Estée Lauder disclosed a breach after attackers exploited an Oracle E-Business Suite vulnerability in its HR system last August, exfiltrating personal, financial, and health data. Patch if you self-host EBS (some enterprises); most lean-IT teams rely on cloud HR platforms and can ignore this one.Cyber Resilience desk
Sources (3)
What this means for you — CISO:This is the same Oracle EBS zero-day (CVE-2026-58644) exploited last August in the Clop-linked campaign — check whether your instance was live then and pull HR/finance data-access logs for that window, not just current exposure.
What this means for you — Lean IT orgs:If you ran Oracle E-Business Suite for HR or payroll last August, assume the same flaw could have hit you — check with whoever manages that system now, even if you don't have security staff to do it yourselves.
What this means for you — MSP:Flag every client running on-prem Oracle EBS from last year's exploitation window for a retroactive compromise check, not just current patch status — the attack predates today's disclosure by nearly a year.
What this means for you — Researcher:Estée Lauder's disclosure timeline (breach in August 2025, disclosed July 2026) adds another data point to the EBS zero-day campaign's victim list — worth cross-referencing against other confirmed EBS victims for shared TTPs and exfil infrastructure.