Estée Lauder discloses data breach via Oracle E-Business flaw

Estée Lauder’s Data Breach Exposes Sensitive Information of 57,000 Employees and Customers

Cosmetics giant Estée Lauder has disclosed a data breach that occurred in August 2025, when hackers exploited a flaw in Oracle E-Business Suite, a software system used by the company for human resources management. The breach exposed sensitive information of certain individuals, including full names, postal addresses, email addresses, dates of birth, social security numbers, passport numbers, financial account information, health information, and employment details.

Estée Lauder became aware of the issue on June 19, 2026, after conducting an investigation into a cybersecurity incident. The company’s notification to affected individuals reveals that hackers gained access to the Oracle E-Business Suite system on or around August 9, 2025, using a vulnerability in the BI Publisher Integration component. This allowed attackers to bypass authentication and remotely execute code, potentially giving them access to sensitive HR and business data.

The breach is linked to a mass-exploitation campaign targeting Oracle E-Business Suite through CVE-2025-61882, which was identified as a zero-day vulnerability by Google and Mandiant researchers in October 2025. The flaw affected EBS versions 12.2.3–12.2.14 and was exploited by the Clop ransomware gang to steal data from several high-profile organizations, including Harvard University, the University of Pennsylvania, and Logitech.

Estée Lauder’s breach is not an isolated incident; it has been compromised before, in 2023, when the Clop threat actor exploited another zero-day in the MOVEit Transfer platform. The company is now advising recipients of the breach notification letter to remain vigilant for signs of identity theft and fraud, offering 24 months of complimentary identity monitoring services through Kroll.

The Estée Lauder data breach serves as a reminder that even large and well-established companies can fall victim to cyber attacks. It highlights the importance of regularly updating software systems, conducting thorough security audits, and implementing robust cybersecurity measures to prevent such incidents. In light of this incident, it is essential for individuals and organizations alike to remain cautious and take proactive steps to protect their sensitive information.

To mitigate similar risks, organizations should prioritize regular security testing and vulnerability assessment. This can include breach and attack simulation tests to identify weaknesses in their systems and ensure that detection tools are effective. By taking a proactive approach to cybersecurity, companies can reduce the likelihood of data breaches and protect themselves against potential threats.


Source: Bleeping Computer — 2026-07-20