Cosmetics leader Estée Lauder has informed its customers about a data breach stemming from an exploited vulnerability in the Oracle E-Business Suite, utilized for its human resources operations.
In a recent announcement, Estée Lauder revealed that it detected an intrusion occurring on August 9, 2025, enabling threat actors to access the “personal information of certain individuals.”
The official notice stated, “We have become aware of a cybersecurity issue related to a vulnerability in the Oracle E-Business Suite system used by The Estée Lauder Companies for human resources management.”
“On June 19, 2026, we discovered that on or about August 9, 2025, an unauthorized third party accessed Oracle E-Business Suite systems and obtained personal information of specific individuals,” the company reported.
As detailed in a disclosure letter, the compromised data includes:
- Full name
- Post code
- Email address
- Date of birth
- Social Security Number (SSN)
- Passport number
- Financial account information, including bank account number
- Health information
- Employment details such as payroll calculations and performance reports
Based in New York, Estée Lauder boasts annual sales of $14.3 billion and ranks as the second-largest cosmetics company globally, employing 57,000 individuals and operating both online and offline stores worldwide.
While Estée Lauder’s notification did not specify the vulnerability exploited during the breach, the timing aligns with a significant exploitation campaign targeting the Oracle E-Business Suite via CVE-2025-61882.
In October 2025, cybersecurity experts from Google and Mandiant alerted the public about a breach by the Clop ransomware group, which leveraged the flaw as a zero-day exploit to steal sensitive data.
This vulnerability affected EBS versions 12.2.3 through 12.2.14, granting attackers the ability to bypass authentication and execute code remotely via the BI Publisher integration component, potentially exposing sensitive human resources and business data.
Oracle addressed the CVE-2025-61882 flaw with a fix released on October 4, 2025. Shortly after, cybersecurity firm CrowdStrike confirmed Clop had been exploiting this vulnerability since early August 2025.
Other prominent victims of the same campaign include Harvard University, Dartmouth College, the University of Pennsylvania, the University of Phoenix, the Washington Post, Logitech, GlobalLogic, Cox Enterprises, and Envoy Air, a subsidiary of American Airlines.
Estée Lauder urges recipients of the breach notification letters to remain vigilant for signs of identity theft or fraud. The company offers 24 months of free ID monitoring services through Kroll to affected individuals.
In a previous incident, Estée Lauder was also compromised by Clop in 2023, which exploited another zero-day vulnerability in the MOVEit Transfer platform, one of the company’s internal software tools.
Security teams have documented that only 54% of successful attacks are noted, while warnings are issued on just 14%. The remainder operates undetected within the network.
Picus’ whitepaper provides insights on testing your SIEM and EDR rules in breach and attack simulations to ensure that potential threats are recognized.
Source: www.bleepingcomputer.com




