CyberSecurity

Estée Lauder Confirms Employee Data Stolen in Oracle EBS Zero-Day Attack

Published

on

A Delayed Disclosure, a Massive Data Haul

Nearly a year after the infamous Cl0p cybercrime group exploited a critical vulnerability in Oracle E-Business Suite (EBS), cosmetics giant Estée Lauder has finally begun notifying employees that their personal information was stolen. The breach, which the company says occurred in early August 2025, leveraged a zero-day flaw — tracked as CVE-2025-61882 — that allowed unauthenticated remote code execution.

The Cl0p group wasted no time. By November 2025, over 100 companies found themselves listed on Cl0p’s leak site. Most confirmed the impact quickly. Estée Lauder did not. It took until March 2026 for the group to dump 870GB of archive files allegedly stolen from the company, making Estée Lauder one of the last major holdouts — alongside Broadcom, Bechtel, and Abbott Laboratories — to disclose the full scope of the damage.

What Was Stolen? A Full HR Dossier

The notification letter, filed with the California Attorney General’s Office, spells it out in grim detail. Estée Lauder’s Oracle EBS instance was used for HR management. That means the compromised data reads like a complete employee dossier: names, addresses, dates of birth, Social Security numbers, passport numbers, bank account numbers, health information, and payroll records.

It’s hard to overstate how sensitive that mix is. Bank details alone can fuel fraud. Combine them with SSNs and health data, and you have the raw material for identity theft that can plague victims for years. Estée Lauder is offering 24 months of free identity monitoring to those affected — a standard but necessary step.

The Timeline: How the Attack Unfolded

The zero-day itself was patched by Oracle in early October 2025. Shortly after, CrowdStrike confirmed that in-the-wild exploitation had begun on August 9 — the same day Estée Lauder was hit. The company’s internal investigation only concluded in June 2026, determining that data had indeed been exfiltrated from its EBS system.

That’s a long gap between intrusion and confirmation. Security teams often struggle to piece together what exactly was taken, especially when attackers have had months to cover their tracks. But a year-long investigation raises questions about visibility and logging within Estée Lauder’s Oracle environment.

Why the Delay?

Estée Lauder hasn’t explained why the notification took so long. The company says it has notified law enforcement and taken steps to harden its systems. It has not disclosed how many employees are affected. SecurityWeek has reached out for comment but has not yet received a response.

The Bigger Picture: Cl0p’s Oracle EBS Campaign

This wasn’t just a one-off breach. CVE-2025-61882 was a zero-day in Oracle EBS — a widely used enterprise resource planning platform. Cl0p, known for its big-game hunting tactics, scanned for vulnerable instances and punched through. The campaign hit dozens of organizations across industries, from manufacturing to healthcare.

What makes this incident particularly concerning is the nature of the data. Oracle EBS often centralizes HR, finance, and supply chain operations. When an attacker gains access to that system, they don’t just grab a few emails. They pull the company’s entire internal operating picture.

What Estée Lauder Employees Should Do Now

For the affected employees, the advice is straightforward but critical. Monitor bank accounts for unauthorized transactions. Watch for phishing emails that reference your stolen data — Cl0p or other criminals may try to weaponize the information. Place a fraud alert or credit freeze with the major credit bureaus. Estée Lauder’s identity monitoring service is a good start, but it’s not a silver bullet.

The company is also urging vigilance against suspicious calls and texts. Social engineering attacks often follow data breaches, with criminals posing as HR or IT support to extract even more information.

Lessons for Enterprise Security Teams

This breach underscores a few hard truths. First, zero-day vulnerabilities in legacy ERP systems are a ticking clock. Oracle EBS is decades old, but it’s still the backbone of HR and finance operations at thousands of companies. Patching alone isn’t enough — segmentation, monitoring, and incident response plans need to assume that an attacker will eventually get in.

Second, disclosure timelines matter. A year-long investigation erodes trust and leaves employees in the dark. Faster, more transparent communication — even if the full picture isn’t clear — can help mitigate the fallout.

Finally, the Cl0p group isn’t going anywhere. They’ve proven they can exploit enterprise software at scale and hold data for ransom or exposure. Companies running Oracle EBS should treat that as a given, not a possibility.

This is a developing story. SecurityWeek will update this article if Estée Lauder provides additional details on the number of impacted individuals or the remediation steps taken.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version