Estée Lauder says it was hit by data breach caused by Oracle E-Business issue
- Estée Lauder confirms Oracle E‑Business Suite breach from August 2025, only disclosed in June 2026
- Attackers stole extensive personal, financial, health, and employment data from HR management platform
- Breach tied to CVE‑2025‑61882, a critical Oracle EBS RCE flaw exploited across 100+ organizations
If you remember the Oracle E-Business Suite vulnerability that was exploited around October 2025 in numerous attacks, you can now add Estée Lauder to the list of victims.
The cosmetics giant has confirmed having been hit, despite the initial breach happening almost a year ago, following an investigation in mid-June 2026 uncovering the incident.
In a data breach notification letter that is now being sent out, the company said that “on June 19, 2026, we determined through our investigation that, on or around August 9, 2025, an unauthorized third party gained access to the Oracle E-Business Suite system and obtained personal information of certain individuals.”
Major remote code...
Copyright of this story solely belongs to techradar.com. To see the full text click HERE