Cosmetics giant Estée Lauder has begun notifying employees that their personal data was stolen from the company's Oracle E-Business Suite (EBS) instance during the Cl0p cybercrime group's mass exploitation of a zero-day vulnerability. The company confirmed in a notification letter filed with the California Attorney General's Office that the intrusion occurred in early August 2025, and that its investigation concluded in June 2026 that HR data had been exfiltrated. Cl0p leaked roughly 870GB of archive files allegedly stolen from the company.
What Happened
Estée Lauder was compromised on August 9, 2025, the same day CrowdStrike later determined the in-the-wild exploitation of the Oracle EBS zero-day began. The attackers abused CVE-2025-61882, an unauthenticated remote code execution flaw in Oracle EBS, to reach and exfiltrate data from the company's HR management system. The vulnerability was not patched until early October 2025, giving the Cl0p group nearly two months of exposure window across its victim pool. In November 2025, more than 100 organizations were listed on the Cl0p leak site, with many confirming impact. By March 2026, Estée Lauder was among only a handful of major names (alongside Broadcom, Bechtel, and Abbott Laboratories) that had not yet disclosed. The company's own investigation did not confirm that personal information was stolen until June 2026, roughly ten months after the initial intrusion.
What Was Taken
The compromised HR dataset is deeply sensitive. According to the notification letter, the stolen information includes names, addresses, dates of birth, Social Security numbers, passport numbers, bank account numbers, health information, and employment-related data including payroll records. Cl0p claimed to have exfiltrated approximately 870GB of archive files. Estée Lauder has not disclosed the number of affected individuals, but the combination of government-issued identifiers, financial account details, and health data represents a full-spectrum identity theft package. The company is offering affected individuals 24 months of free identity monitoring.
Why It Matters
This incident underscores that a single unpatched enterprise application can expose the most sensitive records an organization holds. Oracle EBS is a core business platform, and its use for HR management concentrated Social Security numbers, passport numbers, and banking data in one internet-reachable system. The long disclosure timeline is also instructive: nearly a year passed between the August 2025 intrusion and the June 2026 confirmation of data theft, illustrating how forensic uncertainty and complex data-scoping can delay victim notification well past the point of practical remediation. For defenders, the Cl0p campaign is a reminder that mass zero-day exploitation against widely deployed enterprise software remains this group's signature playbook, following its earlier MOVEit and GoAnywhere campaigns.
The Attack Technique
The entry vector was CVE-2025-61882, a zero-day vulnerability in Oracle E-Business Suite that enabled unauthenticated remote code execution. Because exploitation required no credentials, any internet-exposed EBS instance was reachable by the attackers. Cl0p operated at scale, hitting numerous organizations during the exploitation window before Oracle shipped a patch in early October 2025. CrowdStrike's analysis placed the start of active exploitation at August 9, 2025, aligning precisely with the date of the Estée Lauder compromise. The group's model is data theft and extortion rather than encryption, using its dedicated leak site to pressure victims into payment.
What Organizations Should Do
- Confirm all Oracle EBS instances are patched against CVE-2025-61882 and audit for any that remained exposed during the August to October 2025 window.
- Remove enterprise applications such as EBS from direct internet exposure; place them behind VPN, zero-trust access, or a web application firewall.
- Hunt retroactively for indicators of compromise tied to the Cl0p campaign, since exploitation may predate detection by weeks or months.
- Inventory where sensitive HR and PII data (SSNs, passport numbers, bank details, health records) resides and minimize its concentration in internet-reachable systems.
- Establish a rapid breach-scoping and notification process so victim disclosure does not lag intrusion by many months.
- Monitor Cl0p's leak infrastructure and threat intelligence feeds for early indication that your organization may be named.
Sources: Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack - SecurityWeek
TWEET: Estée Lauder breached by Cl0p via Oracle EBS zero-day (CVE-2025-61882). 870GB stolen: SSNs, passports, bank + health data. Full breakdown: https://wasteland.me/intel/estee-lauder-oracle-ebs-cl0p-breach #CyberSecurity #ThreatIntel