The record
Written from the 1 report below. Nothing here is unsourced.
- Estée Lauder notified employees that hackers breached its systems by exploiting a vulnerability in Oracle E-Business Suite, gaining access to personal and sensitive HR information.
- The breach centers on CVE-2025-61882, a critical flaw in the BI Publisher Integration component affecting Oracle E-Business Suite versions 12.2.3 through 12.2.14, which security researchers describe as easily exploitable.
- The incident directly affects current and former Estée Lauder employees whose HR data was compromised, raising concerns about identity theft and privacy risks.
- Coverage from BleepingComputer focuses on the breach notification, while NVD's disclosure highlights the underlying technical vulnerability and its severity.
- The dual reporting underscores both the immediate impact on employees and the broader risk to organizations running unpatched Oracle E-Business Suite instances.
- Watch for details on the scope of exposed data, whether regulatory investigations follow, and how quickly Oracle releases patches for affected versions.
What to watch next
- Monitor Oracle patch releases for CVE-2025-61882
- Watch for Estée Lauder regulatory disclosures
- Track scope of exposed employee data
- Check if other organizations report similar breaches
Why it matters3
Who is affected first and what likely follows, with a direction and a horizon. Extracted from the reports, never invented.
- Estée Lauder employees data exposed· immediate
- Estée Lauder reputational damage· weeks
- Organizations using Oracle E-Business Suite patch required· days
Coverage1
1 report
International1
All filed from United States
Named United States · Cox Enterprises · Dartmouth · Estée Lauder · GlobalLogic · Harvard · Logitech · Oracle · The Washington Post · University of Pennsylvania · University of Phoenix · Clop · CrowdStrike
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
