Estée Lauder discloses employee data theft via Oracle zero-day
Estée Lauder notified employees that about 870GB of personal and payroll records were stolen from its Oracle E‑Business Suite after the Cl0p group exploited a zero-day in August 2025.
Estée Lauder notified employees in a letter filed with the California attorney general that personal and payroll records were taken from an Oracle E‑Business Suite instance in early August 2025 after the Cl0p cybercrime group exploited a zero-day vulnerability. The group posted roughly 870GB of files it alleges were stolen.
The filing reports the compromised data includes names, addresses, dates of birth, Social Security numbers, passport numbers, bank account numbers, health information and payroll and other employment records. The company did not disclose how many current or former employees were affected.
The incident involved CVE-2025-61882, an unauthenticated remote code execution flaw in Oracle E-Business Suite. CrowdStrike reported evidence that exploitation in the wild began on August 9, the same day Estée Lauder was hit. Oracle released a patch in early October after the vulnerability became widely known.
The Cl0p group targeted multiple Oracle EBS customers as part of a broader campaign and listed more than 100 alleged victims on its leak site. Security teams responding to the campaign warned that unauthenticated RCE allows attackers to run commands or deploy tools on vulnerable systems without prior access, increasing the risk of large-scale data exfiltration from business applications.
Estée Lauder has notified law enforcement, implemented additional protections for the affected environment and is providing potentially impacted individuals with 24 months of identity monitoring. The company’s notice to individuals includes steps for monitoring financial accounts and recognizing phishing attempts. The company continues its investigation.








