Estée Lauder affected by Oracle E-Business data breach.
The cosmetics giant Estée Lauder is informing its employees of a data breach after hackers accessed the Oracle software used for its human resources operations. The initial report came from BleepingComputer.
A year of uncertainty
The timing is particularly concerning. According to the notification sent by the company, an attacker infiltrated its Oracle E-Business Suite system on or around August 9, 2025. Estée Lauder only confirmed the breach on June 19, 2026, with notifications sent out on July 17. This indicates nearly a year of exposure.
A broad range of data compromised
The stolen information is extensive. It includes full names, mailing and email addresses, birth dates, Social Security numbers, passport information, bank account details, health records, and employment data such as payroll and performance reviews. The company is offering impacted employees two years of complimentary identity monitoring through Kroll.
One vulnerability, numerous victims
Estée Lauder does not specify the vulnerability in its communication. However, the timeline corresponds with a widespread exploitation campaign targeting Oracle E-Business Suite through a vulnerability identified as CVE-2025-61882.
This vulnerability is critical. It is a pre-authentication flaw that enables an attacker to execute code on the system without needing a username or password. Oracle issued a patch on October 4, 2025, but by that time, the Clop ransomware group had already been exploiting it as a zero-day since early August, according to cybersecurity experts.
Estée Lauder is not alone in this predicament. More than 100 organizations fell victim to the same exploit, including notable entities like Harvard, the University of Pennsylvania, The Washington Post, Logitech, and Cox Enterprises.
A recurring issue
This incident highlights a persistent vulnerability within the industry: reliance on trusted third-party business software. Attackers can bypass direct defenses if they exploit a vendor's weaknesses. A single unpatched flaw in a shared platform can result in multiple simultaneous data breaches.
Estée Lauder has faced similar situations previously. In 2023, the company was attacked by Clop via a zero-day vulnerability in the MOVEit file-transfer tool. The more significant concern is the delay in detection. A breach occurring in August and only becoming known the following summer provides criminals with a significant head start, while victims receive minimal warning before their data is misused.
As noted by TechRadar, a notification received this late is of limited effectiveness, serving as a forewarning of how these extortion schemes may continue to unfold.
Other articles
Estée Lauder affected by Oracle E-Business data breach.
Estée Lauder reported that hackers took employees' Social Security numbers, banking, and health information through a vulnerability in Oracle E-Business in 2025, revealing the breach almost a year later.
