Estée Lauder customer data compromised in Oracle E-Business Suite breach | brief | SC Media

July 22, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: scworld.com

Threat Risk: High
Victim: Estée Lauder
Incident: Data breach resulting from the exploitation of CVE-2025-61882 in Oracle E-Business Suite.
Impact: Exposure of extensive PII, including SSNs, passport numbers, and financial account details.
Attacker: Clop ransomware gang
Analysis: Threat actors leveraged CVE-2025-61882 to bypass authentication and execute remote code within the Oracle E-Business Suite environment. The attack targeted HR operations, leading to the theft of highly sensitive PII including Social Security and passport numbers. This event is part of a wider campaign attributed to the Clop ransomware gang.
Recommendations: Patch Oracle E-Business Suite to versions beyond 12.2.14 immediately.; Implement strict network segmentation for HR and financial management systems.; Enable enhanced monitoring for authentication bypass attempts in enterprise software.
Source: SC Media

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *