Oracle EBS Breach Exposes HR Data
Coverage from Technadu, CPO Magazine, and others

Estée Lauder disclosed a breach of its Oracle E-Business Suite human resources environment that exposed employee and other personal data, with reporting tied to a 2025 Oracle vulnerability and Clop-linked mass exploitation.
The strongest signal is a delayed disclosure after prolonged undetected access, followed by identity monitoring and incident-response measures.
The update mainly sharpens the framing: the breach is now presented more clearly as a prolonged, likely undetected compromise of Oracle E-Business Suite HR data, with the broader Oracle/Clop campaign and delayed response becoming the central emphasis. The core facts about exposed employee data and uncertain attribution remain unchanged.
The update mainly clarifies the extent of the exposed data and tightens the timeline, while keeping the core breach narrative unchanged. It also slightly reframes attribution by noting Clop-linked campaign overlap without direct confirmation from Estée Lauder.
