Estée Lauder Breach Tied to Oracle Flaw
A critical vulnerability in Oracle E-Business Suite led to the exposure of personal data at the global cosmetics firm.
Cosmetics giant Estée Lauder is currently notifying individuals following a data breach stemming from an intrusion into its human resources infrastructure. The company identified that an unauthorized party accessed sensitive files stored within its Oracle E-Business Suite system, a platform utilized by the firm for internal management operations.
Timeline of the Unauthorized Access
The company stated that the intrusion occurred on August 9, 2025, though it was not confirmed until a subsequent investigation concluded on June 19, 2026. The attackers leveraged a specific vulnerability in the Oracle software to bypass security controls, ultimately extracting personal records belonging to employees and other individuals connected to the organization.
We became aware of a cybersecurity issue involving a vulnerability in the Oracle E-Business Suite system which is used by the Estee Lauder Companies for HR management purposes.
— Estée Lauder, via its official breach notification letter
Scope of the Compromised Data
The unauthorized access resulted in the potential exposure of a wide range of sensitive personal and professional documentation. According to a sample of the disclosure letter, the data accessed by the third party included the following:
- Full names and postal addresses
- Email addresses and dates of birth
- Social Security numbers
- Passport numbers
- Financial account information, including bank account numbers
- Health and employment information, such as payroll and performance reports
Context of the Oracle Exploit
While the company did not initially name the specific vulnerability, the timing of the incident aligns with a broader campaign targeting organizations using Oracle E-Business Suite. The attacks involved CVE-2025-61882, a flaw that allowed attackers to execute code remotely and bypass authentication via the BI Publisher Integration component. Oracle released fixes for this vulnerability on October 4, 2025.
This incident is not the first time the firm has faced such challenges. Estée Lauder was previously targeted by the Clop ransomware group in 2023, during which attackers exploited a separate zero-day vulnerability in the MOVEit Transfer platform.
Implications for System Security
For organizations, the breach underscores the risks associated with zero-day vulnerabilities in enterprise resource planning software. When critical components of HR and business management systems are left exposed by unpatched flaws, the resulting data theft can involve highly sensitive government-issued identification and financial records. Businesses relying on third-party suites must ensure rigorous patch management processes to mitigate the window of opportunity for threat actors who actively scan for and exploit known vulnerabilities across their infrastructure.
Sources
- BleepingComputer Original source
- sample of the disclosure letter Also reporting
- released fixes Also reporting
- since early August, 2025 Also reporting
Continue Reading
LLM-Assisted Phishing Kits Scale Attacks
Researchers uncovered an exposed server revealing how attackers use AI to industrialize the creation of malware delivery campaigns.
Cruciferra Crypter Evolves Malware Tactics
A sophisticated crypter service is leveraging process ghosting and kernel-driver abuse to cloak various commodity malware strains.
Craneware Data Breach Impacts US Health
A cyberattack on the billing software provider has resulted in the theft of employee, customer, and partner records.