Estée Lauder hit by Oracle E-Business data breach
Latest
Hackers stole Estée Lauder staff’s bank and health data. The company took nearly a year to say so.
Estée Lauder has told employees that hackers took their most sensitive records, from social-security numbers to bank details to health data. The break-in happened in August 2025. The company only worked that out this June. It is the latest name on a very long list.
July 22, 2026 – 12:26 pm
Image by: Estée Lauder Companies Inc
The cosmetics giant Estée Lauder is notifying staff of a data breach after hackers slipped into the Oracle software it uses to run human resources. BleepingComputer first reported the disclosure.
Timeline: Nearly a Year in the Dark
The timeline is the uncomfortable part. According to the company’s notification letter, an intruder reached its Oracle E-Business Suite system on or around 9 August 2025. Estée Lauder says it only confirmed the theft on 19 June 2026. The letters went out on 17 July. That is close to a year of exposure.
The Stolen Data
The haul is broad. The stolen records include full names, postal and email addresses, dates of birth, social-security numbers, passport numbers, bank account details, health information, and employment data such as payroll and performance reviews. The company is offering affected staff two years of free identity monitoring through Kroll.
A Known Flaw
Estée Lauder does not name the bug in its letter. The dates, though, line up with a mass-exploitation campaign against Oracle E-Business Suite through a flaw known as CVE-2025-61882.
That flaw is serious. It is a critical, pre-authentication vulnerability that lets an attacker run code on the system with no username or password. Oracle patched it on 4 October 2025. By then, the Clop ransomware gang had already been exploiting it as a zero-day since early August, according to security researchers.
A Familiar Pattern
The case shows a soft spot the industry keeps hitting: trusted third-party business software. Attackers do not need to break down the front door if they can walk through a vendor’s. One unpatched flaw in a shared platform turns into dozens of data breaches at once.
Past Breaches
Estée Lauder has been here before. Clop also hit the company in 2023, that time through a zero-day in the MOVEit file-transfer tool. The bigger worry is the gap. A breach in August that surfaces the following summer gives criminals a long, quiet head start, and gives victims almost no warning before their data is already in play.
As TechRadar noted, a warning this late is of limited help. It is also a preview of how these extortion campaigns will keep playing out.
By
Ana Maria Constantin
With expertise in digital marketing, product management, and branding & identity, Ana Maria Constantin develops strategies that resonate.