Estée Lauder Says Hackers Stole Staff Data Through an Oracle HR System Flaw

The cosmetics giant links the August 2025 break-in to the same Oracle E-Business Suite bug the Clop ransomware crew has been abusing all year.

ThreatVectr Newsdesk· 3 min read
Full-frame photoreal editorial shot of a dimly lit corporate server room with rows of glowing blue and amber rack lights, a slightly out-of-focus enterprise dat
Share

Key points

  • Estée Lauder has told affected people that hackers broke into its Oracle E-Business Suite HR system on or around August 9, 2025.
  • The company confirmed the scope of the theft on June 19, 2026, after a months-long investigation.
  • Stolen data includes names, Social Security numbers, passport numbers, bank details, and health and payroll records.
  • The timing lines up with mass exploitation of CVE-2025-61882, a flaw in Oracle's business software patched on October 4, 2025.
  • Estée Lauder is offering 24 months of free identity monitoring through Kroll.

Estée Lauder is writing to customers and staff to tell them their personal information was stolen in a break-in last summer.

The cosmetics company, which employs around 57,000 people and reported $14.3 billion in annual revenue, said hackers got into its Oracle E-Business Suite system on or around August 9, 2025. Oracle E-Business Suite is a large piece of back-office software that many big companies use to run things like human resources and payroll.

Estée Lauder used it for HR.

The company said it worked out the full picture on June 19, 2026. By then, the intruders had already made off with a serious amount of personal data.

What information was taken?

The stolen files include full names, home addresses, email addresses, dates of birth, Social Security numbers, passport numbers, bank account numbers, health information, and employment records covering payroll and performance reviews.

That is close to a worst-case list. Passport and Social Security numbers are exactly what criminals use to open credit lines or file fake tax returns in someone else's name.

Estée Lauder is offering affected people two years of identity monitoring through Kroll, and telling them to watch for signs of fraud on their accounts.

How did the hackers get in?

Estée Lauder has not named the specific flaw, but the date of the break-in matches a well-documented attack campaign against Oracle E-Business Suite.

The bug is tracked as CVE-2025-61882. In plain English, it let attackers reach the Oracle system over the internet, skip the login step entirely, and then run their own commands on the server. From there, they could read whatever HR and finance data the system held.

The flaw affected E-Business Suite versions 12.2.3 through 12.2.14. Oracle shipped a fix on October 4, 2025. By then, the damage was already spreading.

Google's Mandiant team and CrowdStrike later linked the attacks to Clop, a long-running extortion crew that specialises in hitting one widely used piece of enterprise software at a time and stealing data from every customer it can reach. Clop had been quietly exploiting the Oracle bug since early August 2025, before Oracle knew about it. That makes it a zero-day, meaning a flaw the vendor had no patch for when attacks began.

This was, as first reported by BleepingComputer, a broad campaign. Other confirmed victims include Harvard, the University of Pennsylvania, Dartmouth, the University of Phoenix, The Washington Post, Logitech, Cox Enterprises, and American Airlines subsidiary Envoy Air.

Would multi-factor authentication have helped?

Honestly, not much here. The Oracle flaw let attackers skip the login process entirely by abusing the BI Publisher Integration component, a reporting tool bolted onto E-Business Suite. Multi-factor authentication, which asks for a code from your phone on top of your password, only helps when the attacker actually has to log in. This attack did not need a password at all.

What would have helped is faster patching, tighter network rules on which machines can reach the HR server from the internet, and monitoring for the specific web requests the attackers used.

This is not Estée Lauder's first run-in with Clop either. The same gang hit the company in 2023 through a different zero-day, that time in the MOVEit file-transfer product. Two zero-days, two years apart, same attackers. That is a pattern worth noticing.

© 2026 Threat Vectr