INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Oracle E-Business flaw exposes Estée Lauder's customer data

| 2026-07-20 22:39 CRITICAL HIGH DATA BREACH VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
On August 9, 2025, hackers exploited a flaw in Oracle E-Business Suite to gain unauthorized access and obtain personal information of certain individuals from Estée Lauder. The company later disclosed the breach on June 19, 2026, stating that it had identified an intrusion involving a vulnerability in the system used for human resources management purposes. The exposed data includes passport numbers, financial account information, health information, employment details, and full names of approximately 57,000 employees. Estée Lauder is advising customers to remain vigilant for signs of identity theft and fraud after hackers from the Clop ransomware gang exploited a zero-day in Oracle E-Business Suite to steal sensitive data.
Technical Mitigations AI-generated
• Patch Oracle E-Business Suite versions 12.2.3–12.2.14 with the fix for CVE-2025-61882. • Monitor for signs of identity theft and fraud, especially in industries using similar software tools like MOVEit Transfer. • Regularly review system logs to detect suspicious activity and alert security teams promptly. • Implement breach and attack simulation tests on SIEM and EDR systems to identify vulnerabilities before they are exploited.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-61882CVE-2025-61882
Target & Sectors
Global Scope
Incident Timeline
‎October 2025
Threat actors exploited a previously patched Oracle E-Business flaw, CVE-2025-61882, to bypass authentication and remotely execute code through the BI Publisher Integration component.
infrastructure 12.2.3
infrastructure 12.2.14
Tactical Metrics
Metrics
infrastructure
‎12.2.3
Software Version
Metrics
infrastructure
‎12.2.14
Software Version
Intelligence Sources
BleepingComputer 2026-07-20