Estée Lauder says data breach exposed personal information after Oracle flaw

by

Estée Lauder said it is notifying customers after hackers exploited a flaw in Oracle E-Business Suite used for human resources operations, and a breach found in June exposed personal information of certain individuals after access on or around August 9, 2025.

KEY FACTS

  • Incident Unauthorized access to Oracle E-Business Suite used for HR management.
  • Discovery The company identified the intrusion on June 19, 2026.
  • Data exposed Names, addresses, email addresses, birth dates, SSNs, passport numbers, financial account data, health information and employment records.
  • Help offered 24 months of identity monitoring through Kroll.

The notification says an unauthorized third party gained access to the system on or around August 9, 2025 and obtained personal information. The company did not say how many people were affected.

The disclosure matches a wider campaign tied to CVE-2025-61882, a flaw in Oracle E-Business Suite that affected versions 12.2.3 through 12.2.14 and allowed attackers to bypass authentication and run code remotely through the BI Publisher Integration component. Oracle patched the issue on October 4, 2025.

Google and Mandiant previously warned of breaches linked to the flaw, and CrowdStrike said the Clop group had been exploiting it since early August 2025. Other reported victims include several universities, media companies and technology firms.

The company told recipients to watch for identity theft and fraud. It also said it is offering monitoring services, but it did not identify the specific vulnerability in its notice.

WHY IT MATTERS

The breach may expose sensitive personal and employment records that can be used for identity theft or fraud. The case also shows how flaws in widely used enterprise software can affect companies and institutions beyond the original target.