← All stories
● Covered by 1 source · 1 reportMedium impact

Estée Lauder reports data breach from Oracle E-Business Suite vulnerability

Estée Lauder has disclosed a data breach involving a vulnerability in Oracle E-Business Suite, which was exploited to access personal customer data. The breach, identified on June 19, 2026, occurred on August 9, 2025, and included sensitive information such as Social Security numbers and financial details.

Key points

  • Estée Lauder's breach exposed various personal data of individuals.
  • The compromise was linked to a known vulnerability in Oracle's E-Business Suite.
  • This breach joined a series of attacks affecting multiple high-profile organizations.

Details of the Data Breach

Estée Lauder has reported that hackers exploited a vulnerability in Oracle E-Business Suite, which the company utilized for its HR operations. The intrusion, detected on June 19, 2026, allows access to sensitive personal data that occurred on August 9, 2025.

Nature of Exposed Information

The data breach included full names, addresses, email addresses, dates of birth, Social Security numbers, passport numbers, and financial account details, among other sensitive information. This broad exposure raises concerns about identity theft and financial fraud for those affected.

Vulnerability Context

The breach correlates with mass exploitation campaigns targeting Oracle E-Business Suite, specifically linked to CVE-2025-61882. This vulnerability, affecting EBS versions 12.2.3 to 12.2.14, allowed attackers to bypass authentication measures and execute code remotely, which enabled them to access sensitive business and HR data.

Response and Recommendations

Estée Lauder has advised individuals affected by the data breach to stay vigilant for potential signs of identity theft and fraud. They encouraged recipients of the notification letter to monitor their accounts closely, although the notification did not detail specific mitigation steps being undertaken by the company.

Broader Implications

This incident highlights the ongoing risks associated with vulnerabilities in widely used software solutions like Oracle E-Business Suite. Other high-profile organizations affected by similar attacks underscore the urgent need for heightened cybersecurity measures across industries.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~23 min · 20 stories · Jul 20

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Estée Lauder has disclosed a data breach involving a vulnerability in Oracle E-Business Suite, which was exploited to access personal customer data. The breach, identified on June 19, 2026, occurred on August 9, 2025, and included sensitive information such as Social Security numbers and financial details.