Estée Lauder Data Breach via Oracle E-Business Suite Zero-Day (CVE-2025-61882) — Clop Exploitation — Threadlinqs Intelligence
As of 2026-07-27, Estée Lauder Data Breach via Oracle E-Business Suite Zero-Day (CVE-2025-61882) — Clop Exploitation is a critical-severity data breach threat attributed to Cl0p, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 23 indicators of compromise.
Threat ID: TL-2026-1590 · Severity: CRITICAL · CVSS: 9.8 · Status: ACTIVE · Category: DATA_BREACH
Updated: 2026-07-27 · revalidated 1× · latest source
Attribution: Cl0p · FINANCIAL
Estée Lauder confirmed on June 19, 2026 that the Cl0p ransomware group breached its HR management system around August 9, 2025 by exploiting a zero-day authentication bypass and remote code execution
Beginning as early as August 9, 2025, the Cl0p ransomware/extortion collective (tracked by CrowdStrike as GRACEFUL SPIDER) conducted mass exploitation of an unauthenticated remote code execution zero-day in Oracle E-Business Suite (EBS), CVE-2025-61882, affecting versions 12.2.3 through 12.2.14 in the Oracle Concurrent Processing / BI Publisher (XML Publisher) Template Manager component.
The exploit chain begins with an HTTP POST to the /OA_HTML/SyncServlet endpoint that abuses the EBS configurator/UiServlet flow to bypass authentication, in some cases leveraging default or administrative session context (icx_sessions rows observed with UserID 0 'sysadmin' and UserID 6 'guest'). The attacker then issues GET/POST requests to /OA_HTML/RF.jsp and /OA_HTML/OA.jsp to upload a malicious XSL Template Manager template (an XSLT file such as ieshostedsurvey.xsl) into the xdo_templates_vl database table via the XML Publisher Template Manager. When the template is subsequently previewed/rendered by EBS, the XSLT engine instantiates a Java ScriptEngine, evaluates Base64-decoded JavaScript embedded in the stylesheet, and invokes Java Runtime.exec() to achieve unauthenticated OS command execution on the underlying application server. Post-exploitation, actors deployed web shells (via a two-step process involving FileUtils.java and Log4jConfigQpgsubFilter.java helper classes) invoked through crafted help-content paths such as /OA_HTML/help/state/content/destination./navId.1/navvSetId.iHelp/, and established outbound C2/exfiltration connections over TCP/443 to non-RFC1918 attacker infrastructure.
Exploitation predates public disclosure by nearly two months: extortion emails from addresses support@pubstorm.com and support@pubstorm.net (associated with the Cl0p leak site moniker since at least May 2025) began landing in victim executives' inboxes on September 29, 2025, months after data had already been exfiltrated (files provided to victims showed timestamps dating back to mid-August 2025). A leaked exploit bundle (exp.py, server.py, readme.md) was posted to a Telegram channel on October 3, 2025 by an entity self-identifying as SCATTERED LAPSUS$/'CL0P team', overlapping with monikers used by ShinyHunters and Scattered Spider-affiliated actors, complicating attribution — CrowdStrike assesses GRACEFUL SPIDER (Cl0p) as the primary actor with moderate confidence and cannot rule out a second actor cluster independently weaponizing the same bug. Oracle published its out-of-band security advisory and patch on October 4, 2025 (CVSS 3.1 base score 9.8, vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H); CISA added CVE-2025-61882 to the Known Exploited Vulnerabilities (KEV) catalog on October 6, 2025 with a mandated remediation deadline for federal civilian agencies.
Cl0p subsequently listed 29 alleged victim organizations on its dark-web extortion site, spanning higher education, media, industrials, aviation, retail/consumer, and technology sectors — consistent with the group's prior mass-exploitation extortion campaigns (2023 MOVEit Transfer, 2023 GoAnywhere MFT, 2020-2021 Accellion FTA), all of which followed the same playbook: silent zero-day mass exploitation and exfiltration, followed months later by a coordinated extortion email wave and public shaming site rather than on-host ransomware deployment. Estée Lauder, itself a repeat Cl0p victim from the 2023 MOVEit campaign, confirmed the breach of its HR management system on June 19, 2026 and disclosed exposure of employee names, addresses, emails, dates of birth, Social Security numbers, passport numbers, bank account information, health records, and payroll/performance data, offering 24 months of complimentary Kroll identity-monitoring services to affected employees.
Weaknesses (CWE)
CWE-287, CWE-94, CWE-502
Target sectors: retail, consumergoods, education, news - media, aviation, industrials, technology, health, financialservices
Target regions: North America, Europe, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 23 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
DATA_BREACH, CRITICAL, threat intelligence, cybersecurity, CVE-2025-61882, CVE-2026-46817, T1595, T1587, T1583, T1190, T1059, T1059, T1203, T1505, T1078, T1078