Estée Lauder reports data exposure linked to Oracle E-Business Suite intrusion

Estée Lauder is notifying affected individuals after an unauthorized party accessed an Oracle E-Business Suite environment used for human resources operations and obtained personal information.Accordi...

Estée Lauder is notifying affected individuals after an unauthorized party accessed an Oracle E-Business Suite environment used for human resources operations and obtained personal information.

According to the company’s breach notice, Estée Lauder identified a cybersecurity issue in June 2026. Its investigation determined that an attacker had entered the system on or around August 9, 2025. The company has not publicly identified the attackers or confirmed the specific vulnerability used.

Information potentially exposed

The data involved varies by individual and may include names, mailing and email addresses, dates of birth, Social Security numbers, passport details, bank account information, health data, and employment records such as payroll and performance reports.

Estée Lauder is advising recipients to watch for suspicious communications and possible signs of identity theft or fraud. The company is also offering 24 months of complimentary identity-monitoring services through Kroll.

Possible connection to Oracle flaw

The timing of the incident overlaps with a large-scale campaign targeting Oracle E-Business Suite. Security researchers linked that activity to CVE-2025-61882, a vulnerability in the suite’s BI Publisher Integration component. The flaw affected versions 12.2.3 through 12.2.14 and could allow an unauthenticated attacker to bypass security controls and execute code remotely.

Oracle issued a fix for the vulnerability on October 4, 2025. Researchers and CrowdStrike later reported that the Clop extortion group had exploited the flaw as a zero-day beginning in early August. However, Estée Lauder’s notice does not establish that CVE-2025-61882 was responsible for this particular compromise.

Other organizations publicly associated with the Oracle campaign include several universities, The Washington Post, Logitech, GlobalLogic, Cox Enterprises, and Envoy Air.

The cosmetics company, which is headquartered in New York and operates globally, also disclosed a separate Clop-related incident in 2023 involving the MOVEit Transfer file-transfer platform. That earlier attack affected multiple organizations using the vulnerable service.