
The Estée Lauder Companies is notifying current and former employees that their personal information was stolen after attackers compromised the company's Oracle E-Business Suite (EBS) human resources environment in August 2025.
The intrusion is linked to the wider Oracle EBS exploitation campaign that emerged last year and was later attributed to the Clop ransomware gang.
According to breach notification letters, Estée Lauder discovered the cybersecurity incident during an investigation into a vulnerability affecting Oracle E-Business Suite, the enterprise platform the company uses for HR management. The investigation determined that an unauthorized party gained access to the system on or around August 9, 2025, and exfiltrated personal information belonging to certain individuals. The company said it confirmed on June 19, 2026, that employee data had been accessed during the intrusion.
The Estée Lauder Companies is one of the world's largest cosmetics manufacturers, with a portfolio of brands including Estée Lauder, Clinique, MAC Cosmetics, La Mer, Bobbi Brown, Aveda, Jo Malone London, and The Ordinary. The multinational company employs tens of thousands of people globally and relies on Oracle E-Business Suite to manage human resources and payroll functions.
The compromised information varies by individual but includes highly sensitive personal and employment records. According to the notification, exposed data may include:
- Names
- Postal and email addresses
- Dates of birth
- Social Security numbers
- Passport numbers
- Bank account information
- Health information
- Employment-related records such as payroll and performance evaluations
Although the notification does not identify the threat actor responsible, the timing closely aligns with the mass-exploitation campaign targeting Oracle E-Business Suite, disclosed in October 2025.
At the time, Mandiant revealed that the Clop ransomware operation had exploited multiple Oracle EBS vulnerabilities, including a previously unknown remote code execution flaw tracked as CVE-2025-61882. The critical vulnerability affected Oracle E-Business Suite versions 12.2.3 through 12.2.14 and allowed unauthenticated attackers to execute code remotely through the BI Publisher integration component over HTTP.
Mandiant said Clop began exploiting Oracle EBS environments in August 2025 to steal sensitive corporate data before sending extortion demands to victims. Oracle released patches for some vulnerabilities in July 2025, while the zero-day was not fixed until October 4, 2025.
The August 9, 2025, compromise date disclosed by Estée Lauder falls squarely within the early stages of that campaign, making the company one of the latest organizations to publicly acknowledge being affected by the attacks.
Following the discovery, Estée Lauder said it launched an investigation with external cybersecurity specialists, notified law enforcement, and implemented additional security measures to better protect the affected systems. The company did not disclose how many individuals were impacted or whether it received an extortion demand.
To help reduce the risk of identity theft, Estée Lauder is offering affected individuals 24 months of complimentary identity monitoring and restoration services through Kroll. Impacted individuals have until October 31, 2026, to enroll.






Leave a Reply