Data Breaches

Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack

Hackers exfiltrated personal, financial, and health information from the company’s Oracle EBS instance in August 2025.

Estee Lauder data breach

Cosmetics giant Estée Lauder has started notifying employees that their information was stolen from its Oracle E-Business Suite (EBS) instance last year.

The incident, the company says, occurred in early August 2025, when the infamous Cl0p cybercrime group started exploiting CVE-2025-61882, a zero-day vulnerability in Oracle EBS that enabled unauthenticated remote code execution (RCE), to exfiltrate data from numerous companies.

In November, more than 100 companies were listed on the Cl0p leak website, many of which confirmed being impacted by the campaign.

By March 2026, Broadcom, Bechtel, Estée Lauder, and Abbott Laboratories were the only major companies that had not disclosed the impact from the campaign. Cl0p leaked 870GB of archive files allegedly stolen from Estée Lauder.

Several days after the zero-day was patched in early October, CrowdStrike said it found evidence that the bug’s in-the-wild exploitation started on August 9, the same day that Estée Lauder was hit.

In a notification letter to the affected individuals, a copy of which was filed (PDF) with the California Attorney General’s Office, the cosmetics giant said its investigation into the incident determined in June that personal information had been stolen from its EBS instance, which was used for HR management.

Advertisement. Scroll to continue reading.

The compromised data, the company says, includes names, addresses, dates of birth, Social Security numbers, passport numbers, bank account numbers, health information, and employment-related data, including payroll information.

Estée Lauder is providing the potentially affected individuals with 24 months of free identity monitoring services and is advising them to remain vigilant for suspicious emails, texts, and phone calls.

The company says it has notified law enforcement of the data breach and has taken measures to improve its system’s protections.

Estée Lauder has not disclosed the number of potentially impacted individuals. SecurityWeek has emailed the company for additional details on the incident and will update this article if it responds.

Related: Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data

Related: Clover Health Investments Discloses Data Breach

Related: Multiple Jscrambler Packages Impacted by Supply Chain Attack

Related: Mainline Health, Select Medical Each Disclose Data Breaches Impacting 100,000 People

Related Content

Artificial Intelligence

Spanish regulators say an AI agent chained together a successful login, vulnerability discovery, and access to personal data in a potential milestone for autonomous...

Data Breaches

In June 2026, hackers accessed files containing patients’ names, contact information, diagnosis details, and health insurance information.

Data Breaches

A hacker claims to have stolen 7.5 million customer records after breaching the company’s systems.

Data Breaches

Hackers exploited a vulnerability in a VPN product to steal the personal information of roughly 240,000 people.

Data Breaches

The company unintentionally disclosed users’ information to a third party impersonating a government agency.

Data Breaches

Stolen credentials were used in a multi-month campaign to access subscriber personal data and billing records.

Data Breaches

Hackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking.

Cybercrime

Oleksii Oleksiyovych Lytvynenko has been sentenced to 4 years in prison after he was arrested in Ireland in 2023.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version