The Estée Lauder data breach exposed personal information after attackers accessed an Oracle E-Business Suite system that supports the company’s HR operations.

Estée Lauder discovered the incident last month. Its investigation found that an unauthorised party entered the system on or around 9 August 2025 and took personal data belonging to certain individuals.

The company did not name the vulnerability that enabled the attack. However, the breach date overlaps with a wider campaign that targeted Oracle E-Business Suite through a critical zero-day flaw.

Attackers Took Personal and Employment Data

A sample of Estée Lauder’s notification letter lists several types of data that the attackers may have accessed:

  • Full names
  • Postal and email addresses
  • Dates of birth
  • Social Security numbers
  • Passport numbers
  • Bank account details
  • Health information
  • Employment data, including payroll and performance reports

Estée Lauder used the affected Oracle E-Business Suite environment for HR management.

The New York-based cosmetics company employs around 57,000 people and sells products through online and physical stores worldwide.

Oracle Zero-Day Campaign May Explain the Breach

The Estée Lauder data breach occurred during a mass exploitation campaign involving CVE-2025-61882, a critical Oracle E-Business Suite vulnerability.

The flaw affected E-Business Suite versions 12.2.3 to 12.2.14. Attackers could bypass authentication and run code remotely through the BI Publisher Integration component.

This access could expose sensitive HR and business information.

Oracle released fixes for CVE-2025-61882 on 4 October 2025. Security researchers later reported that the Clop ransomware group had exploited the vulnerability from early August 2025, before Oracle issued patches.

The same campaign reportedly affected several other organisations, including Harvard, the University of Pennsylvania, Dartmouth, The Washington Post, Logitech, GlobalLogic, Cox Enterprises, and Envoy Air.

Estée Lauder has not identified the group behind its breach. Still, the timing strongly suggests a connection to the Oracle E-Business Suite campaign.

Estée Lauder Offers Identity Monitoring

Estée Lauder advises notification recipients to watch for fraud and identity theft.

The company also offers 24 months of free identity monitoring through Kroll.

Clop also hit Estée Lauder in 2023 when the group exploited a separate MOVEit Transfer zero-day.


0 responses to “Estée Lauder Data Breach Linked to Oracle E-Business Flaw”