Estée Lauder Reports Impact of Oracle EBS Zero-Day Attack
A major cosmetics company has initiated communication with employees regarding the unauthorized access of their personal data through a breach of its Oracle E-Business Suite (EBS) system.
The Breach and Vulnerability
The incident, according to the organization, occurred in early August 2025 when the Cl0p cybercriminal collective exploited a previously unknown vulnerability in Oracle EBS, designated CVE-2025-61882. This flaw allowed attackers to execute remote code without authentication, leading to the unauthorized extraction of sensitive information from multiple organizations.
Timeline of Events
By November, over 100 entities were listed on the Cl0p leak platform, with many confirming their involvement in the campaign. As of March 2026, Estée Lauder, along with Broadcom, Bechtel, and Abbott Laboratories, remained the sole large corporations yet to publicly acknowledge the breach. Cl0p reportedly exfiltrated 870GB of compressed files from Estée Lauder’s systems. CrowdStrike reported that the vulnerability was actively exploited in the wild starting on August 9, the same day the company was targeted, shortly before Oracle released a patch in early October.
Data Compromised
A letter to affected individuals, submitted to the California Attorney General’s Office, revealed that an internal investigation concluded in June that personal data had been compromised from the EBS environment, which supported human resources operations. The stolen information reportedly includes names, addresses, birth dates, Social Security numbers, passport details, bank account numbers, health records, and payroll-related data.
The company has offered affected individuals 24 months of complimentary identity monitoring services and urged them to remain cautious of fraudulent communications. Estée Lauder has also reported the breach to law enforcement and implemented additional security measures to strengthen its infrastructure. The exact number of individuals impacted remains undisclosed.
Broader Implications
The breach highlights the risks associated with zero-day vulnerabilities in enterprise software, emphasizing the importance of timely patching and proactive threat detection. The Cl0p group’s use of CVE-2025-61882 underscores the ongoing challenges organizations face in defending against sophisticated cyber threats. The incident also aligns with a broader trend of high-profile data breaches targeting critical systems, prompting renewed scrutiny of cybersecurity protocols across industries. As organizations continue to navigate evolving threat landscapes, the need for robust incident response strategies and transparency remains paramount.
