Estée Lauder has disclosed a significant data breach resulting from an exploited flaw in the Oracle E-Business Suite used for human resource management. The breach occurred on August 9, 2025, but was only identified and disclosed by the company in June 2026.
The compromised data includes a wide range of sensitive personal information such as Social Security numbers, bank details, health, and employment information. The breach, stemming from a zero-day vulnerability CVE-2025-61882, enabled unauthorized access to the system.
The notorious Cl0p cybercrime group was linked to the exploitation of the Oracle EBS vulnerability that affected Estée Lauder as well as over a hundred other companies. This group employed the flaw to execute remote code and exfiltrate large volumes of sensitive data.
Cl0p included 870GB of Estée Lauder's data in their leak on a public site. Investigations led by firms such as CrowdStrike revealed that exploitation aligned with the timeline of Estée Lauder's breach discovery.
Oracle addressed the zero-day vulnerability in October 2025, but companies including Estée Lauder were already significantly affected. Several of the attacked companies, like Broadcom and Bechtel, had also experienced similar breaches but had yet to discuss the full impact.
This incident highlights the critical importance of timely patch management and the risks associated with zero-day vulnerabilities, especially within systems handling sensitive data like HR operations.
Estée Lauder's breach underlines the broader cybersecurity challenge posed by sophisticated threat actors exploiting unpatched vulnerabilities. Affected individuals have been notified and efforts to secure and patch vulnerable systems are ongoing.
The incident has prompted industry-wide scrutiny of Oracle EBS deployments and security protocols, emphasizing the need for enhanced monitoring and preventive measures against such exploits.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Estée Lauder revealed that employee data was stolen during a zero-day attack on its Oracle EBS. The breach, linked to the Cl0p cybercrime group, exposed sensitive personal information and affected numerous companies.
Estée Lauder has disclosed a data breach involving a vulnerability in Oracle E-Business Suite, which was exploited to access personal customer data. The breach, identified on June 19, 2026, occurred on August 9, 2025, and included sensitive information such as Social Security numbers and financial details.