Estée Lauder confirms data breach following Oracle E-Business Suite vulnerability

July 21, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: itbranschen.com

Threat Risk: High
Victim: Estée Lauder
Incident: Unauthorized access to an HR management system via an Oracle E-Business Suite vulnerability.
Impact: Exposure of sensitive PII including Social Security Numbers, passport details, bank accounts, and salary information.
Attacker: Likely Clop ransomware group
Analysis: The breach resulted from the exploitation of an authentication bypass vulnerability in Oracle E-Business Suite, likely CVE-2025-61882. This flaw allowed unauthorized actors to access the BI Publisher Integration component and exfiltrate highly sensitive HR records. The incident aligns with a broader wave of attacks targeting large enterprises using the same vector.
Recommendations: Apply the latest security updates for Oracle E-Business Suite immediately; Implement strict multi-factor authentication (MFA) across all HR and business management platforms; Conduct a comprehensive audit of access logs for the BI Publisher Integration component
Source: itbranschen.com

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *