Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack

Cosmetics giant Estée Lauder has started notifying employees that their information was stolen from its Oracle E-Business Suite (EBS) instance last year.
The incident, the company says, occurred in early August 2025, when the infamous Cl0p cybercrime group started exploiting CVE-2025-61882, a zero-day vulnerability in Oracle EBS that enabled unauthenticated remote code execution (RCE), to exfiltrate data from numerous companies.
In November, more than 100 companies were listed on the Cl0p leak website, many of which confirmed being impacted by the campaign.
By March 2026, Broadcom, Bechtel, Estée Lauder, and Abbott Laboratories were the only major companies that had not disclosed the impact from the campaign. Cl0p leaked 870GB of archive files allegedly stolen from Estée Lauder.
Several days after the zero-day was patched in early October, CrowdStrike said it found evidence that the bug’s in-the-wild exploitation started on August 9, the same day that Estée Lauder was hit.
In a notification letter to the affected individuals, a copy of which was filed (PDF) with the California Attorney General’s Office, the cosmetics giant said its investigation into the incident determined in June that personal information had been stolen from its EBS instance, which was used for HR management.
The compromised data, the company says, includes names, addresses, dates of birth, Social Security numbers, passport numbers, bank account numbers, health information, and employment-related data, including payroll information.
Estée Lauder is providing the potentially affected individuals with 24 months of free identity monitoring services and is advising them to remain vigilant for suspicious emails, texts, and phone calls.
The company says it has notified law enforcement of the data breach and has taken measures to improve its system’s protections.
Estée Lauder has not disclosed the number of potentially impacted individuals. SecurityWeek has emailed the company for additional details on the incident and will update this article if it responds.
Related: Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data
Related: Clover Health Investments Discloses Data Breach
Related: Multiple Jscrambler Packages Impacted by Supply Chain Attack
Related: Mainline Health, Select Medical Each Disclose Data Breaches Impacting 100,000 People
https://www.securityweek.com/estee-lauder-discloses-impact-from-oracle-ebs-zero-day-hack/