CVE Tools

Estée Lauder discloses data breach via Oracle E-Business flaw

BleepingComputerBy Bill Toulas

IncidentOracle E-Business SuiteClop

Our summary

Cosmetics giant Estée Lauder has disclosed a data breach following an attack that exploited a vulnerability in Oracle E-Business Suite (CVE-2025-61882). Hackers gained unauthorized access on August 9, 2025, stealing personal details such as full names, Social Security numbers, health records, and financial account information. The flaw allowed remote code execution and was actively exploited by the Clop ransomware group since early 2025. Oracle issued patches for the issue in October 2025, but the breach highlights ongoing risks for organizations using unpatched systems.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store