Oracle and Estée Lauder: Cosmetics giant Estée Lauder victim of mass Oracle breach

Oracle and Estée Lauder: Cosmetics giant Estée Lauder victim of mass Oracle breach

Estée Lauder Data Breach Exposes Employee Records in Oracle EBS Attack

Estée Lauder, the global cosmetics giant, has begun notifying current and former employees after a cyberattack in August 2025 compromised sensitive internal data. The breach, linked to a vulnerability in Oracle’s E-Business Suite (EBS), exposed personal information including names, addresses, Social Security numbers, passport details, bank records, health data, and HR-related documents such as payroll and performance reviews.

The unauthorized access occurred on or around 9 August 2025, with the company detecting the incident shortly after. Estée Lauder launched an investigation with external cybersecurity experts and notified law enforcement while implementing additional security measures. Affected individuals are being offered identity monitoring through Kroll.

The attack aligns with a broader campaign targeting Oracle EBS instances, primarily attributed to the Cl0p ransomware gang, which exploited vulnerabilities most notably CVE-2025-61882, a remote code execution flaw patched by Oracle in October 2025. While Estée Lauder has not confirmed Cl0p’s involvement or whether ransomware was deployed, the breach reflects the risks of mass-exploitation tactics leveraging enterprise software flaws.

Security experts warn that such incidents underscore the far-reaching consequences of supply chain vulnerabilities, particularly when attackers gain prolonged access to highly sensitive data. The exposure of employee records spanning financial, health, and identity information poses significant risks to affected individuals while raising concerns about corporate accountability in safeguarding workforce data.

Source: https://www.computerweekly.com/news/366645849/Cosmetics-giant-Estee-Lauder-victim-of-mass-Oracle-breach

The Estée Lauder Companies Inc. cybersecurity rating report: https://www.rankiteo.com/company/the-estee-lauder-companies-inc

Oracle cybersecurity rating report: https://www.rankiteo.com/company/oracle

"id": "THEORA1784580016",
"linkid": "the-estee-lauder-companies-inc, oracle",
"type": "Vulnerability",
"date": "8/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Current and former employees',
                        'industry': 'Cosmetics',
                        'location': 'Global',
                        'name': 'Estée Lauder',
                        'type': 'Corporation'}],
 'attack_vector': 'Exploitation of Oracle E-Business Suite (EBS) vulnerability',
 'customer_advisories': 'Affected individuals are being offered identity '
                        'monitoring through Kroll.',
 'data_breach': {'personally_identifiable_information': True,
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Names',
                                              'Addresses',
                                              'Social Security numbers',
                                              'Passport details',
                                              'Bank records',
                                              'Health data',
                                              'HR-related documents (payroll, '
                                              'performance reviews)']},
 'date_detected': '2025-08-09',
 'description': 'Estée Lauder, the global cosmetics giant, has begun notifying '
                'current and former employees after a cyberattack in August '
                '2025 compromised sensitive internal data. The breach, linked '
                'to a vulnerability in Oracle’s E-Business Suite (EBS), '
                'exposed personal information including names, addresses, '
                'Social Security numbers, passport details, bank records, '
                'health data, and HR-related documents such as payroll and '
                'performance reviews.',
 'impact': {'brand_reputation_impact': 'Raised concerns about corporate '
                                       'accountability in safeguarding '
                                       'workforce data',
            'data_compromised': 'Personal information including names, '
                                'addresses, Social Security numbers, passport '
                                'details, bank records, health data, and '
                                'HR-related documents such as payroll and '
                                'performance reviews',
            'identity_theft_risk': 'Significant risks to affected individuals',
            'systems_affected': 'Oracle E-Business Suite (EBS)'},
 'investigation_status': 'Ongoing',
 'lessons_learned': 'Incidents underscore the far-reaching consequences of '
                    'supply chain vulnerabilities, particularly when attackers '
                    'gain prolonged access to highly sensitive data.',
 'post_incident_analysis': {'root_causes': 'Exploitation of Oracle EBS '
                                           'vulnerability (CVE-2025-61882)'},
 'ransomware': {'ransomware_strain': 'Cl0p'},
 'response': {'communication_strategy': 'Notifying affected individuals and '
                                        'offering identity monitoring through '
                                        'Kroll',
              'containment_measures': 'Additional security measures '
                                      'implemented',
              'incident_response_plan_activated': True,
              'law_enforcement_notified': True,
              'third_party_assistance': 'External cybersecurity experts'},
 'threat_actor': 'Cl0p ransomware gang',
 'title': 'Estée Lauder Data Breach Exposes Employee Records in Oracle EBS '
          'Attack',
 'type': 'Data Breach',
 'vulnerability_exploited': 'CVE-2025-61882'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.