New Africa - stock.adobe.com
Cosmetics giant Estée Lauder victim of mass Oracle breach
Employee data at US-based cosmetics firm Estée Lauder was compromised through a vulnerability in Oracle's software, likely orchestrated by the Cl0p ransomware gang.
Cosmetics multinational Estée Lauder is contacting both current and former employees after discovering internal data was compromised in a breach orchestrated through Oracle’s E-Business Suite (EBS) service in the summer of 2025.
The New York-based Estée Lauder group told victims that on or around 9 August 2025, an unauthorised third-party gained access to its EBS system and was able to obtain data including names, postal and email addresses, dates of birth, US Social Security numbers, passport data, bank details, health information, and internal human resources (HR) data such as payroll and performance reviews.
“After learning of the issue with the Oracle E-Business Suite system, we quickly launched an investigation and worked with leading outside cyber security experts to determine the nature and scope of the issue and impacted information,” the firm said.
“We also notified law enforcement authorities. We have put in place additional safeguards to further protect the system.”
The firm is offering affected employees access to identity monitoring through Kroll, and advising people to remain alert for suspicious inbound contacts.
Ransomware gang
Multiple firms were compromised via their EBS instances over a three-month period, most prominently by the Clop/Cl0p ransomware gang. For a time there was also some suggestion that individuals associated with the ShinyHunters collective were involved in exploit activity, but according to threat researchers there was not enough evidence to verify this.
Many of these breaches are thought to have originated via a number of flaws, most prominently a remote code execution (RCE) flaw in the widely-used service, tracked as CVE-2025-61882. Oracle patched this particular vulnerability in October 2025.
Estée Lauder has neither confirmed nor denied that it was attacked by Cl0p gangsters, or whether or not it was affected by ransomware.
Commenting on the firm’s update, Dray Agha, Huntress senior manager of security operations, said: “The Estée Lauder breach highlights the cascading threat of mass-exploitation campaigns targeting enterprise platforms like Oracle EBS, demonstrating how a single vulnerability can hand attackers a highly toxic mix of employee financial, health, and identity data while giving them a multiple-month head start to weaponise it before victims are even aware.
“Beyond the technical failure, this is a deeply human issue for the retail and beauty industry. A brand's reputation is built on trust, and failing to protect the highly sensitive health, financial, and identity records of the very employees who represent the company creates a devastating personal crisis for the workforce,” said Agha. “For today's socially conscious consumers, how a brand protects and treats its own people is just as important as how it protects customer credit cards."
Widespread attacks
The Cl0p ransomware gang has an established modus operandi built up over several distinct campaigns over the years. Historically, it seeks out and exploits vulnerable services – often file transfer software packages – and compromises multiple victims simultaneously. These campaigns are often rather more successful than the gang has capacity to manage, and result in noticeable spikes in ransomware statistics.
Its Oracle EBS campaign was no exception to this, with multiple other victims of the campaign already identified, many of them in the higher education sector. These include US Ivy League colleges Dartmouth, Harvard and Penn.
Other known victims include New York City entertainment and sports venue Madison Square Garden, and a US subsidiary of Computer Weekly publisher Informa.
Read more about ransomware
- Proposals to ban UK government organisations from paying ransomware gangs appear to have lost momentum. The conversation should move towards making critical systems more resilient to attack.
- Data from the UK’s Report Fraud service reveals the scope of ransomware attacks is going underreported, with few businesses confident enough to identify themselves as victims.
- Ransomware pressure and stricter resilience expectations are exposing a gap that Gulf enterprises have not fully confronted.
