Estée Lauder Data Breach Linked to Oracle EBS Vulnerability
Estée Lauder reports a cybersecurity incident linked to a vulnerability in Oracle’s E-Business Suite, exposing sensitive employee data.
Incident Overview
A major cosmetics corporation revealed a security incident connected to a vulnerability within Oracle’s E-Business Suite platform, which was utilized for human resources management. The organization, recognized for its portfolio of high-end skincare, makeup, fragrance, and haircare products, disclosed that an unauthorized entity accessed its Oracle E-Business Suite system.
Timeline of the Breach
The intrusion was detected on June 19, 2026, with the unauthorized access traced to approximately August 9, 2025. The company identified the compromise through internal investigations.
Affected Data
The affected system housed sensitive employee data, including personal identifiers such as names, addresses, birth dates, Social Security numbers, passport details, banking information, health records, and employment-related documentation like performance reviews and payroll histories.
Response and Mitigation
Following the discovery, the company engaged external cybersecurity professionals, reported the incident to authorities, and implemented additional protective measures. To assist affected individuals, the organization is providing complimentary identity monitoring services via Kroll for a period of 24 months, concluding on October 31, 2026.
Security Measures
The notice emphasizes the importance of vigilance in detecting fraudulent activity, advising users to regularly review financial accounts, statements, and credit reports.
Vulnerability Details
The breach timeline corresponds with a widespread exploitation campaign targeting Oracle E-Business Suite vulnerabilities. Researchers from Google and Mandiant confirmed in October 2025 that the Cl0p extortion group leveraged multiple flaws, including the zero-day CVE-2025-61882, to exfiltrate data from multiple organizations in August 2025.
Patch Information
This particular vulnerability enabled unauthenticated attackers to execute code remotely over HTTP, impacting Oracle E-Business Suite versions 12.2.3 to 12.2.14. Oracle addressed the flaw with patches released on October 4, 2025.
According to researchers from Google and Mandiant, the Cl0p extortion group exploited the CVE-2025-61882 vulnerability to exfiltrate data from multiple organizations in August 2025.
Conclusion
Estée Lauder’s incident highlights the risks of unpatched vulnerabilities in enterprise systems. The company’s response, including identity monitoring services and collaboration with cybersecurity experts, underscores the importance of proactive measures in mitigating data breaches.
