Advertisement
Cyber CrimeConfirmed

Estée Lauder Breach Tied to Oracle Flaw

A critical vulnerability in Oracle E-Business Suite led to the exposure of personal data at the global cosmetics firm.

··1 day ago·2 min read
black laptop computer with white paper
Photo by FlyD on Unsplash
Advertisement

Cosmetics giant Estée Lauder is currently notifying individuals following a data breach stemming from an intrusion into its human resources infrastructure. The company identified that an unauthorized party accessed sensitive files stored within its Oracle E-Business Suite system, a platform utilized by the firm for internal management operations.

Timeline of the Unauthorized Access

The company stated that the intrusion occurred on August 9, 2025, though it was not confirmed until a subsequent investigation concluded on June 19, 2026. The attackers leveraged a specific vulnerability in the Oracle software to bypass security controls, ultimately extracting personal records belonging to employees and other individuals connected to the organization.

We became aware of a cybersecurity issue involving a vulnerability in the Oracle E-Business Suite system which is used by the Estee Lauder Companies for HR management purposes.

— Estée Lauder, via its official breach notification letter

Scope of the Compromised Data

The unauthorized access resulted in the potential exposure of a wide range of sensitive personal and professional documentation. According to a sample of the disclosure letter, the data accessed by the third party included the following:

  • Full names and postal addresses
  • Email addresses and dates of birth
  • Social Security numbers
  • Passport numbers
  • Financial account information, including bank account numbers
  • Health and employment information, such as payroll and performance reports

Context of the Oracle Exploit

While the company did not initially name the specific vulnerability, the timing of the incident aligns with a broader campaign targeting organizations using Oracle E-Business Suite. The attacks involved CVE-2025-61882, a flaw that allowed attackers to execute code remotely and bypass authentication via the BI Publisher Integration component. Oracle released fixes for this vulnerability on October 4, 2025.

This incident is not the first time the firm has faced such challenges. Estée Lauder was previously targeted by the Clop ransomware group in 2023, during which attackers exploited a separate zero-day vulnerability in the MOVEit Transfer platform.

Implications for System Security

For organizations, the breach underscores the risks associated with zero-day vulnerabilities in enterprise resource planning software. When critical components of HR and business management systems are left exposed by unpatched flaws, the resulting data theft can involve highly sensitive government-issued identification and financial records. Businesses relying on third-party suites must ensure rigorous patch management processes to mitigate the window of opportunity for threat actors who actively scan for and exploit known vulnerabilities across their infrastructure.

#data breach#oracle#cybersecurity#estee lauder#clop

Sources

Xploitwire Editorial Team

Xploitwire Newsroom

This article's narrative text was drafted by AI (Google Gemini) from the sources listed above, and passed through our automated fact-check gate before publication. It has not been individually reviewed by a human editor prior to going live. Our AI Policy →

← Back to all stories
Advertisement