```html ```
top of page

Estée Lauder Just Confirmed It Was Breached in the Oracle Attack We Covered Last Fall. The Intruders Were Inside Eleven Months Ago — Before the Bug Was Even Public.

  • Writer: Patrick Duggan
    Patrick Duggan
  • 1 minute ago
  • 4 min read

Estée Lauder has told the Vermont Attorney General that attackers broke into its Oracle E-Business Suite HR environment and stole employee data — names, Social Security numbers, and health information. This is not a new attack. It is a name finally attached to an old one, and the timeline is the whole story.


The intruders got in on or around August 9, 2025. Estée Lauder disclosed it on July 10, 2026. Eleven months. And here is the part that should stop you: the vulnerability they used, Oracle's CVE-2025-61882, was not publicly known in August. Oracle did not ship the emergency patch until October. So when Cl0p walked into Estée Lauder's HR system, there was no advisory to read, no patch to apply, no proof-of-concept on GitHub to warn anyone. It was a zero-day, and Estée Lauder is now a dated receipt for exactly how long attackers were inside before the rest of us were allowed to know the door existed.



We were on this campaign when it was live


We are not breaking the Estée Lauder disclosure and we will not pretend to be — it is a breach notification, filed this month. What we can say is that we covered the campaign that produced it while it was happening, not eleven months later.


When Cl0p began mass-exploiting Oracle E-Business Suite last autumn, we wrote it up and we did our own work on it: we hunted the exposed EBS systems ourselves, the internet-facing HR and financials instances sitting where an unauthenticated attacker could reach them. We wrote about the 9.8-severity unauthenticated takeover directly. We wrote a piece called "Larry Ellison's Two-Month Head Start" — about the head start being the attackers'. And eight days ago we flagged that this is not a one-time event: the July disclosure of CVE-2026-46817 made it the third unauthenticated takeover of Oracle EBS in nine months. Estée Lauder is the human cost of the first one, surfacing now.


So this is not a gap we missed. It is a confirmation of a warning we already published — the least satisfying kind of being right, because the cost already happened to real employees while the finding sat unattributed.



Why the eleven-month silence is the actual lesson


The instinct, reading a breach notice about a company breached last summer, is to file it as old news. That instinct is the vulnerability.


Cl0p's Oracle EBS campaign hit dozens of large organizations. SecurityWeek's running count has it down to only a handful of named corporate giants still publicly silent on whether they were affected. Which means the disclosures are not done — they are trickling out one attorney-general filing at a time, on the slow clock of forensics, legal review, and notification law. Estée Lauder was compromised in August 2025 and is telling us in July 2026. There are others on that same clock who have not sent their letter yet, and some who do not yet know they need to.


That is the message for everyone who ran Oracle E-Business Suite through last autumn, and especially for the mid-size organizations without a forensics retainer or a threat-intel team on staff — the ones a firehose of breach headlines never actually reaches. The absence of a breach notification is not evidence you were not breached. It is, at most, evidence that nobody has finished looking. Cl0p's whole model is patience: exfiltrate quietly, sit on the data, and monetize it on their own timeline through extortion — which is exactly why the compromise date and the disclosure date can be eleven months apart.



What to actually do


If your organization ran an internet-reachable Oracle E-Business Suite instance at any point from roughly July 2025 onward, do not wait for a letter to tell you what happened. Assume the zero-day window was open before October and check for it directly.


Patch first: CVE-2025-61882 and the related CVE-2025-61884 are both in CISA's Known Exploited Vulnerabilities catalog, along with July's CVE-2026-46817 — a three-CVE pattern that says Oracle EBS is being actively worked, not incidentally hit. Apply Oracle's fixes to every instance, and get any EBS front-end off the public internet if it does not have to be there.


Then hunt, because patching now does nothing about access gained then. Pull your EBS and web-tier logs back to at least July 2025 and look for the campaign's fingerprints: anomalous requests to the EBS servlet endpoints, unexpected outbound connections from the application tier, new or modified database accounts, and bulk reads of HR and personnel tables that no scheduled job explains. If you find nothing, that is worth knowing with confidence rather than assuming. If you find something, you are earlier on the clock than Estée Lauder was — which is the only advantage available this late.


We hold this at 95 percent, as always. The Estée Lauder specifics are the company's own disclosure to the Vermont AG and the trade-press reporting on the wider Oracle EBS campaign; the attribution to Cl0p and the CVE timeline are Oracle's, Mandiant's, and CISA's. What is ours is the coverage record: we were writing about this campaign and hunting its exposed infrastructure last fall, and we said out loud that Oracle EBS was becoming a repeat door. The letter from Estée Lauder is what that warning looks like eleven months later, with a name on it.




Sources: Estée Lauder breach disclosure to the Vermont Attorney General (filed July 10, 2026), via CyberInsider and Computer Weekly; wider Oracle EBS campaign and remaining-silent count via SecurityWeek. CVE-2025-61882, CVE-2025-61884, and CVE-2026-46817 are in our CISA KEV mirror. Estée Lauder is a victim, not a threat — no indicators were ingested from this disclosure.




Every indicator in this post is in the feed. Free.

1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.


Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page