Estée Lauder discloses data breach via Oracle E-Business flaw
Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. The exposed data includes full names, postal addresses, email addresses, dates of birt…
Intelligence analysis by Llama

Estée Lauder has disclosed a data breach after hackers exploited a flaw in Oracle E-Business Suite. The exposed data includes personal information of certain individuals, including full names, postal addresses, email addresses, dates of birth, social security numbers, passport numbers, financial account information, and health information.
Imagine you're at a big store with lots of people working there. The store has a special computer system that helps them manage things like employee information and customer data. Hackers found a way to break into this system and steal some of the information. This is like someone taking a bunch of files from the store's office and looking through them. The store is now telling everyone who might be affected to be careful and watch out for any problems.
Analysis
A $60B Vote of Confidence
Estée Lauder's recent data breach is a stark reminder of the importance of cybersecurity in today's digital landscape. The company's use of Oracle E-Business Suite, a widely used enterprise resource planning (ERP) system, highlights the need for robust security measures to protect against cyber threats. The breach, which occurred in August 2025, resulted in the exposure of sensitive information, including full names, postal addresses, email addresses, dates of birth, social security numbers, passport numbers, financial account information, and health information. This is not the first time Estée Lauder has been compromised by hackers. In 2023, the company was hit by a zero-day exploit in the MOVEit Transfer platform, one of its internal software tools. The recent breach is a wake-up call for companies to prioritize cybersecurity and invest in robust security measures to prevent similar breaches.
Why Cursor?
The Oracle E-Business Suite vulnerability, CVE-2025-61882, was first identified in October 2025 by Google and Mandiant researchers. The flaw, which affected EBS versions 12.2.3–12.2.14, enabled attackers to bypass authentication and remotely execute code through the BI Publisher Integration component. This potentially gave them access to sensitive HR and business data. Oracle released fixes for the vulnerability on October 4, 2025. Shortly after, cybersecurity firm CrowdStrike confirmed that Clop had been exploiting the flaw since early August, 2025. Other notable victims of the same campaign include Harvard, the University of Pennsylvania, Dartmouth, the University of Phoenix, The Washington Post, Logitech, GlobalLogic, Cox Enterprises, and the American Airlines subsidiary Envoy Air.
The Road Ahead
Estée Lauder is advising recipients of the breach notification letter to remain vigilant for signs of identity theft and fraud. The company is also offering 24 months of complimentary identity monitoring services through Kroll. This is a positive step towards mitigating the impact of the breach. However, it is essential for companies to prioritize cybersecurity and invest in robust security measures to prevent similar breaches. This includes regular security audits, employee training, and the implementation of robust security protocols to protect against cyber threats.
Key points
- Estée Lauder has disclosed a data breach after hackers exploited a flaw in Oracle E-Business Suite.
- The exposed data includes personal information of certain individuals, including full names, postal addresses, email addresses, dates of birth, social security numbers, passport numbers, financial account information, and health information.
- The company is advising recipients of the breach notification letter to remain vigilant for signs of identity theft and fraud.
- Estée Lauder is offering 24 months of complimentary identity monitoring services through Kroll.
Estée Lauder's response to the breach, including offering complimentary identity monitoring services, is a positive step towards mitigating the impact of the breach. The company's commitment to prioritizing cybersecurity and investing in robust security measures will help prevent similar breaches in the future.
The recent data breach at Estée Lauder highlights the ongoing threat of cyber attacks and the need for robust security measures to protect against them. The company's use of Oracle E-Business Suite and the exploitation of a known vulnerability demonstrate the importance of regular security audits, employee training, and the implementation of robust security protocols.



