Estée Lauder Confirms Data Breach After Oracle Hack

July 23, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: safestate.com

Threat Risk: High
Victim: Estée Lauder
Incident: Data breach via exploitation of Oracle E-Business Suite.
Impact: Exposure of SSNs, passport numbers, bank details, and health information for current and former employees.
Attacker: Unidentified threat actors
Analysis: Attackers leveraged a critical zero-day vulnerability (CVE-2025-61882) in Oracle E-Business Suite to bypass authentication and execute remote code. The breach was characterized by a ten-month dwell time, allowing for the extensive extraction of high-value PII and financial data. This event is part of a wider global campaign targeting the same software flaw.
Recommendations: Immediately patch Oracle E-Business Suite to the latest secure version.; Implement strict monitoring for unauthorized authentication bypass attempts in HR systems.; Enable multi-factor authentication (MFA) across all critical enterprise management platforms.
Source: SafeState

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *