Estée Lauder Discloses Data Breach After Oracle E-Business Suite Exploited in Attack

Views: 66 views

401/69 Wednesday, July 22, 2026

Estée Lauder, a major cosmetics company, has disclosed a data breach after attackers exploited a vulnerability in Oracle E-Business Suite, which the company uses for Human Resources (HR) processes. Estée Lauder stated that on June 19, 2026, it determined that unauthorized access to its Oracle E-Business Suite system had occurred around August 9, 2025, and that some individuals’ personal information had been obtained. Estée Lauder is a cosmetics company headquartered in New York City and operates through both online and retail channels in multiple countries worldwide.

According to a sample data breach notification letter, the information that may have been exposed includes full names, mailing addresses, email addresses, dates of birth, Social Security numbers (SSNs), passport numbers, financial account information, including bank account numbers, health information, and employment information, such as payroll data and performance reports. Although Estée Lauder did not specify the vulnerability exploited in this attack, the timing of the incident aligns with an Oracle E-Business Suite attack campaign involving CVE-2025-61882, which Google and Mandiant previously disclosed as being linked to Clop ransomware attacks that exploited the flaw as a zero-day to steal data.

CVE-2025-61882 affects Oracle E-Business Suite versions 12.2.3 through 12.2.14 and could allow attackers to bypass authentication and execute code through BI Publisher Integration, potentially leading to access to sensitive HR and business data. Oracle released a patch for the vulnerability on October 4, 2025, and CrowdStrike later confirmed that the Clop group had been exploiting the flaw in attacks since early August 2025. Estée Lauder advised individuals who received notification letters to remain alert for signs of identity theft and fraud. The company is also offering 24 months of complimentary identity monitoring services through Kroll.

Source: https://www.bleepingcomputer.com/news/security/est-e-lauder-discloses-data-breach-via-oracle-e-business-flaw/