• 2 min read
Estée Lauder discloses Oracle breach nearly a year later
Estée Lauder says attackers accessed its Oracle E-Business Suite in August 2025, stealing sensitive HR data tied to a critical Oracle flaw.

Image: TechRadar
Estée Lauder says attackers breached its Oracle E-Business Suite environment on or around August 9, 2025, but the company only confirmed the incident on June 19, 2026 after an investigation. The company is now sending data breach notifications to affected individuals.
According to the notice, the compromised Oracle E-Business Suite system was used for HR management purposes. Estée Lauder said an unauthorized third party obtained personal information belonging to certain individuals, though it did not say how many people were affected.
The stolen data includes:
- Full names
- Postal addresses
- Email addresses
- Dates of birth
- Social Security numbers
- Passport numbers
- Financial account information, including bank account numbers
- Health information
- Employment information
The breach is tied to CVE-2025-61882, a 9.8/10 critical pre-authentication remote code execution flaw in Oracle EBS. Oracle issued an emergency fix in early October 2025 after cybercriminals began contacting executives at multiple US organizations, claiming they had stolen sensitive files from Oracle E-Business Suite systems.

Recommended reading
1,000 GPUs could destabilize a power grid, researchers warn
Those claims were later borne out, with more than 100 organizations reporting breaches. Oracle said at the time:
“This vulnerability is remotely exploitable without authentication, i.e., it may be exploited over a network without the need for a username and password. If successfully exploited, this vulnerability may result in remote code execution.”
TechRadar reports that Estée Lauder is the latest known victim linked to that broader wave of attacks, which was also covered by BleepingComputer.
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via TechRadar


