Estée Lauder disclosed that attackers breached its Oracle E-Business Suite environment used for human resources operations and stole personal information from certain individuals. The company said unauthorized access occurred on or around August 9, 2025, and was confirmed through an investigation on June 19, 2026. Exposed data varied by person but included highly sensitive records such as Social Security numbers, passport numbers, bank account details, health information, and employment data.
The intrusion aligns with the wider exploitation of Oracle E-Business Suite zero-day CVE-2025-61882, a remote code execution flaw later tied by Google and Mandiant to the Cl0p extortion gang. Oracle released fixes on October 4, 2025, after multiple organizations were reportedly affected in the same campaign. Estée Lauder said it brought in external cybersecurity experts, notified law enforcement, added safeguards, and is offering affected individuals 24 months of identity monitoring through Kroll while warning them to watch for identity theft and fraud.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
Estée Lauder disclosed the data breach and said it is notifying affected individuals whose information was exposed. The company is urging vigilance for identity theft and fraud and offering 24 months of identity monitoring through Kroll.
Estée Lauder said its investigation confirmed on June 19, 2026 that personal information had been stolen from its Oracle E-Business Suite environment. The company also said it engaged outside cybersecurity experts, notified law enforcement, and added safeguards after discovering the incident.
Oracle released patches for the Oracle E-Business Suite vulnerability CVE-2025-61882 after broader exploitation of the flaw, which reporting linked to a campaign later associated with the Cl0p extortion gang.
Estée Lauder said an unauthorized third party accessed its Oracle E-Business Suite environment used for HR operations on or around August 9, 2025, and stole personal information from certain individuals.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
6 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityweek.com
Open sourcehelpnetsecurity.com
Open sourceteiss.co.uk
Open sourcebleepingcomputer.com
Open sourceoag.ca.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.