Skip to main content
Emerging ThreatsData Breaches

Estée Lauder Breach Exposes Sensitive Data via Oracle Flaw

Blurred computer terminal in a corporate office setting with office furniture.

“We became aware of a cybersecurity issue involving a vulnerability in the Oracle E-Business Suite system which is used by the Estee Lauder Companies for HR management purposes,” the company wrote in its notification.

Estée Lauder confirms HR-system intrusion tied to August 9, 2025

Estée Lauder Companies, the New York–based cosmetics firm with $14.3 billion in annual revenue and about 57,000 employees, disclosed that an unauthorized third party gained access to an Oracle E-Business Suite system used for human-resources operations. The company says it determined on June 19, 2026, that the intrusion occurred on or around August 9, 2025 and resulted in the threat actor obtaining "personal information of certain individuals."

Data types exposed

The sample disclosure letter Estée Lauder provided lists a broad set of personal and employment records that were exposed. According to that letter, the compromised information includes:

  • Full names
  • Postal addresses
  • Email addresses
  • Dates of birth
  • Social Security numbers (SSNs)
  • Passport numbers
  • Financial account information, including bank account numbers
  • Health information
  • Employment information, including payroll and performance reports

CVE-2025-61882, Clop, and a broader campaign affecting universities and companies

Although Estée Lauder’s notice does not explicitly name the exploited vulnerability, the August 9, 2025 date correlates with a mass-exploitation campaign that targeted Oracle E-Business Suite and has been tied to CVE-2025-61882. According to the record in the public reporting cited by Estée Lauder, researchers at Google and Mandiant warned in October 2025 about Clop ransomware gang breaches that exploited the flaw as a zero-day to steal data.

The flaw affected EBS versions 12.2.3–12.2.14 and allowed attackers to bypass authentication and remotely execute code through the BI Publisher Integration component, potentially giving them access to sensitive HR and business data. Oracle released fixes for CVE-2025-61882 on October 4, 2025, and security firm CrowdStrike confirmed that Clop had been exploiting the flaw since early August, 2025.

The same campaign named by researchers included high-profile victims across academia and industry: Harvard, the University of Pennsylvania, Dartmouth, the University of Phoenix, The Washington Post, Logitech, GlobalLogic, Cox Enterprises, and the American Airlines subsidiary Envoy Air.

Remediation offered and a prior compromise

In its notification, Estée Lauder advised recipients to remain vigilant for signs of identity theft and fraud and is offering 24 months of complimentary identity monitoring services through Kroll. The company also acknowledged a prior incident: in 2023, Clop exploited a zero-day in the MOVEit Transfer platform used by one of Estée Lauder’s internal tools, compromising the firm then as well.

What this means for technologists, affected employees, and procurement leaders

  • Technologists and security teams: The incident underscores the risks associated with enterprise applications tied to HR processes. Teams will be watching for indicators of compromise tied to CVE-2025-61882 and for attempts to exploit BI Publisher Integration in EBS versions 12.2.3–12.2.14, and will need to verify patching where Oracle released updates on October 4, 2025.
  • Affected employees and individuals named in notifications: People receiving Estée Lauder’s letters should monitor for signs of identity theft and fraud and consider the offered 24 months of identity monitoring through Kroll while keeping close watch on financial accounts and communications.
  • Procurement and IT decision-makers: The recurrence—Estée Lauder was compromised in 2023 via MOVEit and again in 2025 via EBS-related activity—will prompt buyers to scrutinize vendor patch timelines and the security posture of third-party enterprise software, especially components that handle sensitive HR and payroll data.

Estée Lauder’s disclosure places the company among a list of organizations hit during the CVE-2025-61882 exploitation window and ties the intrusion to a known zero-day exploitation campaign. The company’s offer of identity monitoring and its public timeline (intrusion around August 9, 2025; determination on June 19, 2026) are concrete steps; unanswered in the disclosure are the full scope of affected individuals and any regulatory or legal follow-on. Observers will be tracking whether other organizations that used the same Oracle E-Business Suite versions report similar discoveries tied to the October 2025 advisories and the Clop activity.

Source: BleepingComputer — Estée Lauder discloses data breach via Oracle E-Business flaw