Skip to main content
See every side of every news story
Published loading...Updated

Estée Lauder Discloses Data Breach via Oracle E-Business Flaw

The company is offering two years of identity monitoring after attackers stole names, Social Security numbers, passport numbers and bank details from HR records.

  • On June 19, 2026, Lauder confirmed an unauthorized party accessed its Oracle E-Business Suite system on or around 9 August 2025, compromising personal information including Social Security numbers and employment data.
  • CVE-2025-61882, a critical 9.8/10 Oracle EBS RCE flaw, enabled the breach; attackers exploited this vulnerability as a zero-day starting August 2025, before Oracle issued an emergency patch on October 4, 2025.
  • Stolen records include financial account details, health information, and passport numbers. Lauder joins more than 100 organizations, including Harvard, the University of Pennsylvania, and The Washington Post, hit by the same campaign.
  • Affected staff received notification letters on July 17 regarding the incident. Lauder is offering two years of free identity monitoring through Kroll to assist those impacted by the long-delayed disclosure.
  • Clop previously targeted Lauder in 2023 via MOVEit. This incident underscores risks of delayed disclosure, as attackers held almost a year of access to extensive personal, financial, health, and employment records.
Insights by Ground AI

12 Articles

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 75% of the sources are Center
75% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

cybernoz.com broke the news on Monday, July 20, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal