The Estée Lauder Companies has begun notifying employees of a data breach after threat actors exploited a vulnerability in Oracle E-Business Suite (EBS), the human resources platform the cosmetics giant relies on for payroll and workforce management. The company disclosed the incident on July 21, 2026, following a months-long investigation.
The Estée Lauder Breach Timeline
According to the U.S. notification letter, an unauthorised third party obtained personal information on or around August 9, 2025 — but Estée Lauder only confirmed the extent of the incident on June 19, 2026. Exposed records vary by individual but include full names, postal and email addresses, dates of birth, Social Security numbers, passport numbers, bank account details, health information and payroll and performance data.
Estée Lauder said it engaged outside cybersecurity specialists, notified law enforcement and hardened its Oracle systems following discovery, and is offering 24 months of identity monitoring through Kroll with an enrollment deadline of October 31, 2026.
CVE-2025-61882 And The Clop Campaign
Although the notice does not name a threat actor, the intrusion window aligns with the mass exploitation of Oracle E-Business Suite via CVE-2025-61882, an unauthenticated remote code execution flaw in EBS versions 12.2.3 through 12.2.14 that Oracle patched on October 4, 2025. Google and Mandiant researchers subsequently attributed the campaign to the Clop extortion gang, which used the zero-day to steal data from more than 900 exposed EBS instances between early August and October 2025.

Latest In A Wide Victim List
Estée Lauder joins a growing roster of Clop-linked EBS victims that includes Harvard, the University of Pennsylvania, Dartmouth College, The Washington Post, Logitech, GlobalLogic, Cox Enterprises and American Airlines subsidiary Envoy Air. It is also the second time Estée Lauder has been compromised by Clop; the group previously hit the company through the MOVEit Transfer zero-day in 2023. Related coverage includes our recent reports on the Ernst & Young data breach, the WordPress WP2Shell RCE emergency patch and the Fairlife ransomware disruption.
Reporting based on coverage from BleepingComputer, Help Net Security and California Attorney General notice filings.
