Hands on laptop showing data breach

Cosmetics Giant Estée Lauder Discloses a 10-Month Old Data Breach

Cosmetics giant Estée Lauder has disclosed a 10-month-old data breach that exposed the personal information of thousands of employees.

The August 9, 2025, data leak stemmed from a critical (CVSS v3 9.8) vulnerability, CVE-2025-61882, in Oracle E-Business Suite applications, which was widely exploited by the Clop ransomware gang.

“On June 19, 2026, we determined through our investigation that, on or around August 9, 2025, an unauthorized third party gained access to the Oracle E-Business Suite system and obtained personal information of certain individuals,” the company stated.

Estée Lauder hacked via Oracle’s E-Business Suite data breach

The Clop ransomware gang has leaked about 870 GB of data stolen from the cosmetics giant, likely after a failed extortion attempt. The attack exploited a critical vulnerability (CVSS v3 9.8) CVE-2025-61882 in Oracle’s E-Business Suite BI Publisher Integration that could enable an attacker to bypass authentication and execute remote code.

Google Threat Intelligence Group (GTIG) estimated that the Clop ransomware group exploited over 100 organizations. Some confirmed victims include Harvard University, American Airlines’ subsidiary Envoy, the University of Pennsylvania, Dartmouth, University of Phoenix, The Washington Post, GlobalLogic, and Logitech.

Oracle released security fixes on October 4, 2025, but CrowdStrike estimated that the Clop ransomware gang had been exploiting the vulnerability since August 2025.

Upon learning of the data breach, Estée Lauder launched an investigation, with the assistance of external cyber forensics, to determine the nature of the stolen information and to whom it belonged, and notified law enforcement.

The probe determined that the attackers had exfiltrated personal information, including names, postal and email addresses, dates of birth, Social Security Numbers, passport numbers, bank account numbers, health information, and employment-related information, such as payroll and performance reports. The cosmetics giant says it used the platform “for HR management purposes.”

Meanwhile, Estée Lauder has applied additional cybersecurity measures to harden the system and protect the personal information in its custody from further unauthorized access.

The cosmetics giant is also offering 24 months of complimentary identity monitoring services through Kroll. Qualifying customers should enroll by October 31, 2026, to take advantage of the complimentary service.

Additionally, victims should monitor their financial and credit reports and notify authorities and their financial institutions of any suspicious activity. They should also avoid unsolicited communication via phone calls, email, or text to avoid falling victim to targeted phishing (spear phishing). Impacted individuals can also place credit alerts to prevent fraudsters from opening new credit lines.

“Please remain vigilant in protecting against identity theft and fraud, including monitoring your accounts, account statements, and credit reports for signs of suspicious activity,” the company warned.

Clop ransomware strikes again

Estée Lauder is no stranger to data breaches. In 2023, BlackCat/ALPHAV and Clop ransomware gangs breached the cosmetics giant via the MOVEit managed file transfer application and stole at least 131 GB of data.

The MOVEit data breach also affected hundreds of organizations, including the Centers for Medicare & Medicaid Services (CMS), after compromising a third party that manages Medicare Part A/B claims. Others include the Maine State Government, Deutsche Bank, ING, Postbank, and Comdirect.

“This group doesn’t break into companies one at a time,” said John Watters, Chairman and CEO, iCounter. “They find a vulnerability in software that thousands of organizations share, harvest data quietly across as many victims as they can before anyone notices, and then work through the extortion process at their own pace long after the initial compromise. By the time a company like Estée Lauder confirms what happened, Clop has already known the shape of that exposure for the better part of a year.”