All stories

Unauthorized access to Estée Lauder HR systems exposes financial accounts through Oracle flaw

An unauthorized third party gained access to Estée Lauder's HR management systems via a vulnerability in Oracle E-Business Suite. The intruder accessed sensitive financial account numbers and payroll reports. Organizations running affected Oracle versions should verify their patching status immediately.

Summary

Estée Lauder has notified customers that an intrusion occurring on August 9, 2025, resulted in the theft of personal information. The company identified the issue through an investigation into its Oracle E-Business Suite system, which is used for human resources and payroll management.

The stolen data includes financial account information, such as bank account numbers, alongside employment details including payroll and performance reports. Estée Lauder is providing 24 months of identity monitoring services via Kroll to those affected by the incident.

What happened

The intrusion targeted a vulnerability within the Oracle E-Business Suite (EBS) environment used by Estée Lauder for HR operations. While the company's official notification does not name the specific vulnerability, the timing of the August 9 breach aligns with a widespread exploitation campaign targeting Oracle EBS.

This campaign involves the exploitation of a flaw that allows attackers to bypass authentication and execute code remotely. The impact of this activity has been seen across multiple sectors, with high-profile victims including Harvard, the University of Pennsylvania, Dartmouth, The Washington Post, Logitech, and Envoy Air.

Technical details

The breach correlates with the exploitation of CVE-2025-61882, a flaw affecting Oracle E-Business Suite versions 12.2.3 through 12.2.14. The vulnerability resides in the BI Publisher Integration component.

By targeting this specific component, threat actors can bypass authentication mechanisms to achieve remote code execution. This level of access allows attackers to move through the system to extract sensitive business and HR data. Oracle released patches for this vulnerability on October 4, 2025.

Why this matters for defenders

The exploitation of this flaw has been linked to the Clop ransomware gang, who utilized the zero-day to steal data during a mass campaign. This follows a previous incident where the same actor targeted Estée Lauder via the MOVEit Transfer platform in 2023.

Because the vulnerability allows for remote code execution through an authentication bypass, any system running the affected EBS versions is at high risk of full compromise if not patched. The scale of the campaign suggests that many organizations may be currently targeting these specific integration components.

Defender guidance

Organizations running Oracle E-Business Suite should immediately verify their version numbers and apply the patches released by Oracle on October 4, 2025.

  • Identify Version: Check if your instance falls within the affected range of versions 12.2.3 through 12.2.14.
  • Patching: Prioritize updates to the BI Publisher Integration component to mitigate remote code execution risks.
  • Audit Access: Review HR and payroll system logs for unauthorized access or unusual activity originating from the BI Publisher component.

Sources

  1. https://www.bleepingcomputer.com/news/security/est-e-lauder-discloses-data-breach-via-oracle-e-business-flaw/
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -