INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Oracle E-Business flaw exposes Estée Lauder's customer data
| 2026-07-20 22:39 CRITICAL HIGH DATA BREACH VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
On August 9, 2025, hackers exploited a flaw in Oracle E-Business Suite to gain unauthorized access and obtain personal information of certain individuals from Estée Lauder. The company later disclosed the breach on June 19, 2026, stating that it had identified an intrusion involving a vulnerability in the system used for human resources management purposes. The exposed data includes passport numbers, financial account information, health information, employment details, and full names of approximately 57,000 employees. Estée Lauder is advising customers to remain vigilant for signs of identity theft and fraud after hackers from the Clop ransomware gang exploited a zero-day in Oracle E-Business Suite to steal sensitive data.
Technical Mitigations AI-generated
• Patch Oracle E-Business Suite versions 12.2.3–12.2.14 with the fix for CVE-2025-61882.
• Monitor for signs of identity theft and fraud, especially in industries using similar software tools like MOVEit Transfer.
• Regularly review system logs to detect suspicious activity and alert security teams promptly.
• Implement breach and attack simulation tests on SIEM and EDR systems to identify vulnerabilities before they are exploited.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-61882CVE-2025-61882
Target & Sectors
Global Scope
Incident Timeline
October 2025
Threat actors exploited a previously patched Oracle E-Business flaw, CVE-2025-61882, to bypass authentication and remotely execute code through the BI Publisher Integration component.
Click on any entity below to view its context and source!
infrastructure
12.2.3
The flaw affected EBS versions 12.2.3–12.2.14 and enabled attackers to bypass authentication and remotely execute code through the BI Publisher Integration component, potentially giving them access to sensitive HR and business data.
infrastructure
12.2.14
The flaw affected EBS versions 12.2.3–12.2.14 and enabled attackers to bypass authentication and remotely execute code through the BI Publisher Integration component, potentially giving them access to sensitive HR and business data.
Tactical Metrics
Metrics
infrastructure
12.2.3
Software Version
Click for context!
The flaw affected EBS versions 12.2.3–12.2.14 and enabled attackers to bypass authentication and remotely execute code through the BI Publisher Integration component, potentially giving them access to sensitive HR and business data.
Metrics
infrastructure
12.2.14
Software Version
The flaw affected EBS versions 12.2.3–12.2.14 and enabled attackers to bypass authentication and remotely execute code through the BI Publisher Integration component, potentially giving them access to sensitive HR and business data.
Intelligence Sources
BleepingComputer
2026-07-20
Estée Lauder discloses data breach via Oracle E-Business flaw
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T08:25
Comprehensive Tactical Telemetry
Highly Correlated Entities
21x
organisation
Identified Entity
Financial
entity
8x
timeline
Temporal Reference
October 2025
date
2x
tactic
Cyber Operation Type
Data Breach
tactic
2x
infrastructure
Software Version
12.2.3
version
2x
general metric
%
54
%
Contextual Telemetry
Context Block
4 METRICS
industry
Targeted Sector
Health
sector
vulnerability
Exploited CVE
CVE-2025-61882
cve
general metric
August
9
august
general metric
People
57,000
people
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.