# Clop Hit Estée Lauder Twice. This Time They Took the Full Employee File.
The cosmetics giant is notifying employees and individuals that hackers walked through their HR system last August — and it took ten months to figure out.
Estée Lauder disclosed last week that an unauthorized third party accessed its Oracle E-Business Suite environment on or around August 9, 2025. The company says it completed its investigation on June 19, 2026, and determined that the attacker obtained a category of personal data that reads like a checklist for industrial-scale identity fraud: full names, postal addresses, email addresses, dates of birth, Social Security numbers, passport numbers, bank account numbers, health information, and employment records including payroll data and performance reports.
That's not a leak. That's an HR department in a stranger's hands.
## The Vulnerability Nobody Patched in Time
Although Estée Lauder's notification doesn't name the vulnerability, the breach date is a fingerprint. August 9, 2025 aligns precisely with the early exploitation window for CVE-2025-61882 — a critical flaw in Oracle E-Business Suite versions 12.2.3 through 12.2.14 that allowed attackers to bypass authentication and remotely execute code through the BI Publisher Integration component. No credentials required. No social engineering. Just a network path to a vulnerable EBS instance and access to everything HR had ever touched.
Google and Mandiant researchers didn't publicly warn of active exploitation until October 2025. Oracle released patches on October 4, 2025. CrowdStrike confirmed shortly after that the Clop ransomware operation had been leveraging CVE-2025-61882 as a zero-day since early August — meaning the gang had roughly two months of uncontested access to vulnerable enterprises before defenders even knew what to patch.
Estée Lauder was in the window.
## Clop, Again
If the name Clop sounds familiar in connection with Estée Lauder, that's because it should. In 2023, the same threat actor hit the company via a zero-day in MOVEit Transfer, part of the wave of MOVEit exploitations that Clop used to compromise hundreds of organizations worldwide. Estée Lauder was one of the more prominent victims in that campaign.
Three years later, same gang, different software, same result.
Clop's model is well-established at this point: identify a critical vulnerability in widely-deployed enterprise software, exploit it as a zero-day before vendors or defenders can respond, extract data at scale across dozens or hundreds of targets, then leverage the stolen data for extortion. The group has refined this playbook through GoAnywhere, PaperCut, MOVEit, and now Oracle EBS — each time targeting the category of software that sits between business operations and sensitive data.
Oracle E-Business Suite is exactly the kind of target Clop looks for. It's deeply embedded in enterprise HR and finance operations, often running at organizations that adopted it years ago and haven't modernized their patching cadence. The BI Publisher component that CVE-2025-61882 targeted isn't a flashy external-facing service — it's internal reporting infrastructure that many security teams don't monitor with the same intensity as perimeter systems.
Estée Lauder isn't alone. Harvard, the University of Pennsylvania, Dartmouth, the University of Phoenix, The Washington Post, Logitech, GlobalLogic, Cox Enterprises, and American Airlines subsidiary Envoy Air have all been confirmed or reported as victims of the same campaign. The breadth suggests Clop ran automated exploitation at scale, not targeted intrusions.
## Ten Months Is a Long Time
The gap between breach and notification deserves scrutiny. The intrusion occurred August 9, 2025. The investigation concluded June 19, 2026. Estée Lauder sent breach notifications shortly after. That's approximately ten and a half months between the day Clop extracted data and the day affected individuals learned their SSNs and passport numbers were in someone else's possession.
Some of that timeline is understandable. Zero-day exploits don't leave clean forensic breadcrumbs. The company may not have detected the intrusion until months after it occurred. Investigations at $14 billion enterprises involve legal, compliance, and forensic teams that move carefully. None of that changes the practical reality for employees: they've had roughly ten months of exposure they didn't know about.
The identity monitoring offer — 24 months through Kroll — is standard breach response. It's also worth noting that SSNs and passport numbers have a much longer useful life for fraud than a two-year monitoring window covers.
---
## HackWire Analysis
What makes this breach notable isn't the data categories exposed — HR system compromises routinely produce this kind of haul. It's what Estée Lauder represents: a proof of concept for Clop's long-term enterprise targeting strategy.
The same organization hit twice by the same threat actor through two different zero-days in three years isn't bad luck. It's an indicator that enterprise software risk management is structurally broken at scale. The MOVEit breach should have prompted every Clop victim to ask a hard question: what other enterprise file transfer, HR, or integration software are we running that fits this profile? The answer, apparently, was Oracle E-Business Suite.
Clop's playbook only works because enterprise organizations run complex, heterogeneous software stacks that accumulate over decades. Legacy EBS deployments are notoriously difficult to patch — the EBS architecture creates interdependencies that make unplanned updates risky, so organizations run extended validation cycles before applying fixes. That's exactly the gap Clop exploits. They don't need a long window; they just need the window to open before the patch lands.
The BI Publisher attack vector is worth flagging for defenders. Organizations running Oracle EBS 12.2.3–12.2.14 should treat CVE-2025-61882 as a confirmed exploitation priority, verify patch status immediately, and review authentication logs around August 2025 if they haven't already. The campaign may be months old, but the forensic question — were we in Clop's harvest window? — is still worth answering. If you can't answer it definitively, assume you were.
For HR system operators broadly: the Clop pattern targets software that aggregates sensitive data across the full employee lifecycle. Payroll, performance, health benefits, identity documents — that's the jackpot, and enterprise HR platforms are the vault. Segmenting HR data access, monitoring BI and reporting components specifically, and treating patch timelines for HR software with the same urgency as perimeter systems are no longer optional hygiene.
Two Clop hits in three years. The third won't wait for the next zero-day — it'll use credentials from this breach.
— HackWire Editorial
---
## Related Coverage