• 2 min read
Estée Lauder says Oracle HR breach exposed SSNs
Estée Lauder says hackers accessed its Oracle E-Business Suite HR system in August 2025, exposing personal data including SSNs and bank details.

Image: BleepingComputer
Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in the Oracle E-Business Suite platform the company used for HR operations.
According to the company’s notification, Estée Lauder identified the cybersecurity issue last month and determined on June 19, 2026 that an unauthorized third party had accessed the system on or around August 9, 2025. The company says the attacker obtained personal information of certain individuals.
“We became aware of a cybersecurity issue involving a vulnerability in the Oracle E-Business Suite system which is used by the Estee Lauder Companies for HR management purposes.”
A sample disclosure letter says the exposed data includes:

Recommended reading
Free 0Patch fix arrives for Windows LegacyHive zero-day
- Full names
- Postal addresses
- Email addresses
- Dates of birth
- Social Security numbers
- Passport numbers
- Financial account information, including bank account numbers
- Health information
- Employment information, including payroll and performance reports
The notice does not name the vulnerability, but the reported breach date aligns with the mass exploitation of CVE-2025-61882, an Oracle E-Business Suite flaw tied to attacks by the Clop ransomware gang. In October 2025, researchers at Google and Mandiant warned that Clop had used the bug as a zero-day to steal data.
The flaw affected EBS versions 12.2.3–12.2.14 and allowed attackers to bypass authentication and execute code remotely through the BI Publisher Integration component, potentially exposing sensitive HR and business data. Oracle released patches for CVE-2025-61882 on October 4, 2025, and CrowdStrike later said Clop had been exploiting it since early August 2025.
Other organizations linked to the same campaign include Harvard, the University of Pennsylvania, Dartmouth, the University of Phoenix, The Washington Post, Logitech, GlobalLogic, Cox Enterprises, and Envoy Air, a subsidiary of American Airlines.
Estée Lauder, a New York-based cosmetics company with $14.3 billion in annual revenue, says affected people should watch for signs of identity theft and fraud. The company is offering 24 months of complimentary identity monitoring through Kroll.
The incident is also not the company’s first run-in with Clop. Estée Lauder was hit in 2023 when the group exploited a separate zero-day in MOVEit Transfer.
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via BleepingComputer


