
Estée Lauder Confirms Data Breach After Oracle Hack
.webp)
Cosmetics giant Estée Lauder has confirmed a data breach that exposed sensitive personal information belonging to current and former employees. The Estée Lauder data breach stems from a vulnerability in Oracle E-Business Suite, software the company used for human resources management. Attackers gained access to the system in August 2025. The company only pieced together the full scope of the intrusion this summer.
The New York-based beauty giant is the second-largest cosmetics company in the world. It employs 57,000 people and generates $14.3 billion in annual revenue. That scale makes this data breach one of the more consequential entries in a wider wave of attacks tied to the same Oracle flaw.
What Happened in the Estée Lauder Data Breach
Estée Lauder detected the intrusion last month during an internal investigation. The actual compromise, however, dates back much further. According to the company's notification letter, an unauthorized third party accessed its Oracle E-Business Suite system around August 9, 2025.
The company did not confirm the exact vulnerability exploited. But the timing lines up closely with a mass-exploitation campaign that hit Oracle E-Business Suite customers worldwide last year. That campaign traced back to a single critical flaw. The Estée Lauder breach fits the same pattern seen across dozens of other victims.
Ten months passed between the initial intrusion and its discovery. That gap gave attackers a long window to extract data from HR systems before anyone noticed.
What Data Was Exposed
The scope of information exposed in the Estée Lauder data breach is broad. It includes some of the most sensitive categories a company can hold. Affected individuals had their full names, postal addresses, email addresses, and dates of birth exposed. Social Security numbers and passport numbers were also taken, alongside bank account details.
Health information was compromised too, along with employment records covering payroll and performance reports. This combination of financial, medical, and identity data creates significant fraud risk. Attackers holding this data can attempt identity theft or open fraudulent accounts. They can also file false tax returns using stolen Social Security numbers.
Estée Lauder is offering 24 months of complimentary identity monitoring through Kroll to individuals affected by the breach. The company is urging recipients of its notification letter to watch closely for signs offraud.
The Oracle E-Business Suite Vulnerability Behind the Breach
Estée Lauder has not named the specific flaw behind the breach. But the timeline points to CVE-2025-61882, a critical vulnerability in Oracle E-Business Suite exploited as a zero-day starting in early August 2025. The flaw affected EBS versions 12.2.3 through 12.2.14. It let attackers bypass authentication and execute code remotely through the platform's BI Publisher Integration component.
Security researchers linked the exploitation to the Clop ransomware gang. Clop used the flaw to steal data from dozens of organizations before Oracle released a patch on October 4, 2025. Other confirmed victims of the same campaign include Harvard, the University of Pennsylvania, Dartmouth, and the University of Phoenix. The Washington Post, Logitech, GlobalLogic, Cox Enterprises, and Envoy Air were also hit.
SafeState has previously covered this campaign's reach into other sectors, including a related breach at Mazda tied to the same Oracle E-Business Suite exploitation wave. The pattern is consistent. Attackers target HR and business systems running unpatched EBS instances, extract data quietly, then use it for extortion.
A Second Clop Breach in Three Years
This is not Estée Lauder's first encounter with the Clop ransomware gang. In 2023, the same group breached the company through a separate zero-day flaw in the MOVEit Transfer platform, one of its internal file-sharing tools.
Two breaches from the same threat actor within three years raise a fair question. How quickly can large enterprises close security gaps once a pattern of targeting becomes clear? Clop has built a reputation for exploiting file transfer and enterprise software flaws at scale. It often hits hundreds of organizations through a single vulnerability rather than pursuing individual targets one at a time.
What Affected Individuals Should Do
Anyone who receives a notification tied to the Estée Lauder data breach should treat it as a serious warning. The exposed data, especially Social Security and passport numbers, gives attackers enough material for long-term identity fraud, not just short-term scams.
Enrolling in the identity monitoring service Estée Lauder is offering is a reasonable first step. Beyond that, affected individuals should watch bank and credit card statements closely. They should also consider a fraud alert or credit freeze with major credit bureaus, and stay cautious of unsolicited emails referencing the breach.
The Estée Lauder data breach adds another major name to the growing list of organizations hit by Oracle E-Business Suite exploitation. As fallout from this campaign continues to surface, more disclosures tied to the same Oracle vulnerability are likely in the months ahead.
Subscribe to receive the latest blog posts to your inbox every week.