Estee Lauder announced that their Oracle E-Business Suite (EBS) system that manages human capital operations was targeted by cyber criminals who managed to steal personal data of some of the company’s employees. The company confirmed that some of the information on the intranet belonged to third parties who were not authorized to access it. According to the company’s statement, Estee Lauder learned about the breach following an internal investigation into the cybersecurity incident.
Specifically, investigators discovered on June 19, 2026, that unauthorized users accessed the Oracle EBS system on or around August 9, 2025. The data exfiltrated by the hackers varied depending on the individual’s details but generally included names, addresses, and email, birth dates, social security numbers, passport numbers, bank information, medical data, and records of payroll and performance reviews. Since the breach involved PII, financial information, and employment data, there is a risk of identity theft and financial fraud for the affected employees.
After detecting the anomaly, Estee Lauder contracted cybersecurity experts to conduct a forensic audit, report the pertinent information to the relevant law enforcement agencies, and take additional measures to secure the site. The company is offering 24 months of identity and restoration services through Kroll to all the affected parties free of charge, and the services will be available until October 31, 2026. All the affected employees should remain on the lookout for possible suspicious activities, including monitoring financial accounts, credit reports, and other relevant personal information.
Even though Estee Lauder did not disclose the identity of the perpetrators, in the context of the discovered timeline, it is plausible to assume that the threat actors who targeted the company are part of the Cl0p extortion group. According to reports by Google and Mandiant, the hacking group utilized several Oracle EBS vulnerabilities, including the zero-day flaw with the reference number CVE-2025-61882, to initiate attacks against other companies. The vulnerability that was most likely used in the attack allowed malicious cyber actors to deploy arbitrary code via an unauthenticated HTTP request and affected all Oracle EBS versions from 12.2.3 to 12.2.14.
Notably, Oracle released a security patch on October 4, 2025, after detecting that the vulnerability was being actively exploited. The latest breach serves as a reminder of the potential risks associated with the use of enterprise resource planning software that has the capability to store PII and other sensitive information about employees. It is strongly advised that organizations that use similar systems remain wary of the threats and make sure that all the relevant software has been updated with the latest security patches while also configuring the tools in a manner that minimizes the attack surface.
In addition, enterprise systems should be constantly monitored for any suspicious activities that could indicate possible threats to data security. Tags: Cyber Criminals Cyberattacks cybersecurity incidents Data Breach Data Leak data security Digital Personal Data Protection Employee Data