Timeline of the Incident
Estée Lauder disclosed a breach affecting customer and employee data on June 12, 2026, though the attack occurred back in August 2025. Hackers exploited an unauthenticated RCE vulnerability in Oracle E-Business Suite (CVE-2025-3271) – a classic supply chain attack that exposed PII for 3.2 million records.
The frustrating detail? A patch for this vulnerability had been available for four months prior to the attack. As noted in our coverage, the company was running customized Oracle EBS modules without timely updates. Oracle EBS isn't unique – SAP, IBM Maximo, and older ServiceNow versions face similar risks due to:Oracle EBS Security Checklist
The Legacy System Problem in 2026