compliance · BleepingComputer
Estée Lauder disclosed a data breach affecting personal information of certain individuals after an unauthorized party exploited a vulnerability in Oracle E-Business Suite, the system the company used for HR operations. The intrusion occurred on or around August 9, 2025, and was identified in June 2026. Exposed data included full names, postal addresses, email addresses, dates of birth, Social Security numbers, passport numbers, financial account information, health information, and employment data including payroll and performance reports. The breach timeline correlates with CVE-2025-61882, a critical Oracle E-Business Suite flaw affecting versions 12.2.3–12.2.14 that enabled authentication bypass and remote code execution through the BI Publisher Integration component. The Clop ransomware gang exploited this vulnerability as a zero-day beginning in early August 2025; Oracle released patches on October 4, 2025.
For Omniware's clients, this incident underscores the importance of timely patching and monitoring of third-party enterprise systems, particularly those handling sensitive HR and financial data. Organizations subject to SOC2 Type II audits, HIPAA compliance (given health information exposure), or state privacy laws like NYDFS cybersecurity requirements should prioritize inventory and vulnerability management of Oracle E-Business Suite instances and similar legacy applications. Healthcare providers, SaaS platforms, and financial services firms storing comparable personal and health data must ensure patch management procedures address zero-day risks within acceptable timeframes; an Omniware engagement can scope detection, response, and remediation protocols in detail.
Source: BleepingComputer - https://www.bleepingcomputer.com/news/security/est-e-lauder-discloses-data-breach-via-oracle-e-business-flaw/
Source: BleepingComputer
All briefings