Estée Lauder Data Breach via Oracle E-Business Suite Zero-Day (CVE-2025-61882) — Clop Exploitation

Estée Lauder Data Breach via Oracle E-Business Suite (TL-2026-1590), also tracked as Oracle EBS Zero-Day Extortion Campaign, is a critical-severity data breach scored CVSS 9.8, first published 2026-07-21 and last reviewed 2026-07-27. It is attributed to Cl0p with medium confidence, affects Oracle E-Business Suite, references 2 CVEs (CVE-2025-61882, CVE-2026-46817), maps to 19 MITRE ATT&CK techniques (T1027, T1041, T1059), and is covered by 9 detection rules and 23 indicators of compromise.

Key facts for TL-2026-1590

Threat ID
TL-2026-1590
Also known as
Oracle EBS Zero-Day Extortion Campaign, Cl0p Oracle EBS Campaign
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
DATA_BREACH
First published
2026-07-21
Last reviewed
2026-07-27
Attribution
Cl0p
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
retail, consumergoods, education, news - media, aviation, industrials, technology, health, financialservices
Target regions
North America, Europe, Global
Detection rules
9
Indicators of compromise
23
Updates
2026-07-27 · revalidated 1× · latest source

Malware and tooling in Estée Lauder Data Breach via Oracle E-Business Suite

Malware and tooling: Cl0p leak-site extortion (no on-host ransomware payload)

Estée Lauder confirmed on June 19, 2026 that the Cl0p ransomware group breached its HR management system around August 9, 2025 by exploiting a zero-day authentication bypass and remote code execution flaw (CVE-2025-61882) in the Oracle E-Business Suite BI Publisher / XML Publisher Template Manager component. Exposed data includes employee PII, SSNs, passport numbers, bank details, health records, and payroll data. The same campaign compromised nearly 30 organizations globally including Harvard, UPenn, Dartmouth, University of Phoenix, Washington Post, Logitech, GlobalLogic, Cox Enterprises, Envoy Air, Schneider Electric, Emerson, Pan American Silver, LKQ Corporation, and Copeland.

How Estée Lauder Data Breach via Oracle E-Business Suite works

Beginning as early as August 9, 2025, the Cl0p ransomware/extortion collective (tracked by CrowdStrike as GRACEFUL SPIDER) conducted mass exploitation of an unauthenticated remote code execution zero-day in Oracle E-Business Suite (EBS), CVE-2025-61882, affecting versions 12.2.3 through 12.2.14 in the Oracle Concurrent Processing / BI Publisher (XML Publisher) Template Manager component.

The exploit chain begins with an HTTP POST to the /OA_HTML/SyncServlet endpoint that abuses the EBS configurator/UiServlet flow to bypass authentication, in some cases leveraging default or administrative session context (icx_sessions rows observed with UserID 0 'sysadmin' and UserID 6 'guest'). The attacker then issues GET/POST requests to /OA_HTML/RF.jsp and /OA_HTML/OA.jsp to upload a malicious XSL Template Manager template (an XSLT file such as ieshostedsurvey.xsl) into the xdo_templates_vl database table via the XML Publisher Template Manager. When the template is subsequently previewed/rendered by EBS, the XSLT engine instantiates a Java ScriptEngine, evaluates Base64-decoded JavaScript embedded in the stylesheet, and invokes Java Runtime.exec() to achieve unauthenticated OS command execution on the underlying application server. Post-exploitation, actors deployed web shells (via a two-step process involving FileUtils.java and Log4jConfigQpgsubFilter.java helper classes) invoked through crafted help-content paths such as /OA_HTML/help/state/content/destination./navId.1/navvSetId.iHelp/, and established outbound C2/exfiltration connections over TCP/443 to non-RFC1918 attacker infrastructure.

Exploitation predates public disclosure by nearly two months: extortion emails from addresses support@pubstorm.com and support@pubstorm.net (associated with the Cl0p leak site moniker since at least May 2025) began landing in victim executives' inboxes on September 29, 2025, months after data had already been exfiltrated (files provided to victims showed timestamps dating back to mid-August 2025). A leaked exploit bundle (exp.py, server.py, readme.md) was posted to a Telegram channel on October 3, 2025 by an entity self-identifying as SCATTERED LAPSUS$/'CL0P team', overlapping with monikers used by ShinyHunters and Scattered Spider-affiliated actors, complicating attribution — CrowdStrike assesses GRACEFUL SPIDER (Cl0p) as the primary actor with moderate confidence and cannot rule out a second actor cluster independently weaponizing the same bug. Oracle published its out-of-band security advisory and patch on October 4, 2025 (CVSS 3.1 base score 9.8, vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H); CISA added CVE-2025-61882 to the Known Exploited Vulnerabilities (KEV) catalog on October 6, 2025 with a mandated remediation deadline for federal civilian agencies.

Cl0p subsequently listed 29 alleged victim organizations on its dark-web extortion site, spanning higher education, media, industrials, aviation, retail/consumer, and technology sectors — consistent with the group's prior mass-exploitation extortion campaigns (2023 MOVEit Transfer, 2023 GoAnywhere MFT, 2020-2021 Accellion FTA), all of which followed the same playbook: silent zero-day mass exploitation and exfiltration, followed months later by a coordinated extortion email wave and public shaming site rather than on-host ransomware deployment. Estée Lauder, itself a repeat Cl0p victim from the 2023 MOVEit campaign, confirmed the breach of its HR management system on June 19, 2026 and disclosed exposure of employee names, addresses, emails, dates of birth, Social Security numbers, passport numbers, bank account information, health records, and payroll/performance data, offering 24 months of complimentary Kroll identity-monitoring services to affected employees.

MITRE ATT&CK techniques used in TL-2026-1590

Defense Evasion

T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution

Command and Control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer

Persistence

T1078 Valid Accounts; T1505 Server Software Component

Privilege Escalation

T1078 Valid Accounts

Discovery

T1082 System Information Discovery; T1083 File and Directory Discovery

Collection

T1119 Automated Collection; T1213 Data from Information Repositories

Initial Access

T1190 Exploit Public-Facing Application

Impact

T1486 Data Encrypted for Impact; T1657 Financial Theft

Resource Development

T1583 Acquire Infrastructure; T1587 Develop Capabilities

Reconnaissance

T1595 Active Scanning

Affected products and versions in Estée Lauder Data Breach via Oracle E-Business Suite

  • Oracle — E-Business Suite
    Vulnerable versions: 12.2.3; 12.2.4; 12.2.5; 12.2.6; 12.2.7; 12.2.8; 12.2.9; 12.2.10; 12.2.11; 12.2.12
    Fixed in: 12.2.x with Oracle Security Alert patch for CVE-2025-61882 (October 4, 2025), requires October 2023 Critical Patch Update as prerequisite

Remediation for Estée Lauder Data Breach via Oracle E-Business Suite

Patches

  • Oracle Security Alert Advisory CVE-2025-61882, published October 4, 2025 — Oracle E-Business Suite Concurrent Processing / BI Publisher Integration component

Immediate actions

  • Apply Oracle's October 4, 2025 out-of-band security patch for CVE-2025-61882 to all Oracle E-Business Suite instances (12.2.3-12.2.14) immediately
  • Confirm the October 2023 Critical Patch Update prerequisite is installed before applying the CVE-2025-61882 patch
  • Hunt xdo_templates_vl for unauthorized/unexpected XSL template entries
  • Review icx_sessions for anomalous sessions under UserID 0 (sysadmin) or UserID 6 (guest)
  • Inspect EBS application-tier hosts and web-accessible paths (especially /OA_HTML/help/state/content/...) for planted web shells or unexpected .jsp/.java artifacts
  • Block/alert on outbound TCP/443 connections from EBS application servers to non-RFC1918, non-Oracle destinations
  • Search email gateways for extortion messages referencing support@pubstorm.com / support@pubstorm.net
  • Rotate credentials and session tokens for EBS administrative and integration accounts

Workarounds

  • Where immediate patching is not possible, restrict network access to EBS OA_HTML/SyncServlet, RF.jsp, and OA.jsp endpoints to trusted internal IP ranges only
  • Disable or restrict XML/BI Publisher Template Manager preview functionality for untrusted or unauthenticated sessions

Longer-term hardening

  • Segment Oracle EBS application tiers from general corporate network and restrict internet exposure of OA_HTML endpoints
  • Deploy EDR/behavioral monitoring on EBS application servers capable of detecting Java Runtime.exec() spawning from web-server processes
  • Implement WAF rules to inspect/block anomalous XSLT/XML Publisher template upload requests
  • Establish a vulnerability management SLA for internet-facing ERP/EBS systems aligned with CISA KEV deadlines
  • Conduct regular threat-hunting sweeps for historical Cl0p mass-exploitation campaigns (MOVEit, GoAnywhere, Accellion) given repeat targeting of this actor

CVEs associated with Estée Lauder Data Breach via Oracle E-Business Suite

CVE-2025-61882, CVE-2026-46817

Weaknesses (CWE) in Estée Lauder Data Breach via Oracle E-Business Suite

CWE-287, CWE-94, CWE-502

Timeline of Estée Lauder Data Breach via Oracle E-Business Suite

  • First known exploitation of CVE-2025-61882 against Oracle E-Business Suite instances begins; Estée Lauder's HR management system compromised around this date.
  • GRACEFUL SPIDER (Cl0p) begins sending extortion emails from support@pubstorm.com / support@pubstorm.net to executives at victim organizations, claiming data exfiltration from Oracle EBS.
  • Text of Cl0p extortion emails sent to Oracle EBS customers publicly reported by media (CyberScoop).
  • A working exploit bundle (exp.py, server.py, readme.md) for CVE-2025-61882 is posted to a Telegram channel by an actor self-identifying as SCATTERED LAPSUS$/'CL0P team'.
  • Oracle publishes an out-of-band Security Alert advisory and patch for CVE-2025-61882 (CVSS 9.8), covering E-Business Suite 12.2.3-12.2.14.
  • CISA adds CVE-2025-61882 to the Known Exploited Vulnerabilities (KEV) catalog, mandating remediation for federal civilian agencies.
  • Cl0p lists roughly 29 alleged victim organizations, including Harvard, Washington Post, Envoy Air, Logitech, Cox Enterprises, on its dark-web extortion site.
  • Cl0p's Oracle E-Business Suite mass-exploitation campaign begins generating claims against Italian organizations (4 claims recorded January-February 2026), per the ransomNews RedACT H1 2026 tracker cited by SecurityAffairs.
  • Oracle E-Business Suite continues to be targeted into 2026 via a second flaw, CVE-2026-46817 (Improper Privilege Management), reported actively exploited in the wild (The Hacker News).
  • Estée Lauder confirms the breach of its HR management system, disclosing exposure of employee PII, SSNs, passport numbers, bank data, health records, and payroll data.
  • The Register reports Oracle E-Business Suite was under attack via CVE-2026-46817 before public exploit code was even released; Bleeping Computer separately reports 900+ internet-exposed Oracle EBS instances at risk.
  • CISA adds CVE-2026-46817 (Oracle E-Business Suite Improper Privilege Management) to the Known Exploited Vulnerabilities catalog with a short (3-day) remediation deadline.
  • The Cyber Express publishes detailed coverage of the Estée Lauder breach and its connection to the broader Oracle EBS Cl0p campaign.

Update history for TL-2026-1590

Sources cited for Estée Lauder Data Breach via Oracle E-Business Suite

Threats related to Estée Lauder Data Breach via Oracle E-Business Suite

Detection coverage for TL-2026-1590

As of 2026-07-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1590 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-1590

2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats