Estée Lauder affected by Oracle E-Business data breach.

      The cosmetics giant Estée Lauder is informing its employees of a data breach after hackers accessed the Oracle software used for its human resources operations. The initial report came from BleepingComputer.

      A year of uncertainty

      The timing is particularly concerning. According to the notification sent by the company, an attacker infiltrated its Oracle E-Business Suite system on or around August 9, 2025. Estée Lauder only confirmed the breach on June 19, 2026, with notifications sent out on July 17. This indicates nearly a year of exposure.

      A broad range of data compromised

      The stolen information is extensive. It includes full names, mailing and email addresses, birth dates, Social Security numbers, passport information, bank account details, health records, and employment data such as payroll and performance reviews. The company is offering impacted employees two years of complimentary identity monitoring through Kroll.

      One vulnerability, numerous victims

      Estée Lauder does not specify the vulnerability in its communication. However, the timeline corresponds with a widespread exploitation campaign targeting Oracle E-Business Suite through a vulnerability identified as CVE-2025-61882.

      This vulnerability is critical. It is a pre-authentication flaw that enables an attacker to execute code on the system without needing a username or password. Oracle issued a patch on October 4, 2025, but by that time, the Clop ransomware group had already been exploiting it as a zero-day since early August, according to cybersecurity experts.

      Estée Lauder is not alone in this predicament. More than 100 organizations fell victim to the same exploit, including notable entities like Harvard, the University of Pennsylvania, The Washington Post, Logitech, and Cox Enterprises.

      A recurring issue

      This incident highlights a persistent vulnerability within the industry: reliance on trusted third-party business software. Attackers can bypass direct defenses if they exploit a vendor's weaknesses. A single unpatched flaw in a shared platform can result in multiple simultaneous data breaches.

      Estée Lauder has faced similar situations previously. In 2023, the company was attacked by Clop via a zero-day vulnerability in the MOVEit file-transfer tool. The more significant concern is the delay in detection. A breach occurring in August and only becoming known the following summer provides criminals with a significant head start, while victims receive minimal warning before their data is misused.

      As noted by TechRadar, a notification received this late is of limited effectiveness, serving as a forewarning of how these extortion schemes may continue to unfold.

Other articles

Google and Ford are investing in trading as artificial intelligence takes over office roles. Google and Ford are investing in trading as artificial intelligence takes over office roles. Google, Ford, Carhartt, and BlackRock have formed a partnership aimed at filling 2.1 million skilled-trade positions by 2030, focusing on jobs that cannot be automated by AI. Light Flip: the $299 anti-AI flip phone that doesn't have a touchscreen. Light Flip: the $299 anti-AI flip phone that doesn't have a touchscreen. Light's inaugural flip phone removes the touchscreen, apps, social media, and AI features. Priced at $299, the Light Flip caters to those looking for a digital detox and is set to be released in 2027. Apple has resolved an issue with the Hide My Email feature that revealed users' actual email addresses. Apple has resolved an issue with the Hide My Email feature that revealed users' actual email addresses. A vulnerability in Hide My Email revealed actual addresses through returned spam messages for more than a year before Apple fixed it, just days after it became public knowledge. TSMC may implement a price increase that could directly affect your next phone, laptop, or tablet. TSMC may implement a price increase that could directly affect your next phone, laptop, or tablet. Reports indicate that TSMC intends to raise chip prices by as much as 10% in 2027, a move that could impact the prices of almost every device you purchase. SkyPilot secures $20 million to position itself as the neutral hub for AI computing. SkyPilot secures $20 million to position itself as the neutral hub for AI computing. Ion Stoica's team at Berkeley has secured $20 million for SkyPilot, a provider-agnostic control plane that consolidates dispersed AI computing resources from over 20 cloud platforms into a single entity. US computer science enrollment declines for the first time in two decades. US computer science enrollment declines for the first time in two decades. A Stanford study reveals that enrolment in computer science programs in the US has declined for the first time in 20 years, attributed to AI's capability to write code, although economists are not yet placing blame on AI.

Estée Lauder affected by Oracle E-Business data breach.

Estée Lauder reported that hackers took employees' Social Security numbers, banking, and health information through a vulnerability in Oracle E-Business in 2025, revealing the breach almost a year later.