Estée Lauder confirms Oracle EBS zero-day breach in Cl0p campaign
Estée Lauder notified the California AG on July 21 that Cl0p exploited Oracle EBS CVE-2025-61882 to steal HR data — names, SSNs, passports, bank accounts, health records — starting August 2025.
Estée Lauder filed a data-breach notification with the California Attorney General's Office on July 21, 2026, confirming the cosmetics group is among the named victims of the Cl0p extortion campaign against Oracle E-Business Suite. The attackers exploited CVE-2025-61882 — the unauthenticated RCE in Oracle EBS's BI Publisher Integration component — beginning August 9, 2025, per Google Cloud's Mandiant writeup of the campaign. Estée Lauder confirmed the intrusion internally on June 19, 2026 and reported it to regulators on July 10 before the public notification.
What was taken
Per the notification letter linked from SecurityWeek's coverage, the compromised system was the company's HR / payroll platform. The exfiltrated data set covers:
- Full names and postal addresses
- Dates of birth
- Social Security numbers
- Passport numbers
- Bank account numbers
- Health information
- Payroll data and performance evaluations
Estée Lauder has not disclosed the number of affected individuals. Twenty-four months of identity monitoring through Kroll is on offer to notified individuals.
What the bug is
- CVE-2025-61882 — unauthenticated remote code execution in the BI Publisher Integration component of Oracle E-Business Suite, reachable over HTTP without credentials.
- Affected releases: Oracle EBS 12.2.3 through 12.2.14.
- Oracle patched the zero-day out-of-band on October 4, 2025. The vulnerability had been exploited in the wild for roughly eight weeks before the fix.
Exploitation status
Confirmed and attributed. Mandiant's October 2025 report documents Cl0p exploiting CVE-2025-61882 and other Oracle EBS flaws starting August 9, 2025 to exfiltrate large data sets. CrowdStrike separately confirmed the same window. Cl0p began publishing victim names to its data-leak site in November 2025; the list has since grown past 100 organizations, including Cox, Broadcom, Bechtel, and Abbott Laboratories.
Estée Lauder's own investigation, per the notification, confirmed data theft on June 19, 2026 — nearly ten months after the intrusion began. That gap is characteristic of Cl0p's mass-exploitation model: the campaign hits many targets in a short window, then the group works the leak-site drip over the following year.
Action checklist
For any operator still running Oracle EBS 12.2.x:
- Confirm the October 2025 CVE-2025-61882 patch is applied on every EBS environment. Oracle's October 4, 2025 Security Alert is the reference. If your EBS instance was internet-reachable between August 9, 2025 and the patch date, assume compromise until proven otherwise.
- Hunt across the eight-week exposure window. Mandiant's report includes IOCs and attacker TTPs — BI Publisher endpoint hits from unusual IP ranges, staged data exfiltration to attacker-controlled hosts, and lateral movement from the EBS host into HR/finance systems. Log retention past August 2025 is the constraint most defenders will hit.
- Assume HR/finance datasets are the target. Estée Lauder's compromised dataset — payroll, SSNs, passports, bank data — is the same shape Cox and other named victims have disclosed. If your EBS instance holds HR or vendor-payment data, prioritize forensic scope on those tables.
- Watch the Cl0p leak site. The group has been drip-releasing names for nine months. Enrollment in a takedown/monitoring service is a hedge for both current victims and those Cl0p has yet to name publicly.
- Notify counsel and regulators on your own timetable, not Cl0p's. Estée Lauder confirmed internally in June and notified in July — a five-week gap consistent with US state notification statutes. If you are still investigating, do not wait for Cl0p to name you.
Context
Oracle EBS is now the busiest enterprise-application breach beat of 2026 — CVE-2026-46817 in EBS Payments drew active exploitation in June before any public PoC existed, and the Cl0p campaign around CVE-2025-61882 is looking like the largest enterprise-application breach cycle since MOVEit. Mandiant's October writeup traced multiple EBS vulnerabilities being chained by Cl0p — CVE-2025-61882 was the pre-auth entry, but other post-auth flaws let the group escalate through the application stack once inside. Named disclosures have arrived from Cox, Broadcom, Bechtel, Abbott, and now Estée Lauder; the pattern from MOVEit suggests the eventual public list will run several times the current 100+.
Cl0p's operating model — mass-exploit a single enterprise zero-day, exfiltrate broadly, drip-release over 12–18 months — remains the highest-yield extortion play the group runs. The Oracle EBS window closed in October; the disclosure tail will run through 2026.