Cosmetics large Estée Lauder has notified prospects of an information breach after hackers exploited a flaw within the Oracle E-Enterprise Suite, which the corporate makes use of for human sources (HR) operations.
Final month, the corporate introduced that it had recognized an intrusion that occurred on August 9, 2025, which allowed menace actors to acquire “private data of sure people.”
“We’ve change into conscious of a cybersecurity subject concerning a vulnerability within the Oracle E-Enterprise Suite system utilized by The Estée Lauder Firms for human sources administration functions,” the discover states.
“On June 19, 2026, we decided by way of investigation that on or about August 9, 2025, an unauthorized third celebration gained entry to Oracle E-Enterprise Suite programs and obtained private data of sure people.”
In line with the pattern disclosure letter, the info uncovered contains:
- full title
- submit code
- electronic mail handle
- date of start
- Social Safety Quantity (SSN)
- passport quantity
- Monetary account data, together with checking account quantity
- well being data
- Employment data similar to payroll calculations and efficiency experiences
Estée Lauder is a New York-based cosmetics large with annual gross sales of $14.3 billion. The corporate is the second largest cosmetics firm on the earth, with 57,000 workers and working on-line and bodily shops worldwide.
Though Estée Lauder’s notification doesn’t disclose the vulnerability exploited within the breach, the date of the breach correlates with a large-scale exploitation marketing campaign concentrating on Oracle E-Enterprise Suite by way of CVE-2025-61882.
In October 2025, researchers from Google and Mandiant warned of a breach by the Clop ransomware group, which exploited the flaw as a zero-day to steal knowledge.
This flaw affected EBS variations 12.2.3 by way of 12.2.14 and will permit an attacker to bypass authentication and remotely execute code by way of the BI Writer integration element, doubtlessly getting access to delicate human sources and enterprise knowledge.
Oracle launched a repair for CVE-2025-61882 on October 4, 2025. Shortly after, cybersecurity agency CrowdStrike confirmed that Clop had been exploiting this flaw since early August 2025.
Different notable victims of the identical marketing campaign embody Harvard College, Dartmouth Faculty of the College of Pennsylvania, the College of Phoenix, the Washington Submit, Logitech, GlobalLogic, Cox Enterprises, and Envoy Air, a subsidiary of American Airways.
Estée Lauder advises recipients of breach notification letters to all the time be looking out for indicators of identification theft or fraud. The corporate additionally provides 24 months of free ID monitoring providers by way of Kroll.
Estée Lauder was additionally compromised by Crop in 2023, with the attacker exploiting one other zero-day within the MOVEit Switch platform, one of many firm’s inside software program instruments.

Safety groups doc 54% of profitable assaults and subject a warning on solely 14%. The remaining strikes invisibly by way of the atmosphere.
Picus’ whitepaper reveals find out how to take a look at your SIEM and EDR guidelines in breach and assault simulations to make sure threats go undetected.
Get the white paper
