Cl0p group steals sensitive employee data from Estée Lauder via Oracle zero-day exploit
The Cl0p cybercrime group exploited a zero-day vulnerability in Oracle E-Business Suite to exfiltrate massive amounts of sensitive employee data from Estée Lauder. The attack targeted an instance used for HR management, resulting in the theft of Social Security numbers, bank details, and health information. Organizations running Oracle EBS should verify their patching status immediately.
Summary
Estée Lauder has begun notifying employees that personal information was stolen following a cyberattack on its Oracle E-Business Suite (EBS) environment. The incident occurred in early August 2025, coinciding with the start of a widespread exploitation campaign by the Cl0p cybercrime group.
The attackers targeted a zero-day vulnerability, identified as CVE-2025-61882, which allowed for unauthenticated remote code execution (RCE). This flaw enabled the group to exfiltrate data from numerous organizations globally. While many companies have confirmed their involvement in this campaign, Estée Lauder was among several major entities that delayed public disclosure of the impact.
What happened
The breach targeted an Oracle EBS instance used by Estée Lauder for HR management functions. According to company notifications filed with the California Attorney General's Office, an investigation concluded in June that personal data had been stolen during the August 2025 window.
Cl0p reportedly leaked 870GB of archive files allegedly taken from the company. The compromised information includes highly sensitive employee records:
- Names and addresses
- Dates of birth
- Social Security numbers
- Passport numbers
- Bank account numbers
- Health information
- Payroll and employment-related data
CrowdStrike reported that in-the-wild exploitation of the vulnerability began on August 9, the same day Estée Lauder was hit. The zero-day remained unpatched until early October 2025.
Technical details
The attack centered on CVE-2025-61882, a critical vulnerability in Oracle E-Business Suite. This flaw permitted unauthenticated remote code execution (RCE), meaning an attacker could execute commands on the target system without needing valid login credentials.
This specific vulnerability was used as part of a broader campaign by Cl0p to target high-value corporate environments. By March 2026, several major companies-including Broadcom, Bechtel, and Abbott Laboratories-were noted alongside Estée Lauder as entities that had not yet disclosed the full impact of this exploitation campaign.
Why this matters for defenders
The targeting of HR management systems presents a high risk of identity theft and financial fraud for employees. Because the vulnerability allowed unauthenticated RCE, any internet-facing Oracle EBS instance was a potential entry point for the Cl0p group.
Defenders should prioritize the following actions:
- Verify Patching: Ensure all Oracle E-Business Suite instances are patched against CVE-2025-61882. The patch was released in early October 2025.
- Audit HR Systems: Review access logs for EBS instances used for sensitive personnel data to identify any unauthorized file exfiltration or unusual administrative activity.
- Monitor for Credential Exposure: Since bank account numbers and Social Security numbers were part of the stolen archives, employees should be monitored for signs of identity theft.
