Estee Lauder customer data stolen via Oracle EBS flaw
Estee Lauder's customer data was stolen because its Oracle E-Business Suite software had an unpatched security hole. Attackers exploited this to access sensitive information like names, emails, and payment details.
- Report priority
- Medium
- Involves
- Estee Lauder
What is known
Attackers sent a specially crafted request to Estee Lauder's Oracle E-Business Suite 12.2.3, 12.2.14, tricking it into leaking customer data it should not have shared.
What to do
Check whether the installed Estee Lauder version is between 12.2.3 and 12.2.14.
Follow the Estee Lauder advisory for a fixed release or mitigation. Then verify the installed version.
Reported details
An attacker sends a fake request to Estee Lauder's Oracle E-Business Suite. The software, running an old version, sends back customer names, emails, and payment info it was not supposed to share. The attacker now has a list of 1.3 million records with personal details.
CVE-2025-61882 is an unauthenticated remote code execution flaw in the BI Publisher integration component of Oracle E-Business Suite, versions 12.2.3 through 12.2.14. The Clop group used it as a zero-day starting before Oracle's October 2025 patch, chaining it with other EBS weaknesses to exfiltrate data from dozens of organizations before extorting them. Estee Lauder is one of the confirmed victims whose customer data was taken through this campaign.
References
- bleepingcomputer.com · est-e-lauder-discloses-data-breach-via-oracle-e-business-flaw BleepingComputer
- securityweek.com · estee-lauder-discloses-impact-from-oracle-ebs-zero-day-hack SecurityWeek
- infosecurity-magazine.com · lidl-notifies-customers-of Infosecurity Magazine
- infosecurity-magazine.com · insurance-giant-aflac-data-breach Infosecurity Magazine
- securityweek.com · clover-health-investments-discloses-data-breach SecurityWeek