Sunday, 16 August 2026
The Verified Journalism Press

Journalism with its sources attached.

Sections
WORLD
AUSTRALIA
INDIA
BUSINESS
TECHNOLOGY
SCIENCE
SOCIETY
RIGHTS
CORRUPTION
CULTURE
OPINION
FAMOUS
The Press
Latest
Brussels has child safety cases open against Snapchat, Meta and TikTok, but not YouTube or the app storesMost Australian under-16s are still using social media, the regulator's own evaluation findsAI-designed viruses clear peer review, then an independent check finds them close relatives of the natural originalMIT's AI supercomputer has fallen 36 places in the world rankings without getting any slowerArizona physicists shift the quantum noise inside a light pulse, and watch it move in real timeApple has handed Siri to Google, and Amazon's Alexa+ has reached AustraliaBrussels has child safety cases open against Snapchat, Meta and TikTok, but not YouTube or the app storesMost Australian under-16s are still using social media, the regulator's own evaluation findsAI-designed viruses clear peer review, then an independent check finds them close relatives of the natural originalMIT's AI supercomputer has fallen 36 places in the world rankings without getting any slowerArizona physicists shift the quantum noise inside a light pulse, and watch it move in real timeApple has handed Siri to Google, and Amazon's Alexa+ has reached Australia
Markets
ASX 200
S&P 500
Nasdaq
FTSE 100
Nikkei
Gold
Brent
AUD / USD
AUD / EUR
AUD / GBP
AUD / JPY
Bitcoin
Ethereum
Yahoo · ECB · CoinGecko

Front page / Technology

Cybersecurity

Companies are still discovering they were caught in the 2025 Oracle and Red Hat breaches

Estee Lauder told regulators in July 2026 that intruders reached its Oracle E-Business Suite in August 2025, a breach it says it only identified in May this year. It is one of more than a hundred organisations swept up in two vendor compromises whose consequences are still arriving.

USA 17 at Oracle Corporation Headquarters - July 2019 (8327)
USA 17 at Oracle Corporation Headquarters - July 2019 (8327). Photograph: Gregory Varnum, CC BY-SA 4.0

The Cyber Express reported on 21 July 2026 that Estee Lauder had notified people affected by unauthorised access to the Oracle E-Business Suite system it uses for human resources. On the company's account, the access occurred around 9 August 2025, the incident was identified in May 2026 and its scope was confirmed on 19 June 2026. The exposed records included names, addresses, dates of birth, social security numbers, passport numbers, bank account details, health information and payroll records. Affected individuals were offered 24 months of identity monitoring.

That is a gap of eleven months between compromise and notification, and it is the pattern running through both the Oracle and the Red Hat compromises: a slow release of consequences into other people's organisations.

The Oracle flaw at the centre of it is CVE-2025-61882, an unauthenticated remote code execution vulnerability in the Concurrent Processing component of E-Business Suite, rated 9.8 on the CVSS severity scale and affecting versions 12.2.3 through 12.2.14. Rapid7 documented exploitation in the wild. Oracle issued an emergency patch on 4 October 2025, after the flaw had already been used as a zero day.

Google's Threat Intelligence Group and its Mandiant incident response arm attributed the campaign to an actor highly likely affiliated with Cl0p, the extortion crew also linked to the financially motivated group tracked as FIN11. CyberScoop reported that extortion emails were sent from hundreds of compromised accounts, a technique that bypasses reputation based spam filtering, and that demands reached as high as US$50 million.

The victim count grew steadily. SecurityWeek reported that Cl0p had named close to 30 alleged victims on its leak site by November 2025. SOCRadar's later analysis counted 103 organisations listed, with data for 77 of them published via torrent and magnet links. Organisations that have publicly confirmed being affected include Harvard University, Dartmouth College, the University of Pennsylvania, the University of the Witwatersrand, the American Airlines subsidiary Envoy Air, Logitech, Schneider Electric, Cox Enterprises and Madison Square Garden Entertainment.

The Washington Post published the clearest account of what one of these breaches looks like from inside. BleepingComputer and CyberScoop reported that the newspaper was first contacted on 29 September 2025 by someone claiming access to its Oracle applications, that its investigation concluded on 27 October, and that it notified 9,720 current and former employees and contractors. The attacker had access to its Oracle environment between 10 July and 22 August 2025. Stolen data included names, bank account and routing numbers, social security numbers and tax identification numbers.

The Red Hat side of the story has followed the same pattern at smaller scale. Red Hat confirmed on 2 October 2025 that an unauthorised third party had accessed and copied data from a GitLab instance used for Red Hat Consulting collaboration. The company said the instance held project specifications, sample code, internal communications and business contact information, that it had isolated the environment and contacted authorities, and that it had no reason to believe other Red Hat services or products were affected.

Red Hat has not confirmed the numbers the attackers publicised. The claims of 570 gigabytes taken from 28,000 repositories, including around 800 Customer Engagement Reports, come from the Crimson Collective, the group that carried out the intrusion, not from Red Hat. BleepingComputer and Dark Reading reported that the extortion escalated when the stolen material began appearing on the leak site operated by Scattered Lapsus$ Hunters, with the Crimson Collective describing itself as a customer of that infrastructure rather than a member of the group.

The downstream effect has been documented in at least one case. Security Affairs reported in December 2025 that Nissan disclosed the exposure of personal data belonging to roughly 21,000 customers of Nissan Fukuoka Sales, held in a customer management system developed using the compromised Red Hat GitLab instance. Nissan said Red Hat notified it on 3 October 2025 and that it reported the matter to Japan's Personal Information Protection Commission.

Patch discipline is only part of the answer here. The Oracle flaw was being exploited before a patch existed, which limits how much patching alone could have done. The sharper problem is detection. Estee Lauder's timeline, and The Washington Post's month long window of undetected access, suggest that many organisations running internet facing enterprise resource planning systems could not tell when someone had been inside them.

What is still open: no arrests have been announced in connection with either campaign, Red Hat has not published a concluding report on its investigation, and victims continue to surface almost a year after the original exploitation. The final list is not complete.

Sources

Every factual claim above rests on the 12 published sources below. They are listed so you can check the reporting rather than take it on trust.

  1. The Cyber ExpressEstee Lauder Data Breach Linked To Oracle EBS Flaw
  2. Red HatSecurity update: Incident related to Red Hat Consulting GitLab instance
  3. Security AffairsRed Hat GitLab breach exposes data of 21,000 Nissan customers
  4. BleepingComputerWashington Post data breach impacts nearly 10K employees, contractors
  5. CyberScoopWashington Post confirms data on nearly 10,000 people stolen from its Oracle environment
  6. SecurityWeekNearly 30 Alleged Victims of Oracle EBS Hack Named on Cl0p Ransomware Site
  7. SOCRadarCl0p's Oracle EBS Zero-Day Campaign: What We Know So Far
  8. Rapid7CVE-2025-61882: Critical 0day in Oracle E-Business Suite exploited in the wild
  9. CyberScoopHere is the email Clop attackers sent to Oracle customers
  10. BleepingComputerRed Hat data breach escalates as ShinyHunters joins extortion
  11. Dark ReadingRed Hat Hackers Team Up With Scattered Lapsus$ Hunters
  12. UpGuardData breach reported for Madison Square Garden Entertainment due to Oracle EBS breach

The Verified Briefing

One email each morning. Every story in it carries its sources, so you can check the reporting before you repeat it.

No tracking pixels. One click to leave.