Estée Lauder hack steals customer data

Published July 21, 2026

An attacker broke into Estée Lauder's Oracle EBS system and stole customer names, emails, payment details, and health records. The breach happened in August 2025 but was only disclosed in July 2026.

Severity
Not scoredNo CVSS score recorded
Fix
Not confirmed
Affects
Estée Lauder+1 more
Exploited
Not confirmedNo confirmation recorded

How it works

Attackers exploited an unknown flaw in Oracle EBS to bypass security and access customer data without a password.

What to do

Check whether the installed Estée Lauder version is older than the fixed version in the vendor advisory or current release.

Visit Estée Lauder's official breach page for updates and watch for their next steps on data protection.

Technical details

The underlying flaw is CVE-2025-61882, a critical bug (outdated CVSS versions) in the BI Publisher Integration component of Oracle Concurrent Processing within outdated Oracle E-Business Suite versions. It let an unauthenticated attacker with network access send crafted HTTP requests to fully take over the affected component. Oracle disclosed and patched the flaw in October 2025, but exploitation against E-Business Suite customers, including Estee Lauder, began earlier, in August 2025, before a fix existed.