant delay between the initial intrusion in August 2025 and its disclosure in June 2026.
Recommendations: Apply the emergency patch for CVE-2025-61882 to all Oracle E-Business Suite installations.; Perform a comprehensive forensic audit of ERP and HR system logs to detect signs of historical unauthorized access.; Implement strict network segmentation and enhanced monitoring for critical internal business applications.
Source: TechRadar

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *