Estée Lauder is notifying customers after attackers exploited a flaw in Oracle E-Business Suite used for HR operations and accessed personal information belonging to certain individuals. The breach is linked to the Clop campaign targeting CVE-2025-61882, which also affected multiple major organizations and led Estée Lauder to offer identity monitoring. #EstéeLauder #OracleEBusinessSuite #CVE-2025-61882 #Clop
Keypoints
- Estée Lauder detected an intrusion tied to its Oracle E-Business Suite HR system.
- Attackers obtained personal information of certain individuals after accessing the system.
- Exposed data included names, addresses, SSNs, passport numbers, and financial details.
- The incident aligns with the Clop exploitation campaign against CVE-2025-61882.
- Estée Lauder is offering 24 months of identity monitoring through Kroll.