Estée Lauder data breach exposes personal info

Published July 15, 2026

Estee Lauder's HR system was hacked, exposing employee names, addresses, birthdates, Social Security numbers, bank details, health records, and passport numbers. The attack used a flaw in Oracle's E-Business Suite.

Report priority
High
Victim
Estee Lauder

What is known

Attackers exploited a flaw in Oracle's E-Business Suite to break into Estee Lauder's HR system and steal employee data.

What to do

Check if you work for Estee Lauder and received a notification about the breach.

If you received a notification, monitor your accounts for suspicious activity and consider freezing your credit if you provided Social Security numbers or bank details.

Reported details

An attacker found a way to break into Estee Lauder's HR system using Oracle's E-Business Suite. They then stole names, addresses, birthdates, Social Security numbers, bank account details, health records, and passport numbers of employees. The stolen data could be used for identity theft or financial fraud.

Estee Lauder's HR platform runs on Oracle E-Business Suite, an enterprise resource planning system many large companies use for functions like HR and finance. The company says an unauthorized party accessed that system around August 9, 2025, and it confirmed the scope of exposed personal data on June 19, 2026. Oracle E-Business Suite has been a repeated target of large-scale intrusion campaigns in 2025 that exploited flaws in the platform to pull data before extortion, though Estee Lauder's notice does not name a specific CVE or attacker group.

References