Estée Lauder confirmed that an unauthorized party gained access to its Oracle E-Business Suite HR platform as far back as August 2025, but the breach wasn’t confirmed until June 2026, nearly ten months later, tied to the broader Cl0p ransomware campaign that has been mass-exploiting Oracle EBS across shared enterprise software, no targeted attack required, no unique vulnerability built just for Estée Lauder, just a shared platform that thousands of other companies were running too.
The breach notification can be read here: ELC – U.S. Individual Notification Letter.pdf
John Watters, Chairman and CEO, iCounter had this to say:
“Ten months between intrusion and disclosure at Estée Lauder isn’t a failure unique to this company, it’s Clop’s business model working exactly as designed. This group doesn’t break into companies one at a time. They find a vulnerability in software that thousands of organizations share, harvest data quietly across as many victims as they can before anyone notices, and then work through the extortion process at their own pace long after the initial compromise. By the time a company like Estée Lauder confirms what happened, Clop has already known the shape of that exposure for the better part of a year.
The organizations that catch this fast aren’t the ones with better firewalls, they’re the ones with threat intelligence mature enough to know, within days of a campaign like this becoming public, whether they were one of the platforms swept up in it, instead of waiting for a forensic investigation to tell them what an intelligence program should have flagged months earlier. And that intelligence work doesn’t stop once the campaign is public. Clop rolls out its victim list over time rather than all at once, which means every new name that gets published is a live signal, not old news. If your organization runs the same software as the companies showing up on that list, each new name should be treated as a countdown, not a headline about somebody else’s bad month.”
This is a #fail. There is no way that this amount of time should have passed before affected parties should have been notified. Normally I would say that someone should be punished for this. But I am pretty sure that this isn’t going to happen in this case.
Related
This entry was posted on July 21, 2026 at 2:51 pm and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Estée Lauder’s ten-month gap between breach and disclosure is a #fail
Estée Lauder confirmed that an unauthorized party gained access to its Oracle E-Business Suite HR platform as far back as August 2025, but the breach wasn’t confirmed until June 2026, nearly ten months later, tied to the broader Cl0p ransomware campaign that has been mass-exploiting Oracle EBS across shared enterprise software, no targeted attack required, no unique vulnerability built just for Estée Lauder, just a shared platform that thousands of other companies were running too.
The breach notification can be read here: ELC – U.S. Individual Notification Letter.pdf
John Watters, Chairman and CEO, iCounter had this to say:
“Ten months between intrusion and disclosure at Estée Lauder isn’t a failure unique to this company, it’s Clop’s business model working exactly as designed. This group doesn’t break into companies one at a time. They find a vulnerability in software that thousands of organizations share, harvest data quietly across as many victims as they can before anyone notices, and then work through the extortion process at their own pace long after the initial compromise. By the time a company like Estée Lauder confirms what happened, Clop has already known the shape of that exposure for the better part of a year.
The organizations that catch this fast aren’t the ones with better firewalls, they’re the ones with threat intelligence mature enough to know, within days of a campaign like this becoming public, whether they were one of the platforms swept up in it, instead of waiting for a forensic investigation to tell them what an intelligence program should have flagged months earlier. And that intelligence work doesn’t stop once the campaign is public. Clop rolls out its victim list over time rather than all at once, which means every new name that gets published is a live signal, not old news. If your organization runs the same software as the companies showing up on that list, each new name should be treated as a countdown, not a headline about somebody else’s bad month.”
This is a #fail. There is no way that this amount of time should have passed before affected parties should have been notified. Normally I would say that someone should be punished for this. But I am pretty sure that this isn’t going to happen in this case.
Share this:
Like this:
Related
This entry was posted on July 21, 2026 at 2:51 pm and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.