Last Update: 08/01/2026 at 1:00 PM EST

Oracle EBS Breach Exposes HR Data

Coverage from TechRadar, Help Net Security, and others

Articles

11

Active Days

73

The Topic

Oracle EBS Breach Exposes HR Data topic image

Estée Lauder disclosed a breach of its Oracle E-Business Suite human resources environment that exposed employee and other personal data, with reporting tied to a 2025 Oracle vulnerability and Clop-linked mass exploitation. The strongest signal is a delayed disclosure after prolonged undetected access, followed by identity monitoring and incident-response measures.

First Article: 05/16/26

Latest Article: 07/27/26

Summary

  • The dominant pattern is a vendor-system breach: Oracle E-Business Suite was used as the entry point into sensitive HR records at Estée Lauder.
  • The incident appears to have remained undetected for many months, with access around August 2025 and disclosure in July 2026.
  • Exposed data consistently includes direct identifiers and high-risk records such as Social Security numbers, passport numbers, bank details, and some health or payroll information.
  • Multiple reports connect the timing to CVE-2025-61882, a high-severity Oracle EBS flaw that was reportedly exploited at scale in 2025.
  • Clop is the main threat actor mentioned in connection with the broader Oracle exploitation campaign, though not every report confirms direct attribution for this specific breach.
  • Estée Lauder's response is consistent across reports: external investigation, law enforcement notification, and 24 months of identity monitoring through Kroll.
  • The topic is coherent and dense, but some factual uncertainty remains around the exact exploited vulnerability and the degree of confirmed actor attribution for the Estée Lauder incident.

History

07/24/2026

The update mainly sharpens the framing: the breach is now presented more clearly as a prolonged, likely undetected compromise of Oracle E-Business Suite HR data, with the broader Oracle/Clop campaign and delayed response becoming the central emphasis. The core facts about exposed employee data and uncertain attribution remain unchanged.

07/22/2026

The update mainly clarifies the extent of the exposed data and tightens the timeline, while keeping the core breach narrative unchanged. It also slightly reframes attribution by noting Clop-linked campaign overlap without direct confirmation from Estée Lauder.

Featured

Timeline: 73 Days

Jul 21Jul 22Jul 23Jul 25Jul 26Jul 27

Additional Articles

⭐⭐⭐⭐⭐

Safestate07-23-2026
Estée Lauder disclosed a 2025 employee data breach linked to Oracle E-Business Suite, exposing SSNs and health records and offering Kroll identity monitoring.
The Next Web07-22-2026
Estée Lauder notified employees after Clop-linked intrusions into Oracle E-Business Suite exposed sensitive HR data, with confirmation in June 2026 following an August 2025 intrusion.
CPO Magazine / Alicia Hope07-27-2026
Estée Lauder disclosed an Oracle E-Business Suite vulnerability exploitation in 2025, later determined in 2026, after ransomware operators stole and leaked sensitive personal data.