
Estée Lauder has begun notifying individuals that their personal information was exposed after an unauthorized party breached an Oracle E-Business Suite system the company relied on for human resources functions. The company said it identified the intrusion last month, tracing unauthorized access back to August 9, 2025.
In a notification letter sent to affected individuals, the New York-based beauty company stated that a cybersecurity issue involving a vulnerability in its Oracle E-Business Suite system led to the exposure. The company said it confirmed on June 19, 2026, that an unauthorized third party had gained access to the system roughly ten months earlier and obtained personal data belonging to certain individuals.
The scope of exposed information varied by individual and included full names, home addresses, email addresses, birth dates, Social Security numbers, and passport numbers. Also compromised were financial account details such as bank account numbers, along with health records and employment-related data including payroll history and performance evaluations.
Estée Lauder ranks as the world’s second-largest cosmetics company, generating $14.3 billion in annual revenue and employing 57,000 people across online and brick-and-mortar operations worldwide. Its portfolio spans prestige skincare, makeup, fragrance, and haircare lines.
After discovering the intrusion, the company engaged external cybersecurity specialists, alerted law enforcement, and implemented additional protective measures for the affected system. Estée Lauder is offering affected individuals 24 months of complimentary identity monitoring through Kroll, with enrollment available through October 31, 2026. The notification urged recipients to monitor their financial accounts, statements, and credit reports for signs of suspicious activity as a precaution against identity theft and fraud.
The company’s disclosure does not name the party responsible for the breach. However, the timing of the intrusion coincides with a broader hacking campaign that targeted Oracle E-Business Suite systems through a vulnerability tracked as CVE-2025-61882. Google and Mandiant researchers reported in October 2025 that the Cl0p extortion group had exploited that flaw, along with other Oracle E-Business Suite vulnerabilities, to steal data from multiple organizations in August 2025.
The vulnerability allowed attackers without valid credentials to execute code remotely over HTTP on systems running Oracle E-Business Suite versions 12.2.3 through 12.2.14. Oracle issued a patch addressing CVE-2025-61882 on October 4, 2025.
This is not the first time Estée Lauder has been targeted by the Cl0p group. In 2023, the company was compromised when the threat actor exploited a separate zero-day vulnerability in the MOVEit Transfer file-sharing platform, one of the tools Estée Lauder used internally at the time.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543