# Estée Lauder Just Told Employees Cl0p Has Had Their Social Security Numbers for Almost a Year


The breach happened in August 2025. The patch shipped in October 2025. Cl0p posted 870 gigabytes of stolen data to its leak site months ago. And Estée Lauder is notifying affected employees right now, in July 2026.


Eleven months is a long time to not know your Social Security number, passport details, bank account numbers, and health information are sitting in a threat actor's hands.


## What Cl0p Did — and How Fast They Moved


CVE-2025-61882 is an unauthenticated remote code execution vulnerability in Oracle E-Business Suite. When Cl0p found it, they treated it the same way they've treated every major enterprise zero-day in recent memory: hit as many targets as possible, extract as much data as possible, and do it all before anyone patches.


According to CrowdStrike's post-incident analysis, exploitation in the wild started on August 9, 2025 — the same day Estée Lauder's Oracle EBS instance was compromised. Oracle didn't ship a fix until early October. That's roughly eight weeks of open season on a platform that countless large enterprises use for HR, finance, procurement, and supply chain management. Cl0p didn't waste a day of it.


By November 2025, the gang had listed more than 100 companies on its leak site. The list reads like a fortune 500 attendance sheet: Broadcom, Bechtel, Abbott Laboratories. And Estée Lauder, which leaked 870GB — one of the larger individual hauls in the campaign.


## The Data That Came Out


Estée Lauder used Oracle EBS for HR management, which is why the breach payload is as damaging as it gets for individual employees. The notification letter filed with the California Attorney General's Office lists:


  • Full names and home addresses
  • Dates of birth
  • Social Security numbers
  • Passport numbers
  • Bank account numbers
  • Health information
  • Employment records and payroll data

  • There's no obvious piece missing from this list. An identity thief handed this data would have everything needed to open credit accounts, file fraudulent tax returns, or impersonate an employee for years. The company is offering 24 months of identity monitoring, which is the standard post-breach response — adequate, but calibrated to the minimum expected by regulators rather than the actual exposure window employees faced.


    ## The Last Holdouts


    One detail that deserves more attention: by March 2026, Estée Lauder was one of only four named major companies that still hadn't publicly disclosed the Cl0p EBS campaign's impact. The others were Broadcom, Bechtel, and Abbott Laboratories. That's seven months after the exploitation window opened, and several months after Cl0p had already made the breach public by posting the stolen data.


    This creates a specific and underappreciated harm. Employees whose data appeared on Cl0p's leak site in late 2025 had no official confirmation from their employer to act on. They couldn't request credit freezes with an official incident date. They couldn't verify whether they were affected. Criminals had the data. The public knew Estée Lauder was a victim. The employees themselves were the last to be told.


    Estée Lauder says its investigation concluded in June 2026 — determining that personal data had actually been stolen. The company hasn't disclosed how many individuals are affected.


    ## Cl0p's Zero-Day Playbook Has Not Changed


    Cl0p's approach here is structurally identical to its MOVEit campaign in 2023 and its exploitation of GoAnywhere MFT that same year. Find an unauthenticated vulnerability in widely-deployed enterprise file transfer or business management software. Exploit it across as many targets as simultaneously as possible before defenders can react. Extort victims. Publish the data.


    What's changed is the target class. MOVEit hit managed file transfer. Oracle EBS hits the operational core of large enterprises — HR, finance, procurement. The underlying exploit type (unauthenticated RCE) keeps working because these systems were built decades ago for internal networks and enterprise trust models, not for the threat landscape they're now exposed to.


    For defenders still running Oracle EBS: CVE-2025-61882 has a patch. The question is whether your patch cadence matched your risk exposure last August, and whether you have the logging to know if you were compromised before you applied it.


    ---


    ## HackWire Analysis


    The Estée Lauder disclosure lands at an uncomfortable intersection of two persistent failures: enterprise patch velocity and breach notification timing.


    On the patch side, CVE-2025-61882 gave Cl0p eight weeks of exploitation runway before Oracle closed it. That gap isn't unusual for complex enterprise ERP systems — Oracle EBS patches require careful regression testing across customized deployments, and organizations routinely defer them. But Cl0p clearly understood this. They hit dozens of targets in the first days of exploitation, suggesting prior reconnaissance or inside knowledge of how long it would take the enterprise world to respond. The same dynamic played out with MOVEit. The question defenders should be asking isn't "did we patch?" but "what was our patch window, and did we monitor for exploitation signs during it?"


    On the notification side, eleven months is damaging in a specific way that doesn't get enough coverage. Cl0p's leak site is not obscure — journalists, security researchers, and dark web monitors saw the Estée Lauder data appear in late 2025. The employees who most needed to act were the last to be told. California's breach notification law requires "expedient" notification once an organization determines a breach has occurred; Estée Lauder is threading the needle by saying its investigation concluded in June 2026. Whether that timeline was genuinely necessary or reflects a litigation-minimization posture is a question worth asking.


    There's also a broader pattern here that other coverage is underweighting: the combination of HR data and financial data in a single EBS breach is close to a worst-case scenario for individual impact. SSNs alone are bad. Add bank account numbers, health records, and payroll history, and you have a dataset that enables layered fraud that victims won't fully surface for years. Two years of monitoring is not proportionate to that exposure horizon.


    The Cl0p zero-day playbook will be run again. The only variable is which enterprise platform comes next.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)