2 min read

Estée Lauder took 11 months to reveal HR data breach

Estée Lauder says hackers accessed Oracle HR software in August 2025 and stole bank, health, and payroll data. Staff were notified in July 2026.

Image: TNW

Estée Lauder is notifying employees that hackers stole sensitive personal data from the Oracle E-Business Suite software it uses for human resources, with the company disclosing the breach nearly a year after the initial intrusion. BleepingComputer first reported the notice.

According to Estée Lauder’s notification letter, an attacker accessed the system on or around 9 August 2025. The company says it confirmed the data theft on 19 June 2026, and letters to affected staff were sent on 17 July.

The exposed data is extensive. Estée Lauder says the stolen records include:

  • Full names
  • Postal and email addresses
  • Dates of birth
  • Social Security numbers
  • Passport numbers
  • Bank account details
  • Health information
  • Employment data, including payroll and performance reviews

The company is offering affected employees two years of free identity monitoring through Kroll.

Recommended reading

Adobe Chrome bug exposed WhatsApp Web chats

The company did not identify the vulnerability in its letter, but the timeline matches a broader attack campaign targeting Oracle E-Business Suite through CVE-2025-61882. That bug is described as a critical, pre-authentication vulnerability that allows attackers to execute code without needing a username or password.

Oracle patched the flaw on 4 October 2025, but security researchers said the Clop ransomware gang had already been exploiting it as a zero-day since early August. More than 100 organisations were affected in the same wave, including Harvard, the University of Pennsylvania, The Washington Post, Logitech, and Cox Enterprises.

For Estée Lauder, it is a repeat incident. The company was also hit by Clop in 2023, when attackers exploited a zero-day in the MOVEit file-transfer tool. The longer-term problem here is the delay: a breach that began in August 2025 was not disclosed to staff until the following July, leaving affected people with little time to respond before their data could already be misused.

Sophia Reynolds

Security Editor

Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.

via TNW

// Keep reading