Estée Lauder Confirms Data Breach Due to Oracle Vulnerability – Veri Sızıntısı

Estée Lauder Discloses Data Breach From Oracle Flaw

Cosmetics giant Estée Lauder has announced a data breach resulting from the exploitation of a vulnerability in its Oracle E-Business Suite system, used for HR operations. The attack is linked to a method previously used by the Clop ransomware group.

Estée Lauder logo with a blurred technology background representing an Oracle server room.

What Happened

Estée Lauder, one of the biggest names in the cosmetics world, has made an announcement that has shaken the cybersecurity community. The company has begun notifying its customers and employees of a data breach stemming from a security vulnerability in its Oracle E-Business Suite system, which it uses to manage human resources (HR) operations. The New York-based giant, the second-largest firm in its sector with an annual revenue of $14.3 billion and 57,000 employees worldwide, confirmed that attackers gained access to sensitive personal information.

According to the company's notification, the cyberattack actually occurred nearly a year ago, on August 9, 2025. However, Estée Lauder was only able to detect this unauthorized access last month, on June 19, 2026. This means the attackers may have remained undetected in the systems for approximately eleven months, potentially maintaining access to data during this period. In its statement, the company said, “We became aware of a cybersecurity issue involving a vulnerability in the Oracle E-Business Suite system which is used by the Estee Lauder Companies for HR management purposes. On June 19, 2026, we determined through our investigation that, on or around August 9, 2025, an unauthorized third party gained access to the Oracle E-Business Suite system and obtained personal information of certain individuals.”

This incident marks the second major cyberattack Estée Lauder has experienced in recent years. In 2023, the company also suffered a data breach when the Clop ransomware gang exploited a zero-day vulnerability in the MOVEit Transfer platform. This pattern raises serious questions about the company's cybersecurity infrastructure and its reliance on third-party software.

What Data Was Stolen

Based on a sample of the disclosure letter sent by Estée Lauder, the scope of the data obtained by the attackers is extensive and includes highly sensitive information. The data of the affected individuals has the potential to be used for a wide range of malicious activities, from identity theft to financial fraud. The stolen information includes:

  • Full names: Basic information for identity verification and social engineering attacks.
  • Postal addresses: Can be used for physical fraud and identity theft.
  • Email addresses: A critical component for targeted phishing attacks and other cyber fraud.
  • Dates of birth: Another key piece of information frequently used in identity verification processes.
  • Social Security numbers (SSNs): One of the most critical pieces of personal data for U.S. citizens. It opens the door to severe fraud, such as opening new credit cards, filing fraudulent tax returns, or use in illegal employment.
  • Passport numbers: Extremely valuable data that can be used for international travel and identity forgery.
  • Financial account information (including bank account numbers): Information that can lead to direct financial losses, creating risks of account draining or unauthorized transfers.
  • Health information: The most private information about individuals, which can be used for blackmail, insurance fraud, or discrimination.
  • Employment information (including payroll and performance reports): Can be used to pressure employees, for blackmail, or for corporate espionage activities where it could be sold to rival firms.

The fact that this data was leaked together creates a much greater danger than the risk posed by each data type individually. Attackers can combine this information to create highly detailed profiles of victims and develop much more convincing fraud scenarios.

How the Attack Happened

Although Estée Lauder did not specify the exact vulnerability exploited in the attack, the date of the breach, August 2025, coincides with an attack campaign that made significant waves in the cybersecurity world. During that period, the Clop ransomware gang was conducting a large-scale campaign targeting a critical zero-day vulnerability in Oracle E-Business Suite, known as CVE-2025-61882.

In October 2025, researchers at Google and Mandiant issued warnings that the Clop gang was actively exploiting this flaw to steal data. The vulnerability affected versions 12.2.3 through 12.2.14 of Oracle E-Business Suite. It allowed attackers to bypass authentication mechanisms and execute code remotely through the system's BI Publisher Integration component. This meant that attackers could infiltrate the system without needing any username or password and gain full access to sensitive HR and business data.

Oracle released patches for this critical vulnerability on October 4, 2025. However, as confirmed by cybersecurity firm CrowdStrike, the Clop gang had already begun exploiting the vulnerability in early August 2025, well before the patches were released. Estée Lauder's breach date falls squarely within this period, suggesting the cosmetics giant was one of the first victims of Clop's zero-day attacks.

Other notable victims of the same attack campaign include Harvard University, the University of Pennsylvania, Dartmouth, the University of Phoenix, The Washington Post, Logitech, GlobalLogic, Cox Enterprises, and Envoy Air, a subsidiary of American Airlines. This list demonstrates the extensive scope and effectiveness of the attack.

Who Is Affected

While Estée Lauder stated that "certain individuals" were affected by the breach, the fact that the attack targeted a system used for human resources management strongly suggests that the victims are likely current and former company employees. The types of data leaked, including payrolls, performance reports, and Social Security numbers, which are directly related to employment, reinforce this theory. The company has not disclosed a specific number of affected individuals. However, with a global workforce of 57,000, it is estimated that the data of potentially tens of thousands of people could be at risk.

What You Can Do

In its letters to individuals affected by the data breach, Estée Lauder advises them to be vigilant for signs of identity theft and fraud. The company is also offering 24 months of complimentary identity monitoring services through Kroll to help mitigate these risks.

If you believe you have been affected by this breach or have received a notification letter, it is recommended that you take the following steps:

  • Check Your Credit Reports: Regularly review your credit reports to detect any suspicious accounts or inquiries opened in your name.
  • Monitor Your Accounts: Carefully examine your bank and credit card statements and immediately report any unrecognized transactions to your bank.
  • Change Your Passwords: If you have passwords related to Estée Lauder or use common passwords across other platforms, change them to strong, unique passwords.
  • Beware of Phishing Attacks: Attackers may use the personal information they have obtained to send you personalized and much more convincing phishing emails. Avoid clicking on links or downloading attachments from unknown sources.
  • Activate the Identity Monitoring Service: By signing up for the free Kroll identity monitoring service offered by Estée Lauder, you can track whether your data is being sold on the dark web or if any suspicious activity is being carried out with your credentials.

What the Company Is Saying

In its notification, Estée Lauder attempts to explain the incident transparently. The company's statement notes, "We became aware of a cybersecurity issue... through our investigation... we determined that an unauthorized third party gained access to the system and obtained personal information." The company states it is providing free identity monitoring services to support affected individuals and is working with cybersecurity experts to investigate the incident. However, the nearly 11-month delay in detecting the event raises concerns about the company's cybersecurity monitoring and incident response processes. Being targeted by the Clop gang in two separate incidents indicates that the company needs to take more proactive measures against future cyberattacks.

Source

https://www.bleepingcomputer.com/news/security/est-e-lauder-discloses-data-breach-via-oracle-e-business-flaw/

This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.

Weekly Newsletter

Curated data breach news delivered to your inbox every week.