Estée Lauder Discloses Data Breach via Oracle E-Business Flaw
The company is offering two years of identity monitoring after attackers stole names, Social Security numbers, passport numbers and bank details from HR records.
- On June 19, 2026, Lauder confirmed an unauthorized party accessed its Oracle E-Business Suite system on or around 9 August 2025, compromising personal information including Social Security numbers and employment data.
- CVE-2025-61882, a critical 9.8/10 Oracle EBS RCE flaw, enabled the breach; attackers exploited this vulnerability as a zero-day starting August 2025, before Oracle issued an emergency patch on October 4, 2025.
- Stolen records include financial account details, health information, and passport numbers. Lauder joins more than 100 organizations, including Harvard, the University of Pennsylvania, and The Washington Post, hit by the same campaign.
- Affected staff received notification letters on July 17 regarding the incident. Lauder is offering two years of free identity monitoring through Kroll to assist those impacted by the long-delayed disclosure.
- Clop previously targeted Lauder in 2023 via MOVEit. This incident underscores risks of delayed disclosure, as attackers held almost a year of access to extensive personal, financial, health, and employment records.
12 Articles
12 Articles
Estée Lauder hit by Oracle E-Business data breach
The cosmetics giant Estée Lauder is notifying staff of a data breach after hackers slipped into the Oracle software it uses to run human resources. BleepingComputer first reported the disclosure. Nearly a year in the dark The timeline is the uncomfortable part. According to the company’s notification letter, an intruder reached its Oracle E-Business Suite […] This story continues at The Next Web
Estée Lauder says it was hit by data breach caused by Oracle E-Business issue
Estée Lauder confirms Oracle E‑Business Suite breach from August 2025, only disclosed in June 2026Attackers stole extensive personal, financial, health, and employment data from HR management platformBreach tied to CVE‑2025‑61882, a critical Oracle EBS RCE flaw exploited across 100+ organizationsIf you remember the Oracle E-Business Suite vulnerability that was exploited around October 2025 in numerous attacks, you can now add Estée Lauder to th…
Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack
Hackers exfiltrated personal, financial, and health information from the company’s Oracle EBS instance in August 2025. The post Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack appeared first on SecurityWeek.
Estée Lauder Data Breach Linked To Oracle EBS Flaw
The Estée Lauder data breach has prompted the global cosmetics company to notify affected individuals after hackers exploited a vulnerability in Oracle E-Business Suite, a platform used for human resources (HR) operations. The Estée Lauder cyberattack stemmed from unauthorized access that occurred on or around August 9, 2025, though the company said it identified the incident last month and confirmed the scope of the breach on June 19, 2026. …
Coverage Details
Bias Distribution
- 75% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium










