Estée Lauder Confirms Data Breach: SSNs, Passport Numbers, and Health Data Exposed via Oracle EBS Exploit

Published
Written by:
Lore Apostol
Lore Apostol
Cybersecurity Writer
Key Takeaways
  • Breach date: The intrusion occurred on or around August 9, 2025, and was disclosed on July 20, 2026.
  • Data exposed: Compromised information includes Social Security numbers, passport numbers, and financial and health data.
  • Concluded investigation: Estée Lauder closed its investigation late last month, approximately ten months after the intrusion.

Cosmetics giant Estée Lauder disclosed a data breach on July 20, 2026, after hackers exploited a vulnerability in Oracle E-Business Suite (EBS) used for the company's human resources operations. The intrusion occurred nearly a year earlier, on or around August 9, 2025.

Estée Lauder is urging affected individuals to watch closely for signs of identity theft and fraud, and is offering 24 months of complimentary identity monitoring through Kroll to those impacted.

What Data Was Exposed

An unauthorized third party gained access to the Oracle EBS system and obtained personal information belonging to certain individuals. The Estée Lauder data breach spans:

Estée Lauder only concluded its investigation on June 19, 2026, meaning the exposure went undetected for nearly ten months. 

Oracle E-Business Suite Flaw Tied to Cl0p

While Estée Lauder's notice doesn't name the specific flaw, the timing of the breach lines up with the mass-exploitation campaign targeting CVE-2025-61882, a vulnerability that let attackers bypass authentication and remotely execute code. 

The Cl0p ransomware gang exploited this flaw as a zero-day, stealing data before Oracle had a chance to release fixes. Kela’s 2025 Midyear Threat Report listed Cl0p Ransomware among the year’s top threats.

Estée Lauder joins a growing list of Oracle campaign victims. The same Oracle EBS campaign has also hit Nissan, a Canon Subsidiary, Harvard University, the University of Phoenix, The Washington Post, and Logitech. Over 100 organizations were reportedly affected in the Cl0p Oracle hacking campaign.

The beauty company also faced a class action lawsuit in 2023 and exposed 440 million internal records in 2021.


For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: