VYPR
breachPublished Jul 20, 2026· Updated Jul 21, 2026· 2 sources

Estée Lauder Suffers Data Breach Via Exploited Oracle E-Business Suite Vulnerability

Cosmetics giant Estée Lauder has disclosed a data breach impacting customer personal information, stemming from the exploitation of a vulnerability in Oracle E-Business Suite.

Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite, a system the company utilized for its human resources (HR) operations. The intrusion, identified by the company last month, occurred on August 9, 2025, leading to the unauthorized acquisition of sensitive personal information belonging to certain individuals.

In a notification to affected parties, Estée Lauder stated, “We became aware of a cybersecurity issue involving a vulnerability in the Oracle E-Business Suite system which is used by the Estee Lauder Companies for HR management purposes.” The company further elaborated that through its investigation on June 19, 2026, it determined that an unauthorized third party had gained access to the system around August 9, 2025, and obtained personal data.

The exposed data, as detailed in a sample disclosure letter, is extensive and includes full names, postal addresses, email addresses, dates of birth, Social Security numbers (SSNs), passport numbers, financial account information (including bank account numbers), health information, and employment details such as payroll and performance reports. This breach affects a significant portion of the personal data typically handled by HR systems.

While Estée Lauder's notice does not explicitly name the exploited vulnerability, the timing of the breach strongly correlates with the mass-exploitation campaign targeting Oracle E-Business Suite through CVE-2025-61882. This specific flaw was highlighted in October 2025 by researchers from Google and Mandiant, who warned of data theft by the Clop ransomware gang exploiting it as a zero-day.

The vulnerability, CVE-2025-61882, affected Oracle EBS versions 12.2.3 through 12.2.14. It allowed attackers to bypass authentication mechanisms and execute remote code through the BI Publisher Integration component. This capability provided a direct pathway to sensitive HR and business data stored within the affected systems. Oracle released patches for this vulnerability on October 4, 2025, shortly after which cybersecurity firm CrowdStrike confirmed Clop's active exploitation since early August 2025.

Estée Lauder joins a list of prominent organizations that have fallen victim to attacks exploiting CVE-2025-61882. Previous victims of this campaign include academic institutions like Harvard, the University of Pennsylvania, and Dartmouth, as well as The Washington Post, Logitech, GlobalLogic, Cox Enterprises, and the American Airlines subsidiary Envoy Air. The widespread impact underscores the critical nature of this vulnerability.

In response to the breach, Estée Lauder is advising affected individuals to remain vigilant for any signs of identity theft or fraud. To assist those impacted, the company is offering 24 months of complimentary identity monitoring services through Kroll. This incident also marks a recurrence for Estée Lauder, which was previously compromised by the Clop ransomware group in 2023 due to a zero-day exploit in the MOVEit Transfer platform.

The breach highlights the persistent risks associated with legacy HR systems and the sophisticated tactics employed by threat actors like the Clop ransomware gang. Organizations relying on such systems must prioritize timely patching and robust security measures to protect sensitive employee and customer data from exploitation.

This new report provides further details on the Estée Lauder data breach, confirming the incident occurred around August 9, 2025, and involved the theft of extensive personal information including Social Security numbers, passport numbers, and bank account details. It also explicitly links the breach to the mass-exploitation campaign targeting Oracle E-Business Suite via CVE-2025-61882, which was previously exploited by the Cl0p gang in August 2025.

Synthesized by Vypr AI