Estée Lauder Uncovers Data Breach Nearly 1 Year Late

Cosmetics giant Estée Lauder has disclosed a data breach dating back to August 9, 2025, after determining, nearly a year later, on June 19, 2026 that attackers accessed its Oracle E-Business Suite system and exfiltrated personal information belonging to employees. The stolen data includes names, addresses, dates of birth, Social Security numbers, passport numbers, bank account numbers, health information, and payroll and performance records — the platform was used for HR management. The intrusion exploited CVE-2025-61882, a critical (CVSS 9.8) authentication bypass in Oracle's BI Publisher Integration that the Clop ransomware gang has used to hit more than 100 organizations, including Harvard, the University of Pennsylvania, The Washington Post, Logitech, and American Airlines' Envoy subsidiary. Clop has since leaked roughly 870 GB of Estée Lauder data, likely after failed extortion.

The 10-month gap between initial compromise and confirmed disclosure is not an outlier — it reflects Clop's playbook of quietly harvesting data from many victims of a shared software vulnerability before beginning extortion, meaning victims often learn the shape of their exposure only after attackers do. When a zero-day like CVE-2025-61882 lands, the window between exploitation and patching is measured in months, and the data leaves long before the CVE is public. Estée Lauder was previously hit through the MOVEit vulnerability in 2023, underscoring how repeat exposure through shared enterprise software has become a structural risk.

Reducing this exposure requires visibility across the application and data layer, not just the perimeter and endpoint. Effective controls and early detection and analytics include leveraging a unified platform like NIKSUN to conduct behavioral analytics on access to enterprise systems like Oracle EBS, baselining of query volumes and data extraction patterns from HR and financial databases, and packet-level capture with long retention to support forensic reconstruction. Read more about this story on our LinkedIn page

We use cookies to offer you a better browsing experience and to analyze site traffic. By using our site, you consent to our use of cookies.

Essential Cookies
Site Analytics