✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Cosmetics
Breach intelligence, attack campaigns, and threat reports targeting the Cosmetics sector.
Explore Other Sectors
Cosmetics Threat Reports
Estée Lauder's 2025 Data Breach: A Cautionary Tale of Unpatched Vulnerabilities
In August 2025, Estée Lauder experienced a significant data breach when attackers exploited a critical vulnerability (CVE-2025-61882) in Oracle's E-Business Suite, specifically targeting the BI Publisher Integration component. This flaw allowed unauthenticated remote code execution, enabling the Clop ransomware group to access and exfiltrate sensitive personal information of certain individuals, including full names, postal addresses, email addresses, dates of birth, Social Security numbers, passport numbers, financial account information, health information, and employment details. The breach was identified in June 2026, prompting Estée Lauder to notify affected individuals and offer 24 months of complimentary identity monitoring services through Kroll. ([oracle.com](https://www.oracle.com/security-alerts/alert-cve-2025-61882.html?utm_source=openai)) This incident underscores the critical importance of timely patch management and proactive vulnerability assessments. The exploitation of CVE-2025-61882 by the Clop group highlights a broader trend of ransomware actors leveraging zero-day vulnerabilities to infiltrate enterprise systems, emphasizing the need for organizations to enhance their cybersecurity posture to mitigate such threats. ([computerweekly.com](https://www.computerweekly.com/news/366632397/Oracle-patches-E-Business-suite-targeted-by-Cl0p-ransomware?utm_source=openai))
13 hours ago
Kill Chain
Rituals Data Breach 2026: Safeguarding Customer Information
In April 2026, Dutch cosmetics company Rituals experienced a data breach affecting its 'My Rituals' membership database. Unauthorized parties accessed and downloaded personal information, including full names, email addresses, phone numbers, dates of birth, gender, and home addresses. Notably, no passwords or payment information were compromised. The company promptly contained the breach, notified affected customers, and initiated a forensic investigation to prevent future incidents. This incident underscores the growing trend of cyberattacks targeting customer loyalty programs, which often house extensive personal data. Organizations must prioritize the security of such databases to mitigate risks associated with unauthorized access and potential misuse of personal information.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports