• 2 min read
Estée Lauder discloses Oracle data breach
Estée Lauder says hackers accessed HR data through Oracle E-Business Suite, exposing sensitive personal, financial, health, and employment information.

Image: BleepingComputer
Estée Lauder is notifying customers that hackers accessed its Oracle E-Business Suite system, which the cosmetics company uses for human resources operations. The company said it identified the intrusion last month and determined on June 19, 2026, that unauthorized access had occurred on or around August 9, 2025.
“We became aware of a cybersecurity issue involving a vulnerability in the Oracle E-Business Suite system which is used by the Estee Lauder Companies for HR management purposes.”
A sample disclosure letter says the stolen information may include:
- Full names, postal addresses, email addresses, and dates of birth
- Social Security numbers and passport numbers
- Financial account information, including bank account numbers
- Health and employment information, including payroll and performance reports
Estée Lauder, based in New York, reported $14.3 billion in annual revenue. It employs 57,000 people and operates online and physical stores globally.

Recommended reading
Ostium loses $23.75 million in price-feed attack
Oracle flaw linked to mass exploitation
The company did not identify the vulnerability in its notice, but the breach date overlaps with a mass-exploitation campaign targeting Oracle E-Business Suite through CVE-2025-61882. Google and Mandiant researchers said in October 2025 that the Clop ransomware group had exploited the flaw as a zero-day to steal data.
The vulnerability affected EBS versions 12.2.3 through 12.2.14. It allowed attackers to bypass authentication and remotely execute code through the BI Publisher Integration component, potentially exposing sensitive HR and business data. Oracle released patches on October 4, 2025, while CrowdStrike later said Clop had been exploiting the flaw since early August 2025.
Other reported victims included Harvard, the University of Pennsylvania, Dartmouth, the University of Phoenix, The Washington Post, Logitech, GlobalLogic, Cox Enterprises, and Envoy Air, an American Airlines subsidiary.
Estée Lauder is urging recipients to watch for identity theft and fraud. It is also offering 24 months of complimentary identity monitoring through Kroll. The company was previously compromised by Clop in 2023 through a zero-day in MOVEit Transfer, an internal software tool.
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via BleepingComputer


