Vulnerability in Oracle Software

Estée Lauder Reports Data Breach Caused by Oracle Vulnerability

Estée Lauder
Facebook
X
LinkedIn
Reddit
WhatsApp
Source: salarko/Shutterstock.com

Estée Lauder reports a data breach. Attackers exploited a vulnerability in Oracle E-Business Suite to steal personal and customer data.

The US cosmetics giant Estée Lauder is informing affected individuals about a data security incident within its systems. In June 2026, the company identified unauthorized access to the Oracle E-Business Suite software, which is used internally for HR management processes. According to investigations, the actual intrusion occurred as early as August 9, 2025. In the notification letter, the company describes the status of the investigation:

Ad

“On June 19, 2026, we determined through our investigation that, on or around August 9, 2025, an unauthorized third party gained access to the Oracle E-Business Suite system and obtained personal information of certain individuals.”

Estée Lauder

Ad

Affected data categories and company scale

Various categories of sensitive data were exfiltrated during the incident. According to the company, the stolen information includes:

  • Full names and postal addresses
  • Email addresses and dates of birth
  • Social Security numbers and passport numbers
  • Financial and bank account information
  • Health information
  • Employment data, including salary and performance reports

Estée Lauder is headquartered in New York, generates annual revenue of 14.3 billion US dollars, and employs approximately 57,000 people worldwide.

Technical background and the role of Clop

Although Estée Lauder’s notification does not explicitly name the exploited vulnerability, the timing of the intrusion correlates with a global cyberattack campaign. In this campaign, attackers exploited the vulnerability CVE-2025-61882 in versions 12.2.3 through 12.2.14 of the Oracle E-Business Suite. The extortion group Clop utilized this vulnerability as a zero-day flaw starting in early August 2025 to bypass authentication and execute malicious code via the BI Publisher Integration component.

Oracle released security updates for the flaw on October 4, 2025. In addition to Estée Lauder, other organizations such as universities, logistics providers, and media outlets were compromised as part of the same campaign. Estée Lauder was previously targeted by the Clop group in 2023, when a flaw in the MOVEit Transfer software was exploited. As a protective measure, the company is offering affected individuals 24 months of complimentary identity monitoring services through the provider Kroll.

(red)

Ad

Weitere Artikel