Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations.
The company says that last month it identified an intrusion that had occurred on August 9, 2025, which led to the threat actor obtaining ” personal information of certain individuals.”
“We became aware of a cybersecurity issue involving a vulnerability in the Oracle E-Business Suite system which is used by the Estee Lauder Companies for HR management purposes,” the notification says.
“On June 19, 2026, we determined through our investigation that, on or around August 9, 2025, an unauthorized third party gained access to the Oracle E-Business Suite system and obtained personal information of certain individuals.”
According to a sample of the disclosure letter, the exposed data includes:
Estée Lauder is a New York-based cosmetics giant with an annual revenue of $14.3 billion. It is the second-largest cosmetics firm in the world, employing 57,000 people and operating online and physical shops globally.
Although the Estée Lauder notice does not disclose the vulnerability exploited in the intrusion, the date of the breach correlates with the mass-exploitation campaign targeting Oracle E-Business Suite through CVE-2025-61882.
In October 2025, Google and Mandiant researchers warned of breaches from the Clop ransomware gang exploiting the flaw as a zero-day to steal data.
The flaw affected EBS versions 12.2.3-12.2.14 and enabled attackers to bypass authentication and remotely execute code through the BI Publisher Integration component, potentially giving them access to sensitive HR and business data.
Oracle released fixes for CVE-2025-61882 on October 4, 2025. Shortly after, cybersecurity firm CrowdStrike confirmed that Clop had been exploiting the flaw since early August, 2025.
Other notable victims of the same campaign include Harvard, the University of Pennsylvania, Dartmouth, the University of Phoenix, The Washington Post, Logitech, GlobalLogic, Cox Enterprises, and the American Airlines subsidiary Envoy Air.
Estée Lauder is advising recipients of the breach notification letter to remain vigilant for signs of identity theft and fraud. The company is also offering 24 months of complimentary identity monitoring services through Kroll.
Estée Lauder was also compromised by Clop in 2023, when the threat actor exploited another zero-day in the MOVEit Transfer platform, one of the firm’s internal software tools.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Kubota says hackers had month-long access to network systems
Over 900 Oracle E-Business instances exposed to ongoing attacks
Hackers now exploit critical Oracle E-Business flaw in attacks
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
WordPress Core “wp2shell” RCE flaws get public exploits, patch now
Microsoft warns of surge in ACR Stealer attacks on customers
Do you have what it takes to challenge DARKROOM? Signup for an exclusive DEFCON CTF!
AI broke vulnerability management. Get the guide CISOs use to shift budget to BAS.
Privacy by policy or privacy by architecture? See how age checks work when the face never leaves the device.
Calculate what you’d save by replacing your MDR.
Pentest your web apps on-demand. Find what humans miss. Scope and launch a pentest in minutes.
See how Pixellot discovered and secured hundreds of unmanaged AI agent identities in weeks, not months. Read the case study.
Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure
Read our posting guidelinese to learn what content is prohibited.



