Estée Lauder Data Breach via Oracle E-Business Suite Zero-Day (CVE-2025-61882) — Clop Exploitation
Estée Lauder Data Breach via Oracle E-Business Suite (TL-2026-1590), also tracked as Oracle EBS Zero-Day Extortion Campaign, is a critical-severity data breach scored CVSS 9.8, first published 2026-07-21 and last reviewed 2026-07-27. It is attributed to Cl0p with medium confidence, affects Oracle E-Business Suite, references 2 CVEs (CVE-2025-61882, CVE-2026-46817), maps to 19 MITRE ATT&CK techniques (T1027, T1041, T1059), and is covered by 9 detection rules and 23 indicators of compromise.
Key facts for TL-2026-1590
- Threat ID
- TL-2026-1590
- Also known as
- Oracle EBS Zero-Day Extortion Campaign, Cl0p Oracle EBS Campaign
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- DATA_BREACH
- First published
- 2026-07-21
- Last reviewed
- 2026-07-27
- Attribution
- Cl0p
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- retail, consumergoods, education, news - media, aviation, industrials, technology, health, financialservices
- Target regions
- North America, Europe, Global
- Detection rules
- 9
- Indicators of compromise
- 23
- Updates
- 2026-07-27 · revalidated 1× · latest source
Malware and tooling in Estée Lauder Data Breach via Oracle E-Business Suite
Malware and tooling: Cl0p leak-site extortion (no on-host ransomware payload)
Estée Lauder confirmed on June 19, 2026 that the Cl0p ransomware group breached its HR management system around August 9, 2025 by exploiting a zero-day authentication bypass and remote code execution flaw (CVE-2025-61882) in the Oracle E-Business Suite BI Publisher / XML Publisher Template Manager component. Exposed data includes employee PII, SSNs, passport numbers, bank details, health records, and payroll data. The same campaign compromised nearly 30 organizations globally including Harvard, UPenn, Dartmouth, University of Phoenix, Washington Post, Logitech, GlobalLogic, Cox Enterprises, Envoy Air, Schneider Electric, Emerson, Pan American Silver, LKQ Corporation, and Copeland.
How Estée Lauder Data Breach via Oracle E-Business Suite works
Beginning as early as August 9, 2025, the Cl0p ransomware/extortion collective (tracked by CrowdStrike as GRACEFUL SPIDER) conducted mass exploitation of an unauthenticated remote code execution zero-day in Oracle E-Business Suite (EBS), CVE-2025-61882, affecting versions 12.2.3 through 12.2.14 in the Oracle Concurrent Processing / BI Publisher (XML Publisher) Template Manager component.
The exploit chain begins with an HTTP POST to the /OA_HTML/SyncServlet endpoint that abuses the EBS configurator/UiServlet flow to bypass authentication, in some cases leveraging default or administrative session context (icx_sessions rows observed with UserID 0 'sysadmin' and UserID 6 'guest'). The attacker then issues GET/POST requests to /OA_HTML/RF.jsp and /OA_HTML/OA.jsp to upload a malicious XSL Template Manager template (an XSLT file such as ieshostedsurvey.xsl) into the xdo_templates_vl database table via the XML Publisher Template Manager. When the template is subsequently previewed/rendered by EBS, the XSLT engine instantiates a Java ScriptEngine, evaluates Base64-decoded JavaScript embedded in the stylesheet, and invokes Java Runtime.exec() to achieve unauthenticated OS command execution on the underlying application server. Post-exploitation, actors deployed web shells (via a two-step process involving FileUtils.java and Log4jConfigQpgsubFilter.java helper classes) invoked through crafted help-content paths such as /OA_HTML/help/state/content/destination./navId.1/navvSetId.iHelp/, and established outbound C2/exfiltration connections over TCP/443 to non-RFC1918 attacker infrastructure.
Exploitation predates public disclosure by nearly two months: extortion emails from addresses support@pubstorm.com and support@pubstorm.net (associated with the Cl0p leak site moniker since at least May 2025) began landing in victim executives' inboxes on September 29, 2025, months after data had already been exfiltrated (files provided to victims showed timestamps dating back to mid-August 2025). A leaked exploit bundle (exp.py, server.py, readme.md) was posted to a Telegram channel on October 3, 2025 by an entity self-identifying as SCATTERED LAPSUS$/'CL0P team', overlapping with monikers used by ShinyHunters and Scattered Spider-affiliated actors, complicating attribution — CrowdStrike assesses GRACEFUL SPIDER (Cl0p) as the primary actor with moderate confidence and cannot rule out a second actor cluster independently weaponizing the same bug. Oracle published its out-of-band security advisory and patch on October 4, 2025 (CVSS 3.1 base score 9.8, vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H); CISA added CVE-2025-61882 to the Known Exploited Vulnerabilities (KEV) catalog on October 6, 2025 with a mandated remediation deadline for federal civilian agencies.
Cl0p subsequently listed 29 alleged victim organizations on its dark-web extortion site, spanning higher education, media, industrials, aviation, retail/consumer, and technology sectors — consistent with the group's prior mass-exploitation extortion campaigns (2023 MOVEit Transfer, 2023 GoAnywhere MFT, 2020-2021 Accellion FTA), all of which followed the same playbook: silent zero-day mass exploitation and exfiltration, followed months later by a coordinated extortion email wave and public shaming site rather than on-host ransomware deployment. Estée Lauder, itself a repeat Cl0p victim from the 2023 MOVEit campaign, confirmed the breach of its HR management system on June 19, 2026 and disclosed exposure of employee names, addresses, emails, dates of birth, Social Security numbers, passport numbers, bank account information, health records, and payroll/performance data, offering 24 months of complimentary Kroll identity-monitoring services to affected employees.
MITRE ATT&CK techniques used in TL-2026-1590
Defense Evasion
T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution
Command and Control
T1071 Application Layer Protocol; T1105 Ingress Tool Transfer
Persistence
T1078 Valid Accounts; T1505 Server Software Component
Privilege Escalation
Discovery
T1082 System Information Discovery; T1083 File and Directory Discovery
Collection
T1119 Automated Collection; T1213 Data from Information Repositories
Initial Access
T1190 Exploit Public-Facing Application
Impact
T1486 Data Encrypted for Impact; T1657 Financial Theft
Resource Development
T1583 Acquire Infrastructure; T1587 Develop Capabilities
Reconnaissance
Affected products and versions in Estée Lauder Data Breach via Oracle E-Business Suite
- Oracle — E-Business Suite
Vulnerable versions: 12.2.3; 12.2.4; 12.2.5; 12.2.6; 12.2.7; 12.2.8; 12.2.9; 12.2.10; 12.2.11; 12.2.12
Fixed in: 12.2.x with Oracle Security Alert patch for CVE-2025-61882 (October 4, 2025), requires October 2023 Critical Patch Update as prerequisite
Remediation for Estée Lauder Data Breach via Oracle E-Business Suite
Patches
- Oracle Security Alert Advisory CVE-2025-61882, published October 4, 2025 — Oracle E-Business Suite Concurrent Processing / BI Publisher Integration component
Immediate actions
- Apply Oracle's October 4, 2025 out-of-band security patch for CVE-2025-61882 to all Oracle E-Business Suite instances (12.2.3-12.2.14) immediately
- Confirm the October 2023 Critical Patch Update prerequisite is installed before applying the CVE-2025-61882 patch
- Hunt xdo_templates_vl for unauthorized/unexpected XSL template entries
- Review icx_sessions for anomalous sessions under UserID 0 (sysadmin) or UserID 6 (guest)
- Inspect EBS application-tier hosts and web-accessible paths (especially /OA_HTML/help/state/content/...) for planted web shells or unexpected .jsp/.java artifacts
- Block/alert on outbound TCP/443 connections from EBS application servers to non-RFC1918, non-Oracle destinations
- Search email gateways for extortion messages referencing support@pubstorm.com / support@pubstorm.net
- Rotate credentials and session tokens for EBS administrative and integration accounts
Workarounds
- Where immediate patching is not possible, restrict network access to EBS OA_HTML/SyncServlet, RF.jsp, and OA.jsp endpoints to trusted internal IP ranges only
- Disable or restrict XML/BI Publisher Template Manager preview functionality for untrusted or unauthenticated sessions
Longer-term hardening
- Segment Oracle EBS application tiers from general corporate network and restrict internet exposure of OA_HTML endpoints
- Deploy EDR/behavioral monitoring on EBS application servers capable of detecting Java Runtime.exec() spawning from web-server processes
- Implement WAF rules to inspect/block anomalous XSLT/XML Publisher template upload requests
- Establish a vulnerability management SLA for internet-facing ERP/EBS systems aligned with CISA KEV deadlines
- Conduct regular threat-hunting sweeps for historical Cl0p mass-exploitation campaigns (MOVEit, GoAnywhere, Accellion) given repeat targeting of this actor
CVEs associated with Estée Lauder Data Breach via Oracle E-Business Suite
Weaknesses (CWE) in Estée Lauder Data Breach via Oracle E-Business Suite
CWE-287, CWE-94, CWE-502
Timeline of Estée Lauder Data Breach via Oracle E-Business Suite
- First known exploitation of CVE-2025-61882 against Oracle E-Business Suite instances begins; Estée Lauder's HR management system compromised around this date.
- GRACEFUL SPIDER (Cl0p) begins sending extortion emails from support@pubstorm.com / support@pubstorm.net to executives at victim organizations, claiming data exfiltration from Oracle EBS.
- Text of Cl0p extortion emails sent to Oracle EBS customers publicly reported by media (CyberScoop).
- A working exploit bundle (exp.py, server.py, readme.md) for CVE-2025-61882 is posted to a Telegram channel by an actor self-identifying as SCATTERED LAPSUS$/'CL0P team'.
- Oracle publishes an out-of-band Security Alert advisory and patch for CVE-2025-61882 (CVSS 9.8), covering E-Business Suite 12.2.3-12.2.14.
- CISA adds CVE-2025-61882 to the Known Exploited Vulnerabilities (KEV) catalog, mandating remediation for federal civilian agencies.
- Cl0p lists roughly 29 alleged victim organizations, including Harvard, Washington Post, Envoy Air, Logitech, Cox Enterprises, on its dark-web extortion site.
- Cl0p's Oracle E-Business Suite mass-exploitation campaign begins generating claims against Italian organizations (4 claims recorded January-February 2026), per the ransomNews RedACT H1 2026 tracker cited by SecurityAffairs.
- Oracle E-Business Suite continues to be targeted into 2026 via a second flaw, CVE-2026-46817 (Improper Privilege Management), reported actively exploited in the wild (The Hacker News).
- Estée Lauder confirms the breach of its HR management system, disclosing exposure of employee PII, SSNs, passport numbers, bank data, health records, and payroll data.
- The Register reports Oracle E-Business Suite was under attack via CVE-2026-46817 before public exploit code was even released; Bleeping Computer separately reports 900+ internet-exposed Oracle EBS instances at risk.
- CISA adds CVE-2026-46817 (Oracle E-Business Suite Improper Privilege Management) to the Known Exploited Vulnerabilities catalog with a short (3-day) remediation deadline.
- The Cyber Express publishes detailed coverage of the Estée Lauder breach and its connection to the broader Oracle EBS Cl0p campaign.
Update history for TL-2026-1590
- 2026-07-27 — LockBit5 and Qilin Lead H1 2026 Ransomware Surge Against Italian Organizations (148 Confirmed Claims): What changed Cl0p's Oracle EBS mass-exploitation campaign, previously tracked here only for CVE-2025-61882, is confirmed continuing into 2026 against a second Oracle EBS flaw, CVE-2026-46817 (Improper Privilege Management) — exploited befor
Sources cited for Estée Lauder Data Breach via Oracle E-Business Suite
- Estée Lauder Data Breach: Oracle EBS Flaw Exploited by Clop
- Critical 0day in Oracle E-Business Suite exploited in-the-wild
- CrowdStrike Identifies Campaign Targeting Oracle E-Business Suite via Zero-Day Vulnerability Tracked as CVE-2025-61882
- CVE-2025-61882: Oracle E-Business Suite Zero-Day Exploited in Clop Extortion Campaigns
- Lessons from Oracle E-Business Suite Hack That Allegedly Compromises Nearly 30 Organizations Worldwide
- Nearly 30 Alleged Victims of Oracle EBS Hack Named on Cl0p Ransomware Site
- Google: Clop Accessed "Significant Amount" of Data in Oracle EBS Exploitation
- Here is the email Clop attackers sent to Oracle customers
- Oracle customers targeted with emails claiming E-Business Suite breach, data theft
- Cl0p ransomware gang names 29 Oracle EBS breach victims
- Clop's New Extortion Wave Hits Oracle E-Business Suite
- Inside Cl0p Ransomware: How Oracle EBS Clients Can Stay Ahead of Threats
- Dartmouth College Data Breach: Clop Ransomware Exploits Oracle E-Business Suite Zero-Day (CVE-2025-61882)
- Cl0p Abuses Oracle E-Business Suite for Account Takeover
Threats related to Estée Lauder Data Breach via Oracle E-Business Suite
- Q1 2026 Ransomware Landscape: Qilin Dominance, LockBit 5.0 Comeback, and FortiGate (CVE-2024-55591) / Oracle EBS (CVE-2025-61882) Mass Exploitation
- CISA KEV Adds CVE-2026-12569 (PTC Windchill/FlexPLM Unauthenticated RCE via Deserialization) and CVE-2026-20230 (Cisco Unified CM WebDialer SSRF to Root)
- CVE-2026-46817: Critical Unauthenticated File-Read/Takeover Flaw in Oracle E-Business Suite Payments Exploited Pre-PoC
- CVE-2026-46817: Unauthenticated Arbitrary File Read in Oracle E-Business Suite Payments File Transmission Exploited Before Public PoC
- CVE-2026-46817: Active Exploitation Against ~950 Internet-Exposed Oracle E-Business Suite Payments Instances
- CVE-2026-46817: Oracle E-Business Suite Payments Authentication Bypass – Unauth Remote Takeover via /OA_HTML/ibytransmit
Detection coverage for TL-2026-1590
As of 2026-07-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1590 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1590
2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.