breach
Estée Lauder Confirms Oracle EBS Breach, Ten Months On
2026-07-21

Estée Lauder is writing to customers about a data breach that traces back to its Oracle E-Business Suite, the platform the cosmetics giant used for HR. The intrusion happened on 9 August 2025. The company only confirmed the scope of the theft on 19 June 2026, nearly ten months later.
The timing lines up neatly with the mass-exploitation campaign against Oracle EBS through CVE-2025-61882, an authentication bypass in the BI Publisher Integration component that let attackers run code remotely and help themselves to HR and business data. Oracle patched it on 4 October 2025. CrowdStrike later confirmed the Clop ransomware crew had been quietly working the flaw since early August, weeks before anyone knew it existed.
A crowded victim list
Estée Lauder has plenty of company. Also caught in the same sweep:
- Harvard
- The University of Pennsylvania
- Dartmouth
- The University of Phoenix
- The Washington Post
- Logitech
- Cox Enterprises
- Envoy Air, an American Airlines subsidiary
Affected individuals are being offered 24 months of identity monitoring through Kroll, which is by now the standard consolation prize.
Familiar playbook
There is a familiar ring to all this. Estée Lauder was also hit by Clop back in 2023, when the same gang burned a zero-day in MOVEit Transfer. Different tool, same approach: find an enterprise file-mover or business suite that thousands of large organisations run, and quietly work through the list before anyone notices. Clop has built a lucrative niche out of turning enterprise software supply into a target list.
The MOVEit campaign eventually racked up more than 2,700 victim organisations. The Oracle EBS campaign is still unfolding, and the disclosure timelines coming out now suggest a lot of organisations are still piecing together what was taken.
The two-month gap
For everyone else running EBS, the useful question is not whether the October patch was applied. It's what happened in the environment between early August and that patch date. Attackers had roughly two months of undetected access before the flaw was public. That's a long time to move laterally, stage data and set up follow-on access.
Log retention becomes the deciding factor. Organisations that keep verbose EBS and network logs for a year or more can go back and hunt for the indicators CrowdStrike and Oracle have since published. Those running default retention windows are, at this point, mostly relying on Clop to tell them whether they were breached, which is a rough spot to be in.
Expect the Estée Lauder disclosure to be one of many still to come. The pattern from MOVEit was that new names appeared for the better part of a year after the initial exploitation window. There is little reason to think EBS will be different.