Estée Lauder discloses data breach tied to Oracle EBS vulnerability
Reported exploitedOracle E-Business SuiteCl0pOur summary
Cosmetics giant Estée Lauder has revealed a data breach linked to an unpatched vulnerability in Oracle E-Business Suite (EBS), which was used for internal HR operations. The breach occurred on or around August 9, 2025, when an unauthorized party accessed the system and stole sensitive personal and financial information from some individuals. The incident is connected to the exploitation of CVE-2025-61882, a critical flaw allowing remote code execution without authentication. Oracle issued patches for this vulnerability on October 4, 2025, but many organizations remained vulnerable during the active exploitation period. Estée Lauder has engaged cybersecurity experts, informed authorities, and is providing two years of free identity monitoring to affected individuals.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.