Estée Lauder Companies and Oracle: Estée Lauder Companies hit by data breach targeting HR operation software

Estée Lauder Companies and Oracle: Estée Lauder Companies hit by data breach targeting HR operation software

Estée Lauder Companies Suffers Data Breach Exposing Employee Personal and Financial Information

Estée Lauder Companies (ELC) disclosed a data breach impacting its HR operations system, stemming from a vulnerability in its Oracle E-Business Suite (EBS). The incident, which occurred in August 2025, was uncovered during an internal investigation and reported to California authorities in compliance with state disclosure laws.

The breach exposed sensitive personal data of certain employees, including names, addresses, dates of birth, Social Security numbers, passport numbers, bank account details, and health information. Employment-related records, such as performance evaluations and payroll data, were also compromised. The extent of exposed information varied by individual.

ELC detected the unauthorized access on June 19, 2026, confirming that a third party infiltrated the Oracle EBS system on or around August 9, 2025. Following the discovery, the company engaged external cybersecurity experts to assess the breach’s scope, notified law enforcement, and implemented additional security measures.

To mitigate risks, ELC partnered with Kroll, a risk advisory firm, to provide affected employees with two years of identity monitoring. The company advised impacted individuals to monitor accounts and credit reports for suspicious activity.

The incident highlights ongoing risks to enterprise HR systems, particularly those reliant on third-party software like Oracle EBS. No further details on the attackers or their motives have been released.

Source: https://cosmeticsbusiness.com/est%C3%A9e-lauder-companies-hit-by-data-breach

Oracle cybersecurity rating report: https://www.rankiteo.com/company/oracle

The Estée Lauder Companies Inc. cybersecurity rating report: https://www.rankiteo.com/company/the-estee-lauder-companies-inc

"id": "ORATHE1784810063",
"linkid": "oracle, the-estee-lauder-companies-inc",
"type": "Breach",
"date": "8/2025",
"severity": "85",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'industry': 'Cosmetics',
                        'name': 'Estée Lauder Companies',
                        'type': 'Corporation'}],
 'attack_vector': 'Vulnerability in Oracle E-Business Suite (EBS)',
 'customer_advisories': 'Affected employees advised to monitor accounts and '
                        'credit reports for suspicious activity',
 'data_breach': {'personally_identifiable_information': ['Names',
                                                         'Addresses',
                                                         'Dates of Birth',
                                                         'Social Security '
                                                         'Numbers',
                                                         'Passport Numbers'],
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Personal Identifiable '
                                              'Information (PII)',
                                              'Financial Information',
                                              'Health Information',
                                              'Employment Records']},
 'date_detected': '2026-06-19',
 'description': 'Estée Lauder Companies (ELC) disclosed a data breach '
                'impacting its HR operations system, stemming from a '
                'vulnerability in its Oracle E-Business Suite (EBS). The '
                'incident exposed sensitive personal data of certain '
                'employees, including names, addresses, dates of birth, Social '
                'Security numbers, passport numbers, bank account details, and '
                'health information. Employment-related records, such as '
                'performance evaluations and payroll data, were also '
                'compromised.',
 'impact': {'data_compromised': 'Sensitive personal and financial information '
                                'of employees',
            'identity_theft_risk': 'High',
            'payment_information_risk': 'High',
            'systems_affected': 'HR operations system'},
 'investigation_status': 'Ongoing',
 'lessons_learned': 'Ongoing risks to enterprise HR systems, particularly '
                    'those reliant on third-party software like Oracle EBS',
 'post_incident_analysis': {'corrective_actions': 'Engaged external '
                                                  'cybersecurity experts, '
                                                  'implemented additional '
                                                  'security measures, provided '
                                                  'identity monitoring for '
                                                  'affected employees',
                            'root_causes': 'Vulnerability in Oracle E-Business '
                                           'Suite (EBS)'},
 'references': [{'source': 'Incident disclosure'}],
 'regulatory_compliance': {'regulations_violated': 'California state '
                                                   'disclosure laws',
                           'regulatory_notifications': 'Reported to California '
                                                       'authorities'},
 'response': {'communication_strategy': 'Advisories to affected employees to '
                                        'monitor accounts and credit reports',
              'incident_response_plan_activated': 'Yes',
              'law_enforcement_notified': 'Yes',
              'remediation_measures': 'Additional security measures '
                                      'implemented',
              'third_party_assistance': 'Kroll (risk advisory firm)'},
 'title': 'Estée Lauder Companies Suffers Data Breach Exposing Employee '
          'Personal and Financial Information',
 'type': 'Data Breach',
 'vulnerability_exploited': 'Oracle E-Business Suite (EBS) vulnerability'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.