Cosmetics giant Estée Lauder has disclosed a data breach after attackers gained unauthorized access to the company’s Oracle E-Business Suite environment, exposing sensitive personal information belonging to current and former employees. The incident is part of a broader campaign that targeted organizations running vulnerable Oracle E-Business Suite servers during 2025.

 

 

According to breach notification letters, Estée Lauder became aware of the security issue while investigating vulnerabilities affecting Oracle E-Business Suite, the platform the company uses for human resources management. The investigation concluded that an unauthorized third party accessed the system on or around August 9, 2025, and obtained personal information stored within the HR environment. The company confirmed the scope of the compromise on June 19, 2026, before notifying affected individuals.

The compromised information varies by individual but may include names, home addresses, email addresses, dates of birth, Social Security numbers, passport numbers, financial account information, health-related data, and employment records such as payroll and performance evaluations. Estée Lauder has not disclosed how many people were affected by the breach.

Although the company has not publicly identified the vulnerability exploited in the attack, the timeline closely matches the large-scale exploitation of Oracle E-Business Suite flaw CVE-2025-61882. Security researchers previously linked that campaign to the Clop ransomware group, which exploited vulnerable Oracle EBS servers to steal data from dozens of organizations before issuing extortion demands. Oracle released a patch addressing the zero-day vulnerability in October 2025 after attackers had already begun exploiting affected systems.

Estée Lauder said it has engaged external cybersecurity experts to assist with the investigation, reported the incident to law enforcement, and implemented additional security measures to protect its systems. The company is also providing affected individuals with 24 months of complimentary identity monitoring and fraud protection services through Kroll. It encouraged recipients of the notification to review financial accounts, monitor credit reports, and remain alert for signs of identity theft.

The breach is not the first cybersecurity incident involving Estée Lauder. In 2023, the company disclosed a separate cyberattack that disrupted parts of its business operations after attackers gained unauthorized access to internal systems. That incident occurred during the widespread MOVEit Transfer attacks, although another ransomware group also claimed responsibility for a separate intrusion into the company’s network.

Leave a Reply