Cosmetics giant Estée Lauder has confirmed a data breach affecting individuals whose personal information was stored in its Oracle E-Business Suite system, after threat actors exploited a vulnerability in the platform used for human resources operations. The incident, which the company says occurred on August 9, 2025, was identified last month and resulted in the exposure of sensitive personal and financial data belonging to certain employees and other individuals.
In a notification letter sent to affected parties, Estée Lauder stated that an unauthorized third party gained access to the Oracle E-Business Suite system and obtained a broad range of personal information. The exposed data includes full names, postal addresses, email addresses, dates of birth, Social Security numbers, passport numbers, financial account information including bank account numbers, health information, and employment records such as payroll data and performance reports.
Estée Lauder, a New York-based cosmetics firm with annual revenue of $14.3 billion and approximately 57,000 employees, operates both online and physical retail locations worldwide. The company is the second-largest cosmetics firm globally.
Estée Lauder Breach Linked to Oracle CVE-2025-61882 Exploitation
Although the breach notification does not explicitly name the vulnerability exploited, the timing of the intrusion aligns closely with the mass-exploitation campaign targeting Oracle E-Business Suite through CVE-2025-61882. In October 2025, researchers from Google and Mandiant warned that the Clop ransomware gang was exploiting the flaw as a zero-day to steal data from organizations using the platform.
The vulnerability affects Oracle E-Business Suite versions 12.2.3 through 12.2.14 and allows attackers to bypass authentication and remotely execute code via the BI Publisher Integration component. This access can grant threat actors control over sensitive HR and business data stored within the system.
Oracle released patches for CVE-2025-61882 on October 4, 2025. Cybersecurity firm CrowdStrike subsequently confirmed that Clop had been actively exploiting the vulnerability since early August 2025, matching the timeline of the Estée Lauder intrusion.
Other notable organizations impacted by the same campaign include Harvard, the University of Pennsylvania, Dartmouth College, the University of Phoenix, The Washington Post, Logitech, GlobalLogic, Cox Enterprises, and American Airlines subsidiary Envoy Air.
What Data Was Exposed in the Estée Lauder Breach?
The compromised data includes identifiers that can be used for identity theft and fraud, such as Social Security numbers, passport numbers, and financial account details. The inclusion of health information and employment records further elevates the risk for affected individuals, as such data is often difficult to replace and can be exploited in targeted social engineering attacks.
What Affected Individuals Should Do Now
Estée Lauder is advising recipients of the breach notification to remain vigilant for signs of identity theft and fraud. The company is offering 24 months of complimentary identity monitoring services through Kroll for those impacted. Individuals who believe their data may have been compromised should take the following steps immediately:
- Enroll in the offered identity monitoring service to receive alerts on suspicious activity involving your personal information.
- Place a fraud alert or security freeze on your credit reports with the three major credit bureaus — Equifax, Experian, and TransUnion — to prevent unauthorized accounts from being opened in your name.
- Monitor bank accounts, credit card statements, and other financial accounts regularly for unauthorized transactions.
- Change passwords for any accounts that may use the same credentials as those stored in the compromised system, and enable multi-factor authentication wherever available.
- Review healthcare statements and Explanation of Benefits (EOB) documents for any signs of fraudulent medical claims or services.
This incident marks the second time Estée Lauder has been targeted by Clop. In 2023, the company was compromised when the same threat actor exploited a zero-day vulnerability in the MOVEit Transfer platform, an internal software tool used by the firm.
The breadth of data exposed in this breach underscores the risks associated with widely used enterprise resource planning platforms that centralize sensitive employee and customer information. Organizations using Oracle E-Business Suite should verify that they have applied all available patches for CVE-2025-61882 and other known vulnerabilities, and should implement network segmentation and access controls to limit the exposure of HR and financial systems to the internet. For affected individuals, enrolling in credit monitoring and maintaining a close watch on financial and healthcare accounts represents the most effective defense against downstream fraud.