Estée Lauder Breach via Oracle E‑Business Suite Zero‑Day (CVE‑2025‑61882) Exposes HR PII
What Happened — Hackers leveraged a zero‑day in Oracle E‑Business Suite (CVE‑2025‑61882) to bypass authentication and execute code on Estée Lauder’s HR system. The intrusion, dated August 9 2025, resulted in the theft of full names, addresses, DOB, SSNs, passport numbers, payroll data and health information.
Why It Matters for Compliance & Audit Readiness
- Demonstrates the need for continuous vulnerability‑management controls (SOC 2 CC6.1) and documented patch‑deployment evidence.
- Highlights the importance of mapping ERP security controls to SOC 2 criteria and retaining audit‑ready logs that prove timely remediation.
- Provides a real‑world example of why a Trust Center with continuous evidence collection is essential for demonstrating control effectiveness to auditors.
Who Is Affected – Cosmetics & retail (Estée Lauder), ERP/HR SaaS providers, and any organization running Oracle E‑Business Suite versions 12.2.3‑12.2.14.
Recommended Actions
- Verify that all Oracle E‑Business Suite instances are patched to the post‑Oct 4 2025 release.
- Map the vulnerability‑management process to SOC 2 CC6.1 and collect patch‑install logs as audit evidence.
- Enable continuous monitoring of ERP access logs and integrate them into your Trust Center for real‑time compliance reporting.
Technical Notes – The flaw resides in the BI Publisher Integration component, allowing unauthenticated remote code execution. Exploited by the Clop ransomware gang as part of a broader campaign affecting universities, media, and airlines. Source: BleepingComputer