ProBackend
active vulnerability exploitation
3 hours ago5 min read

Clop Exploited Oracle Flaw to Steal Estée Lauder’s HR Data — And It’s Been Happening Since August

Estée Lauder’s year-long data breach was enabled by a zero-day in Oracle E-Business Suite, exploited by the Clop ransomware gang since August 2025 — a failure that mirrors systemic neglect across enterprise IT.

The Breach Wasn’t a Surprise. It Was Inevitable.

Estée Lauder didn’t get hacked. They were waiting to be hacked.

The company’s HR system — a sprawling Oracle E-Business Suite instance — had been sitting on the internet, exposed, unpatched, and ignored. When Clop slipped in through CVE-2025-61882 in August 2025, they didn’t break in. They walked in. The door was unlocked. The alarm was off. And nobody noticed for ten months.

This isn’t a story about a clever hacker. It’s about a broken system. And Estée Lauder, one of the world’s largest cosmetics companies, is just the latest victim of a pattern we’ve seen a hundred times: enterprise IT ignores Oracle patches until it’s too late.

The data stolen? Social Security numbers. Passport details. Health records. Payroll files. Personal information of 57,000 employees. And it wasn’t stolen by a script kiddie. It was taken by a ransomware gang that’s been doing this since 2021 — and has been targeting Oracle EBS since August 2025.

Clop didn’t need to be smart. They just needed to be patient. And every company that skipped the patch? They were handing Clop the keys.

I’ve seen this before. In 2023, Clop hit Estée Lauder again — this time through MOVEit. They didn’t learn. They didn’t change. They just kept running the same damn system.

And now? Now they’re paying the price. In trust. In lawsuits. In the quiet panic of an employee who just got a letter saying their child’s medical records are on a dark web forum.

This isn’t a breach. It’s a failure of leadership. And it’s happening everywhere.


The Flaw Was Public. The Patch Was Out. Nobody Cared.

CVE-2025-61882 wasn’t some shadowy, unknown vulnerability. Oracle published the patch on October 4, 2025. They called it critical. They warned customers. CrowdStrike confirmed Clop had been exploiting it since early August — two full months before the patch dropped.

And yet.

Estée Lauder didn’t patch.

Neither did Harvard. Or the University of Pennsylvania. Or the Washington Post. Or Logitech. Or Envoy Air.

CISA added this flaw to their Active Exploitation List on October 10, 2025. They issued a directive. They told federal agencies: patch by Saturday.

Did you hear that? Saturday.

And still, companies waited. They told themselves, "We’ll get to it next week." They told themselves, "Our system isn’t exposed." They told themselves, "We’re too small to be targeted."

Spoiler: you’re not too small. You’re just too slow.

The vulnerability? A flaw in the BI Publisher Integration component. It let attackers bypass authentication entirely. No username. No password. Just HTTP traffic. And boom — full access to HR data, financial records, everything.

Oracle’s own documentation says: "Failure to apply patches is the most common cause of successful breaches."

And yet.

We keep doing it.


The Real Crime Isn’t the Hack. It’s the Silence.

Estée Lauder’s breach notification letter? It’s the bare minimum. "We became aware of a cybersecurity issue." "We determined that an unauthorized third party gained access."

Where’s the accountability? Where’s the apology?

No one says: "We knew about this flaw. We had the patch. We chose not to install it. We’re sorry."

They say: "We’re notifying you. We’re offering two years of identity monitoring."

That’s not remediation. That’s damage control.

And here’s the kicker: the same company that’s now offering free credit monitoring to employees? They spent $14 billion last year on marketing. On lipstick. On foundation. On making women feel beautiful.

But they couldn’t spend $50,000 to patch a server?

I’m not mad. I’m just… disappointed.

This isn’t about security teams being understaffed. It’s about executives treating cybersecurity like an IT problem — not a business risk.

If your CFO won’t approve a patch because it might "disrupt payroll," you don’t need a new firewall. You need a new CEO.


Clop Isn’t the Villain. We Are.

Clop didn’t invent this. They just weaponized it. They’re not geniuses. They’re opportunists. And they’ve got a whole industry behind them: vulnerability brokers, exploit markets, ransomware-as-a-service platforms.

But the real villain? The CIO who says, "We don’t have time." The procurement team that won’t renew Oracle support. The legal team that says, "Don’t patch — it might trigger a compliance audit."

We built this. We enabled this. We keep doing it.

And now? Now we’re watching employees suffer while CEOs tweet about "AI-powered security" and "zero trust architectures."

Funny thing about zero trust: it doesn’t work if you’re still running a 12-year-old ERP system with unpatched vulnerabilities.

You can’t secure what you refuse to maintain.


The Lesson? Patch. Now. Or Pay Later.

This isn’t a one-off. It’s a trend. And it’s accelerating.

In 2026 alone, CISA has added 44 Oracle vulnerabilities to their active exploitation list. 13 of them were exploited by ransomware gangs.

And every single one? Patched. Months before the breach.

So here’s your checklist:

  1. Find every Oracle EBS instance you’re running. (Yes, even the one in accounting that nobody remembers.)
  2. Check if CVE-2025-61882 is still present.
  3. Patch it. Today.
  4. Then go find the other 43.

And if you can’t patch? If your vendor won’t support it? If your system is too old?

Then take it offline. Shut it down. Decommission it.

Don’t wait for a letter. Don’t wait for a breach.

Because when it happens — and it will — you won’t get a second chance.

Estée Lauder didn’t lose data.

They lost their credibility.

And that’s the one thing you can’t patch.


The Breach Wasn’t a Surprise. It Was Inevitable

More blogs