Estée Lauder Data Breach Exposes Employee Records in Oracle EBS Attack
Estée Lauder, the global cosmetics giant, has begun notifying current and former employees after a cyberattack in August 2025 compromised sensitive internal data. The breach, linked to a vulnerability in Oracle’s E-Business Suite (EBS), exposed personal information including names, addresses, Social Security numbers, passport details, bank records, health data, and HR-related documents such as payroll and performance reviews.
The unauthorized access occurred on or around 9 August 2025, with the company detecting the incident shortly after. Estée Lauder launched an investigation with external cybersecurity experts and notified law enforcement while implementing additional security measures. Affected individuals are being offered identity monitoring through Kroll.
The attack aligns with a broader campaign targeting Oracle EBS instances, primarily attributed to the Cl0p ransomware gang, which exploited vulnerabilities most notably CVE-2025-61882, a remote code execution flaw patched by Oracle in October 2025. While Estée Lauder has not confirmed Cl0p’s involvement or whether ransomware was deployed, the breach reflects the risks of mass-exploitation tactics leveraging enterprise software flaws.
Security experts warn that such incidents underscore the far-reaching consequences of supply chain vulnerabilities, particularly when attackers gain prolonged access to highly sensitive data. The exposure of employee records spanning financial, health, and identity information poses significant risks to affected individuals while raising concerns about corporate accountability in safeguarding workforce data.
The Estée Lauder Companies Inc. cybersecurity rating report: https://www.rankiteo.com/company/the-estee-lauder-companies-inc
Oracle cybersecurity rating report: https://www.rankiteo.com/company/oracle
"id": "THEORA1784580016",
"linkid": "the-estee-lauder-companies-inc, oracle",
"type": "Vulnerability",
"date": "8/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Current and former employees',
'industry': 'Cosmetics',
'location': 'Global',
'name': 'Estée Lauder',
'type': 'Corporation'}],
'attack_vector': 'Exploitation of Oracle E-Business Suite (EBS) vulnerability',
'customer_advisories': 'Affected individuals are being offered identity '
'monitoring through Kroll.',
'data_breach': {'personally_identifiable_information': True,
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Names',
'Addresses',
'Social Security numbers',
'Passport details',
'Bank records',
'Health data',
'HR-related documents (payroll, '
'performance reviews)']},
'date_detected': '2025-08-09',
'description': 'Estée Lauder, the global cosmetics giant, has begun notifying '
'current and former employees after a cyberattack in August '
'2025 compromised sensitive internal data. The breach, linked '
'to a vulnerability in Oracle’s E-Business Suite (EBS), '
'exposed personal information including names, addresses, '
'Social Security numbers, passport details, bank records, '
'health data, and HR-related documents such as payroll and '
'performance reviews.',
'impact': {'brand_reputation_impact': 'Raised concerns about corporate '
'accountability in safeguarding '
'workforce data',
'data_compromised': 'Personal information including names, '
'addresses, Social Security numbers, passport '
'details, bank records, health data, and '
'HR-related documents such as payroll and '
'performance reviews',
'identity_theft_risk': 'Significant risks to affected individuals',
'systems_affected': 'Oracle E-Business Suite (EBS)'},
'investigation_status': 'Ongoing',
'lessons_learned': 'Incidents underscore the far-reaching consequences of '
'supply chain vulnerabilities, particularly when attackers '
'gain prolonged access to highly sensitive data.',
'post_incident_analysis': {'root_causes': 'Exploitation of Oracle EBS '
'vulnerability (CVE-2025-61882)'},
'ransomware': {'ransomware_strain': 'Cl0p'},
'response': {'communication_strategy': 'Notifying affected individuals and '
'offering identity monitoring through '
'Kroll',
'containment_measures': 'Additional security measures '
'implemented',
'incident_response_plan_activated': True,
'law_enforcement_notified': True,
'third_party_assistance': 'External cybersecurity experts'},
'threat_actor': 'Cl0p ransomware gang',
'title': 'Estée Lauder Data Breach Exposes Employee Records in Oracle EBS '
'Attack',
'type': 'Data Breach',
'vulnerability_exploited': 'CVE-2025-61882'}