Estée Lauder discloses data breach via Oracle E-Business flaw

Estée Lauder recently disclosed a data breach that occurred last August, when hackers exploited a vulnerability in the Oracle E-Business Suite system used for human resources operations. The company’s investigation revealed that an unauthorized third party gained access to personal information of certain individuals, including full names, addresses, email addresses, dates of birth, Social Security numbers, and more.

The breach is particularly concerning because it involved a well-known vulnerability in the Oracle E-Business Suite system. In October 2025, security researchers warned about breaches from the Clop ransomware gang exploiting this flaw to steal data. The vulnerability, known as CVE-2025-61882, affected versions 12.2.3–12.2.14 of the software and allowed attackers to bypass authentication and remotely execute code through the BI Publisher Integration component.

Estée Lauder’s notification letter does not provide details on how the company was compromised, but it appears that the breach occurred around the same time as a mass-exploitation campaign targeting Oracle E-Business Suite systems. The company has advised recipients of the breach notification to remain vigilant for signs of identity theft and fraud, and is offering 24 months of complimentary identity monitoring services through Kroll.

The Estée Lauder breach is not an isolated incident – several other organizations have been affected by the same vulnerability. Harvard, the University of Pennsylvania, Dartmouth, the University of Phoenix, The Washington Post, Logitech, GlobalLogic, Cox Enterprises, and Envoy Air have all been compromised in similar attacks. In some cases, these breaches were linked to the Clop ransomware gang.

It’s worth noting that Estée Lauder was also compromised by Clop in 2023, when the threat actor exploited another zero-day in the MOVEit Transfer platform – one of the firm’s internal software tools. This suggests that the company may have been vulnerable to similar attacks for some time.

The recent breach highlights the importance of keeping software up-to-date and patching known vulnerabilities. Oracle released fixes for CVE-2025-61882 in October 2025, but it appears that many organizations did not apply these patches in a timely manner. As security teams often struggle to detect and respond to attacks, regular penetration testing and vulnerability scanning can help identify potential weaknesses before they are exploited by attackers.

In the aftermath of the Estée Lauder breach, individuals affected should be on the lookout for signs of identity theft and fraud. They can also take steps to protect themselves by monitoring their credit reports and financial accounts closely. For organizations, this incident serves as a reminder to prioritize security and invest in robust threat detection and response capabilities.


Source: Bleeping Computer — 2026-07-20