
Cosmetics giant Estée Lauder confirmed a breach of customer and employee personal data through an exploited vulnerability in Oracle E-Business Suite (EBS). Attackers accessed HR systems on August 9, 2025 via CVE-2025-61882—a flaw previously weaponized by the Clop ransomware group—but the intrusion wasn't detected until June 19, 2026.
At a glance: Key facts
- Breach discovered June 19, 2026 after a 10-month undetected compromise
- CVE-2025-61882 in Oracle EBS allowed authentication bypass and remote code execution
- Victims offered 24 months of free identity monitoring via Kroll
- Second major breach for Estée Lauder after 2023's MOVEit incident
- Oracle released a patch for the vulnerability on October 4, 2025
What data was compromised
While Estée Lauder hasn't disclosed full details, the HR system breach likely exposed:
- Employee names and contact information
- Personal identifiers
- Potentially financial records
Cybersecurity experts note HR systems typically contain sensitive data including Social Security numbers, payroll banking details, health insurance information, and other confidential records—creating long-term risks for identity theft and financial fraud.
Technical breakdown of the Oracle EBS flaw
The attack leveraged CVE-2025-61882 in Oracle E-Business Suite versions 12.2.3–12.2.14. A BI Publisher Integration component vulnerability enabled:
- Authentication bypass
- Remote code execution
- Unauthorized access to business-critical data
Clop actively exploited this as a zero-day from August until Oracle's October patch. Traffic analysis revealed specially crafted HTTP requests targeting BI Publisher to gain system access.
Other known victims
Additional organizations compromised through CVE-2025-61882 include:
- Harvard University
- University of Pennsylvania
- Logitech
- The Washington Post
- American Airlines' subsidiary Envoy Air
Mandiant researchers estimate over 900 vulnerable Oracle EBS instances existed during the attack window. Educational institutions faced disproportionate impact as their HR systems often contain both employee and student data.
Protection steps for affected individuals
Estée Lauder recommends:
- Enable multi-factor authentication on critical accounts
- Monitor banking transactions for suspicious activity
- Enroll in the offered Kroll identity monitoring
- Remain vigilant against phishing using stolen data
Additional precautions:
- Regularly rotate passwords, especially financial logins
- Set up credit report activity alerts
- Minimize personal data shared on social media
Questions & answers
What specific data was stolen from Estée Lauder?
The company hasn't released a comprehensive list, but HR system access likely exposed employee names, addresses, phone numbers, email addresses, Social Security numbers, and banking details used for payroll.
How can I check if my data was compromised?
Estée Lauder is notifying affected individuals directly. You can also check your email on breach notification services like Have I Been Pwned which track major data leaks.
Which Oracle E-Business Suite versions were vulnerable?
Versions 12.2.3 through 12.2.14 required immediate patching after Oracle's October 4, 2025 security update. Organizations using these releases should conduct thorough system audits.
Is Estée Lauder providing compensation?
The company offers 24 months of complimentary Kroll identity monitoring including credit report surveillance, fraud alerts, and identity restoration services if needed.
What are the long-term risks?
Stolen personal data remains valuable for years, potentially enabling phishing schemes, document forgery, or unauthorized loans. Victims should maintain vigilance with credit monitoring and fraud alerts.
How else can I protect myself post-breach?
Consider freezing credit reports with major bureaus to prevent unauthorized account openings. Proactively monitor all financial statements and enable transaction alerts where available.