The Estée Lauder data breach has prompted the global cosmetics company to notify affected individuals after hackers exploited a vulnerability in Oracle E-Business Suite, a platform used for human resources (HR) operations.
The Estée Lauder cyberattack stemmed from unauthorized access that occurred on or around August 9, 2025, though the company said it identified the incident last month and confirmed the scope of the breach on June 19, 2026.
Estée Lauder Data Breach Exposed Sensitive Personal Information
According to the company’s notification letter, the attackers gained access to the Oracle E-Business Suite system and obtained personal information belonging to certain individuals.
We became aware of a cybersecurity issue involving a vulnerability in the Oracle E-Business Suite system which is used by the Estee Lauder Companies for HR management purposes,” the notice states.
It further adds: “On June 19, 2026, we determined through our investigation that, on or around August 9, 2025, an unauthorized third party gained access to the Oracle E-Business Suite system and obtained personal information of certain individuals.”
The exposed data in the incident includes full names, postal addresses, email addresses, dates of birth, Social Security numbers (SSNs), passport numbers, financial account information, including bank account numbers, health information, and employment records such as payroll and performance reports.
Oracle Vulnerability Tied to Estée Lauder Cyberattack
Although Estée Lauder did not identify the specific vulnerability used in the attack, the timeline aligns with the widespread exploitation of the Oracle E-Business Suite flaw CVE-2025-61882.
In October 2025, researchers from Google warned that the Clop ransomware group had exploited the vulnerability as a zero-day to steal data. The flaw affected Oracle EBS versions 12.2.3 through 12.2.14, allowing attackers to bypass authentication and remotely execute code through the BI Publisher Integration component. Successful exploitation could provide access to sensitive HR and business information.
Oracle released security patches for CVE-2025-61882 on October 4, 2025. Soon after, cybersecurity company CrowdStrike confirmed that Clop had been exploiting the vulnerability since early August 2025.
Company Offers Identity Monitoring
Estée Lauder, headquartered in New York, generates annual revenue of $14.3 billion, employs around 57,000 people, and operates retail stores and online businesses worldwide, making it the world’s second-largest cosmetics company.
Following the Estée Lauder data breach, the company is urging recipients of its notification letter to monitor for signs of identity theft and fraud. It is also providing 24 months of complimentary identity monitoring services through Kroll.
The Estée Lauder cyberattack is part of a broader campaign that affected several high-profile organizations, including Harvard, the University of Pennsylvania, Dartmouth, the University of Phoenix, The Washington Post, Logitech, GlobalLogic, Cox Enterprises, and American Airlines subsidiary Envoy Air.
This is not the first time the company has been impacted by Clop. In 2023, Estée Lauder was also compromised after the ransomware group exploited a separate zero-day vulnerability in the MOVEit Transfer platform, one of the company’s internal software tools.






































