The cosmetics company Estee Lauder has begun informing affected individuals of a data breach after an attacker exploited a vulnerability in the company's Oracle E-Business Suite environment, which is used for HR-related business processes.
According to the company, the incident was discovered last month. The subsequent investigation showed that an unauthorized actor likely accessed the system around August 9, 2025, and obtained personal data relating to a number of individuals.
In his information letter he writes: Estee Lauder that the company identified a cybersecurity issue linked to a vulnerability in Oracle E-Business Suite, the platform used for HR management within the group.
Furthermore, the company states that the internal investigation, which was completed on June 19, 2026, showed that an unauthorized third party had gained access to the system around August 9, 2025 and thereby obtained personal data.
Personal data may have been exposed
According to an example of the information letter sent to affected individuals, the following information may have been included in the data breach:
- Full name
- Postal address
- Email address
- Date of birth
- Social Security Number (SSN)
- Passport number
- Bank account details
- Health information
- Employment-related information, including salary and performance data
The data that is affected varies between different individuals.
The timeline points to a known Oracle vulnerability
Estée Lauder has not disclosed the vulnerability behind the breach, but the timing coincides with the large-scale wave of attacks that targeted Oracle E-Business Suite in 2025 via the security flaw. CVE-2025-61882.
In October 2025, security researchers from Google Mandiant reported that the Clop ransomware group exploited the vulnerability as a so-called zero-day vulnerability to steal data from a large number of organizations.
The vulnerability affected Oracle E-Business Suite versions 12.2.3 through 12.2.14 and allowed attackers to bypass authentication and in some cases execute code remotely via the BI Publisher Integration component. A successful attack could provide access to sensitive HR and business data.
Oracle published security updates for CVE-2025-61882 on October 4, 2025. Shortly thereafter, cybersecurity firm CrowdStrike confirmed that Clop had been exploiting the vulnerability since early August of that year.
Several large organizations were affected
The campaign linked to the Oracle vulnerability has previously affected several large organizations, including:
- Harvard University
- University of Pennsylvania
- Dartmouth
- University of Phoenix
- The Washington Post
- Logitech
- GlobalLogic
- Cox Enterprises
- Envoy Air, a subsidiary of American Airlines
However, there is no public confirmation that the same threat actor was behind the breach at Estée Lauder.
Offers identity monitoring
Estée Lauder is urging those affected to be on the lookout for signs of identity theft and financial fraud, and is offering 24 months of free identity monitoring through security firm Kroll.
Second time the company is linked to Clop
This is not the first time Estée Lauder has suffered a major cybersecurity incident.
In 2023, the company was also affected by the global wave of attacks against the file transfer platform MOVEit Transfer, where the ransomware group Clop exploited a critical zero-day vulnerability to steal data from hundreds of organizations worldwide.








