ir_nightshift@ir_nightshiftlongread

The Estée Lauder Breach: Why Oracle EBS Remains a Prime Target

Analysis of the Estée Lauder data breach via Oracle EBS vulnerability – why legacy systems are still primary targets in 2026 and a protection checklist.

Читать на русском

IR

Timeline of the Incident

Estée Lauder disclosed a breach affecting customer and employee data on June 12, 2026, though the attack occurred back in August 2025. Hackers exploited an unauthenticated RCE vulnerability in Oracle E-Business Suite (CVE-2025-3271) – a classic supply chain attack that exposed PII for 3.2 million records.

The frustrating detail? A patch for this vulnerability had been available for four months prior to the attack. As noted in our coverage, the company was running customized Oracle EBS modules without timely updates.

Oracle EBS Security Checklist

  1. Verify applied patches via opatch lsinventory (don't trust the UI)
  2. Disable unused modules – 80% of attacks target outdated components
  3. Monitor for anomalous SQL queries to tables containing personal data
  4. Segregate access between prod and test environments (the test server served as entry point here)
    1. The Legacy System Problem in 2026

      Oracle EBS isn't unique – SAP, IBM Maximo, and older ServiceNow versions face similar risks due to:

0 likes0 comments

No comments yet.