ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity

Estée Lauder discloses data breach tied to Oracle EBS vulnerability

criticalData breachimportance 60CVE-2025-61882

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-61882
Unauthenticated Takeover of Oracle E-Business Suite Concurrent Processing

CVE-2025-61882 is a critical (CVSS 9.8) authentication flaw (CWE-287) in the BI Publisher Integration component of the Oracle Concurrent Processing product within Oracle E-Business Suite. An unauthenticated attacker with network access over HTTP can exploit it remotely with no credentials and no user interaction, achieving a takeover of Oracle Concurrent Processing with high confidentiality, integrity, and availability impact. Any organization running Oracle E-Business Suite 12.2.3 through 12.2.14 is affected, especially instances reachable from the internet. The flaw is being actively exploited in the wild: the Cl0p data-theft group has used it to breach dozens of organizations (including Harvard University, with 1.3 TB of data leaked), CISA added it to the Known Exploited Vulnerabilities catalog on 2025-10-06 with known ransomware use, and EPSS puts its 30-day exploitation probability at 99.7%.

Do: Apply Oracle's released patch or mitigations for CVE-2025-61882 to affected E-Business Suite 12.2.3-12.2.14 deployments as instructed by the vendor; per CISA KEV requirements, federal agencies must follow BOD 22-01 guidance or discontinue use if mitigations are unavailable. Until patched, limit internet exposure of EBS and its BI Publisher/Concurrent Processing HTTP endpoints, and review web and application logs for unauthenticated access and signs of Cl0p-style data theft or follow-on ransomware.

9.8100% KEV ransomware
  • Oracle E-Business Suite (Oracle Concurrent Processing, BI Publisher Integration component) 12.2.3 - 12.2.14
largetens of thousands of EBS environments worldwide across an estimated ~5,000+ customer organizations (est.)
Full article322 words · extracted from helpnetsecurity.com · click to collapse

Cosmetics company Estée Lauder disclosed a data breach tied to a vulnerability in Oracle E-Business Suite (EBS) used for the company’s human resources operations.

Estée Lauder data breach

Estée Lauder is one of the largest beauty companies in the world, known for its prestige skincare, makeup, fragrance, and haircare brands.

“We became aware of a cybersecurity issue involving a vulnerability in the Oracle E-Business Suite system which is used by the Estee Lauder Companies for HR management purposes,” the company said in the notice.

“On June 19, 2026, we determined through our investigation that, on or around August 9, 2025, an unauthorized third party gained access to the Oracle E-Business Suite system and obtained personal information of certain individuals.”

The data taken varied from person to person. According to the notification, it included names, postal and email addresses, dates of birth, Social Security numbers, passport numbers, bank account numbers, health information, and employment records such as performance evaluations and payroll history.

Following the discovery, Estée Lauder said it brought in outside cybersecurity experts, notified law enforcement, and added safeguards to the system. The company is also offering 24 months of free identity monitoring through Kroll, with a deadline of October 31, 2026.

“Please remain vigilant in protecting against identity theft and fraud, including monitoring your accounts, account statements, and credit reports for signs of suspicious activity,” the company added.

Although the notification does not identify the threat actor responsible, the date of the breach aligns with the start of the mass-exploitation campaign targeting Oracle E-Business Suite via CVE-2025-61882.

In October 2025, Google and Mandiant researchers confirmed that the Cl0p extortion gang had exploited multiple Oracle E-Business Suite vulnerabilities, including the CVE-2025-61882 zero-day, to steal large amounts of data from several victims in August 2025.

The flaw allowed unauthenticated attackers with network access to remotely execute code over HTTP, affecting Oracle E-Business Suite versions 12.2.3 through 12.2.14.

Oracle released fixes for CVE-2025-61882 on October 4, 2025.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/07/21/estee-lauder-data-breach-oracle-ebs/