HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Estée Lauder Breach Exposes PII via Exploited Oracle E‑Business Suite (CVE‑2025‑61882)

Estée Lauder disclosed that an unauthenticated attacker exploited Oracle E‑Business Suite (CVE‑2025‑61882) to steal extensive personal and financial data. The breach underscores the need for robust third‑party risk controls and continuous audit evidence for SOC 2 readiness.

LiveThreat™ Intelligence · 📅 July 21, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
helpnetsecurity.com

Estée Lauder Breach Exposes PII via Exploited Oracle E‑Business Suite (CVE‑2025‑61882)

What Happened — A vulnerability (CVE‑2025‑61882) in Oracle E‑Business Suite allowed an unauthenticated attacker to execute code over HTTP. The exploit was used on ≈ August 9 2025 to gain unauthorized access to Estée Lauder’s HR system, resulting in the theft of names, addresses, dates of birth, SSNs, passport numbers, bank details, health information, and payroll records.

Why It Matters for Compliance & Audit Readiness

  • The incident illustrates a classic third‑party risk failure: a critical ERP product was unpatched, breaching the SOC 2 Security principle that requires “risk‑based vendor management” and continuous monitoring of supplier controls.
  • SOC 2 audit evidence must show that you maintain an up‑to‑date inventory of third‑party software, track patch status, and retain proof of remediation actions—exactly the data Verisq’s Vendor Risk capability can automate.
  • Demonstrating timely detection, forensic investigation, and remediation (e.g., adding safeguards, engaging experts) provides the defensible audit trail required for the “System Operations” and “Change Management” criteria.

Who Is Affected — Retail & consumer‑goods companies that rely on Oracle E‑Business Suite or similar ERP platforms for HR/payroll processing.

Recommended Actions

  • Verify that all Oracle E‑Business Suite instances are patched to the October 2025 fix for CVE‑2025‑61882.
  • Update your vendor‑risk program: map critical ERP vendors, enforce patch‑management SLAs, and ingest patch‑status feeds into continuous‑compliance dashboards.
  • Document the breach response (forensics, law‑enforcement notification, identity‑monitoring offer) as audit evidence for SOC 2 Security and Confidentiality criteria.

Source: Help Net Security

Technical Notes

  • Attack vector: Unauthenticated remote code execution over HTTP (network‑level access).
  • Vulnerability: CVE‑2025‑61882, affecting Oracle E‑Business Suite 12.2.3‑12.2.14; Oracle released patches on Oct 4 2025.
  • Data types exfiltrated: PII (SSN, DOB, passport), financial (bank accounts), health, employment records.

Source: same as above

📰 Original Source
https://www.helpnetsecurity.com/2026/07/21/estee-lauder-data-breach-oracle-ebs/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

Point-in-time vendor reviews miss incidents like this.

Verisq AI Trust Operations replaces the annual questionnaire with continuous third-party monitoring — so vendor exposure becomes audit evidence, not a once-a-year guess.

See how Verisq AI Trust Operations works →