Estée Lauder Data Breach Exposes Sensitive Information; Clop Ransomware Exploits Oracle EBS Vulnerability

July 21, 2026
Estée Lauder Data Breach Exposes Sensitive Information; Clop Ransomware Exploits Oracle EBS Vulnerability
  • A major data breach at Estée Lauder Companies emerged from an exploitation of a critical Oracle E-Business Suite vulnerability (CVE-2025-61882) tied to the Clop ransomware campaign, with initial access around August 9, 2025 and data access confirmed on June 19, 2026.

  • The breach exposed highly sensitive personal data, including names, contact details, dates of birth, Social Security numbers, passport numbers, bank information, health data, and employment records such as performance evaluations and payroll history.

  • Estée Lauder engaged external cybersecurity experts, alerted law enforcement, and began enhanced protections, while regulators and potential legal consequences loom due to the exposure of sensitive information; indicators of compromise were not publicly disclosed at reporting.

  • Regulators and industry observers have cited multiple sources for context, and the company provided contact information for inquiries through involved platforms.

  • The reporting traces the timeline from the breach’s discovery and internal review through to the subsequent public disclosure.

  • Technical details describe unauthenticated remote code execution via BI Publisher over HTTP, aligned with MITRE ATT&CK techniques, with possible use of valid accounts and data exfiltration channels; ransomware deployment was not confirmed.

  • Mitigation emphasizes immediate patching of CVE-2025-61882, keeping public-facing apps updated, and strengthening monitoring, with broader actions including log reviews and updated incident response plans.

  • Estée Lauder notified law enforcement and implemented enhanced system protections; the exact number of affected individuals has not been disclosed.

  • The company engaged external cybersecurity experts, notified law enforcement, and offered 24 months of free identity monitoring via Kroll to affected individuals, with guidance to monitor accounts and watch for phishing.

  • The disclosure confirms an Oracle EBS vulnerability breach and outlines the incident timeline from initial access to notification.

  • Oracle released fixes for CVE-2025-61882 on October 4, 2025.

  • Context notes that in October 2025 attackers claimed to have stolen Oracle EBS files from multiple organizations, though the veracity remained uncertain at the time.

Summary based on 6 sources


Get a daily email with more Tech stories

More Stories