Overview
- The company determined on June 19, 2026 that an unauthorized party accessed its Oracle E‑Business Suite instance on or around August 2025 and obtained personal information from the HR system.
- Exposed files varied by person and included full names, postal and email addresses, dates of birth, Social Security numbers, passport numbers, bank account details, health information, and payroll and performance records.
- Estée Lauder is notifying current and former employees, has engaged outside cybersecurity firms and law enforcement, and is offering 24 months of complimentary identity monitoring through Kroll.
- Security researchers link the incident to a wider mid‑2025 mass‑exploitation campaign that targeted the BI Publisher Integration component of Oracle EBS (CVE-2025-61882) and is commonly attributed to the Cl0p extortion group, but the company has not publicly made that attribution.
- The breach highlights how a single flaw in a widely used enterprise platform can expose large volumes of employee data and raise long‑term identity and privacy risks for staff while organizations work to detect, patch, and disclose such intrusions.