Estée Lauder says it was hit by data breach caused by Oracle E-Business issue
Breach Details
The breach happened in August 2025, but was only spotted recently by Estée Lauder.
A new Estée Lauder investigation uncovered an old breach - Estée Lauder confirms Oracle E‑Business Suite breach from August 2025, only disclosed in June 2026. Attackers stole extensive personal, financial, health, and employment data from HR management platform. The breach is tied to CVE‑2025‑61882, a critical Oracle EBS RCE flaw exploited across 100+ organizations.
If you remember the Oracle E-Business Suite vulnerability that was exploited around October 2025 in numerous attacks, you can now add Estée Lauder to the list of victims. The cosmetics giant has confirmed having been hit, despite the initial breach happening almost a year ago, following an investigation in mid-June 2026 uncovering the incident.
In a data breach notification letter that is now being sent out, the company said that “on June 19, 2026, we determined through our investigation that, on or around August 9, 2025, an unauthorized third party gained access to the Oracle E-Business Suite system and obtained personal information of certain individuals.”
Data Compromised
Estée Lauder said the platform was used by the holding company “for HR management purposes.” We don’t know exactly how many people are affected by this incident, but we do know that the attackers obtained:
- Full names
- Postal addresses
- Email addresses
- Dates of birth
- Social Security numbers (SSN)
- Passport numbers
- Financial account information (including bank account numbers)
- Health information
- Employment information
This is more than enough data to run highly disruptive and damaging identity theft attacks, and Estée Lauder’s warning is of little help coming almost a year too late.
Vulnerability and Attack Timeline
In early October 2025, cybercriminals started mailing executives at various American organizations, claiming to have stolen sensitive files from their Oracle E-Business Suite systems. At the time, both Oracle and the wider cybersecurity community were not certain if the breaches actually happened, or if this was just a bluff to get the victims to pay a ransom demand.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
However, the claims were soon confirmed, since more than 100 organizations reported falling victim. In early October 2025, Oracle issued an emergency fix to patch CVE-2025-61882, a 9.8/10 (critical) pre-authentication remote code execution (RCE) vulnerability in Oracle EBS.
“This vulnerability is remotely exploitable without authentication, i.e., it may be exploited over a network without the need for a username and password,” Oracle said in the advisory. “If successfully exploited, this vulnerability may result in remote code execution.”
Via BleepingComputer
➡️ Read our full guide to the best antivirus:
- Best overall: Bitdefender Total Security
- Best for families: Norton 360 with LifeLock
- Best for mobile: McAfee Mobile Security
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.
You must confirm your public display name before commenting. Please logout and then login again, you will then be prompted to enter your display name.
Comments
No comments yet. Start the discussion.