Estée Lauder discloses data breach via Oracle E-Business flaw

Estée Lauder discloses data breach via Oracle E-Business flaw
Estée Lauder is notifying customers after attackers exploited a flaw in Oracle E-Business Suite used for HR operations and accessed personal information belonging to certain individuals. The breach is linked to the Clop campaign targeting CVE-2025-61882, which also affected multiple major organizations and led Estée Lauder to offer identity monitoring. #EstéeLauder #OracleEBusinessSuite #CVE-2025-61882 #Clop

Keypoints

  • Estée Lauder detected an intrusion tied to its Oracle E-Business Suite HR system.
  • Attackers obtained personal information of certain individuals after accessing the system.
  • Exposed data included names, addresses, SSNs, passport numbers, and financial details.
  • The incident aligns with the Clop exploitation campaign against CVE-2025-61882.
  • Estée Lauder is offering 24 months of identity monitoring through Kroll.

Read More: https://www.bleepingcomputer.com/news/security/est-e-lauder-discloses-data-breach-via-oracle-e-business-flaw/