Executive Summary
The Estée Lauder Companies disclosed a significant data breach involving the compromise of sensitive employee information through the exploitation of a critical vulnerability in the Oracle E-Business Suite (EBS) human resources environment. The breach, which occurred on or around August 9, 2025, was confirmed by the company on June 19, 2026, and reported to regulatory authorities on July 10, 2026. The incident is linked to a broader exploitation campaign attributed to the Clop ransomware gang, targeting unpatched Oracle EBS systems. Exposed data includes Social Security numbers, government ID numbers, financial account codes, health records, and employment-related information. Estée Lauder has engaged external cybersecurity specialists, notified law enforcement, and is offering affected individuals 24 months of complimentary identity monitoring. The breach underscores the critical importance of timely patching, third-party risk management, and robust incident response in organizations relying on complex enterprise platforms.
Technical Information
The attack on Estée Lauder Companies was executed through the exploitation of a critical vulnerability in the Oracle E-Business Suite (EBS), specifically CVE-2025-61882. This vulnerability allowed unauthenticated remote code execution via the BI Publisher integration component over HTTP, enabling attackers to gain initial access to the company’s HR environment. The exploitation aligns with a mass campaign disclosed in October 2025 and attributed to the Clop ransomware gang, which is known for targeting enterprise software vulnerabilities for data theft and extortion.
Upon gaining access, the attackers exfiltrated highly sensitive personal and employment records, including names, postal and email addresses, dates of birth, Social Security numbers, passport numbers, bank account information, health information, and employment-related records such as payroll and performance evaluations. The breach was discovered during an internal investigation into the Oracle EBS vulnerability, with confirmation of data access occurring on June 19, 2026.
The technical attack chain mapped to the MITRE ATT&CK framework includes T1190 (Exploit Public-Facing Application), T1059 (Command and Scripting Interpreter), T1078 (Valid Accounts, possible for persistence), T1005 (Data from Local System), T1041 (Exfiltration Over C2 Channel), and potentially T1486 (Data Encrypted for Impact), although ransomware deployment was not confirmed in this case.
The Clop ransomware gang’s modus operandi typically involves exploiting zero-day and n-day vulnerabilities in widely used enterprise platforms, exfiltrating sensitive data, and issuing extortion demands. In this campaign, exploitation of Oracle EBS began in August 2025, with patches for some vulnerabilities released in July 2025 and the zero-day fixed on October 4, 2025. Estée Lauder’s compromise date falls within the early stages of this campaign.
Following the breach, Estée Lauder engaged external cybersecurity specialists, notified law enforcement, and implemented additional security measures. The company has not disclosed the total number of affected individuals or whether an extortion demand was received. Regulatory filings confirm the exposure of highly sensitive data, triggering mandatory reporting and potential legal and regulatory consequences.
Affected Versions & Timeline
The vulnerability exploited was CVE-2025-61882, affecting Oracle E-Business Suite versions 12.2.3 through 12.2.14. The timeline of key events is as follows: unauthorized access occurred on or around August 9, 2025; the mass-exploitation campaign was publicly disclosed in October 2025; Estée Lauder confirmed data access on June 19, 2026; the breach was reported to the Vermont Attorney General on July 10, 2026; and public disclosure followed on July 13, 2026.
Threat Activity
The threat activity is attributed to the Clop ransomware gang, which has a history of exploiting vulnerabilities in enterprise software such as MOVEit, Accellion, GoAnywhere, and Oracle EBS. The group’s tactics include exploiting public-facing applications, executing remote code, exfiltrating sensitive data, and issuing extortion demands. In this campaign, the attackers targeted HR and payroll systems to obtain sensitive employee data, impacting organizations with large, distributed workforces and complex supply chains. The breach at Estée Lauder is part of a broader pattern of sector-specific targeting, with significant implications for regulatory compliance, identity theft risk, and potential legal action.
Mitigation & Workarounds
The following mitigation steps are prioritized by severity:
Critical: Immediately apply all available security patches for Oracle E-Business Suite, especially those addressing CVE-2025-61882 and related vulnerabilities. Ensure that all public-facing enterprise applications are up to date and monitored for signs of exploitation.
High: Conduct a comprehensive review of access logs and system activity for indicators of unauthorized access or data exfiltration. Engage external cybersecurity specialists to perform forensic analysis and validate the integrity of HR and payroll systems.
Medium: Implement enhanced monitoring and alerting for suspicious activity in enterprise applications, and review user account privileges for signs of misuse or persistence mechanisms.
Low: Provide ongoing security awareness training for employees, focusing on phishing, credential theft, and reporting suspicious activity. Review and update incident response plans to address supply chain and third-party risks.
Indicators of Compromise
Indicators of compromise are point-in-time and should be validated before enforcement. No public indicators of compromise were available at the time of writing.
References
https://www.classaction.org/data-breach-lawsuits/the-estee-lauder-companies-july-2026 (Published July 13, 2026), https://cyberinsider.com/estee-lauder-discloses-data-breach-tied-to-oracle-e-business-suite-attacks/ (Published July 20, 2026), https://www.claimdepot.com/data-breach/este-lauder-2026 (Published July 13, 2026)
About Rescana
Rescana’s Third-Party Risk Management (TPRM) platform enables organizations to continuously monitor and assess the security posture of their vendors and critical enterprise applications. Our platform provides actionable insights into supply chain vulnerabilities, supports regulatory compliance efforts, and helps organizations respond rapidly to emerging threats in complex IT environments.
We are happy to answer questions at info@rescana.com.



