Estée Lauder data breach exposes personal info
Estee Lauder's HR system was hacked, exposing employee names, addresses, birthdates, Social Security numbers, bank details, health records, and passport numbers. The attack used a flaw in Oracle's E-Business Suite.
- Report priority
- High
- Victim
- Estee Lauder
What is known
Attackers exploited a flaw in Oracle's E-Business Suite to break into Estee Lauder's HR system and steal employee data.
What to do
Check if you work for Estee Lauder and received a notification about the breach.
If you received a notification, monitor your accounts for suspicious activity and consider freezing your credit if you provided Social Security numbers or bank details.
Reported details
An attacker found a way to break into Estee Lauder's HR system using Oracle's E-Business Suite. They then stole names, addresses, birthdates, Social Security numbers, bank account details, health records, and passport numbers of employees. The stolen data could be used for identity theft or financial fraud.
Estee Lauder's HR platform runs on Oracle E-Business Suite, an enterprise resource planning system many large companies use for functions like HR and finance. The company says an unauthorized party accessed that system around August 9, 2025, and it confirmed the scope of exposed personal data on June 19, 2026. Oracle E-Business Suite has been a repeated target of large-scale intrusion campaigns in 2025 that exploited flaws in the platform to pull data before extortion, though Estee Lauder's notice does not name a specific CVE or attacker group.
References
- nvd.nist.gov vdb entry
- oag.ca.gov · ELC - U.S. Individual Notification Letter.pdf The Cyber Express
- cyble.com · what-is-cybersecurity The Cyber Express
- thehackernews.com · worlds-largest-ai-model-repository.html TheHackerNews
- bleepingcomputer.com · hugging-face-breach-autonomous-ai-agent-system-internal-datasets-credentials BleepingComputer
- bleepingcomputer.com · jadepuffer-agentic-attacks-now-target-ai-model-data-with-ransomware BleepingComputer
- cyber.gc.ca · dell-security-advisory-av26-716 CCCS Canada
- dell.com · en-ca CCCS Canada
- cyber.gc.ca · zyxel-security-advisory-av26-725 CCCS Canada
- zyxel.com · zyxel-security-advisory-for-post-authentication-command-injection-vulnerability-in-certain-dsl-ethernet-cpe-fiber-onts-and-wireless-extenders-07-21-2026 CCCS Canada
- zyxel.com · security-advisories CCCS Canada
- advisory.splunk.com · SVD-2026-0706 Splunk
- advisory.splunk.com · SVD-2026-0705 Splunk
- cyber.gc.ca · ubuntu-security-advisory-av26-717 CCCS Canada
- ubuntu.com · notices CCCS Canada
- securityweek.com · estee-lauder-discloses-impact-from-oracle-ebs-zero-day-hack SecurityWeek
- bleepingcomputer.com · anubis-ransomware-claims-coca-cola-fairlife-attack-threatens-data-leak BleepingComputer
- bleepingcomputer.com · critical-globalprotect-vpn-bug-now-exploited-in-ransomware-attacks BleepingComputer
- securityweek.com · ransomware-group-threatening-to-leak-data-stolen-from-coca-colas-fairlife SecurityWeek
- thehackernews.com · goldeneyedog-subgroup-linked-to.html TheHackerNews
- bleepingcomputer.com · swiss-rail-giant-stadler-rejects-123m-ransom-demand-after-cyberattack BleepingComputer
- neuracybintel.com · microsofts-july-2026-patch-tuesday-fixes-hundreds-of-vulnerabilities-including-multiple-actively-exploited-zero-days NeuraCybIntel
- msrc.microsoft.com · update-guide NeuraCybIntel
- cisa.gov · known-exploited-vulnerabilities-catalog NeuraCybIntel
- microsoft.com · blog NeuraCybIntel