← Back

Wire · regulatory

Estée Lauder Data Breach Analysis: Oracle E-Business Suite CVE-2025-61882 Exploitation ...

Published

21 July 2026

Topic

regulatory

Sectors

Cybersecurity

Geography

United States

Source

Read at rescana.com

Verified

Fusion42 · 21 July 2026 · Fusion42 review

Estée Lauder suffered a data breach affecting employee personal and financial information through exploitation of Oracle E-Business Suite vulnerability CVE-2025-61882 by the Clop ransomware gang, with breach discovery occurring nearly 11 months after initial compromise in August 2025.

This Wire brief sits within Fusion42's coverage of Cybersecurity.

◆ The Wire takeaway

If you sell enterprise software or run it at scale, your customers are months behind on patches and that gap is now a ransomware delivery system. The breach discovery lag here—11 months—means you need forensic visibility into your own HR and finance systems or your data is already gone.

Coverage

1 source · 21 Jul 2026

Related on Wire

Topics

Cybersecurityoracle-ebs-vulnerabilityransomware-campaignpatch-lag-riskhr-system-breachsupply-chain-dependency