Estée Lauder hack steals customer data
An attacker broke into Estée Lauder's Oracle EBS system and stole customer names, emails, payment details, and health records. The breach happened in August 2025 but was only disclosed in July 2026.
- Severity
- Not scoredNo CVSS score recorded
- Fix
- Not confirmed
- Affects
- Estée Lauder+1 more
- Exploited
- Not confirmedNo confirmation recorded
How it works
Attackers exploited an unknown flaw in Oracle EBS to bypass security and access customer data without a password.
What to do
Check whether the installed Estée Lauder version is older than the fixed version in the vendor advisory or current release.
Visit Estée Lauder's official breach page for updates and watch for their next steps on data protection.
Technical details
The underlying flaw is CVE-2025-61882, a critical bug (outdated CVSS versions) in the BI Publisher Integration component of Oracle Concurrent Processing within outdated Oracle E-Business Suite versions. It let an unauthenticated attacker with network access send crafted HTTP requests to fully take over the affected component. Oracle disclosed and patched the flaw in October 2025, but exploitation against E-Business Suite customers, including Estee Lauder, began earlier, in August 2025, before a fix existed.