Estee Lauder confirmed data theft as Clop and BlackCat both claimed attacks

Organization
The Estee Lauder Companies
Exploit
Ransomware
Industry
Consumer Goods

The Estee Lauder Companies confirmed on July 18, 2023 that an unauthorized third party had gained access to some of its systems and obtained data. The cosmetics group said it had proactively taken systems offline to stop the intruders expanding across its network, and that the incident had caused and was expected to continue causing disruption to parts of its business operations.

Two separate criminal groups listed the company on their leak sites at close to the same time. Clop, which had been exploiting a zero-day flaw in Progress Software's MOVEit Transfer product since the end of May 2023, claimed to hold more than 131 gigabytes of Estee Lauder data. ALPHV, also known as BlackCat, said it had carried out a separate intrusion, claimed more than 130 gigabytes, and stated that it had not encrypted any of the company's systems.

BlackCat said it first contacted company leadership on July 15 and, in a post dated July 18, claimed it still had access while incident responders were working. It referred to information relating to customers, employees and suppliers without giving specifics.

Estee Lauder engaged outside cybersecurity specialists, reported to include Microsoft's incident response team and Mandiant, and coordinated with law enforcement. Estee Lauder made no statement about negotiations. BlackCat said it received no reply to the emails it sent to company leadership, and Bitdefender's HotForSecurity blog inferred from that silence that the company may have decided not to negotiate. The nature and scope of the data taken remained under assessment as of the reporting date.

Sources