news.mlab.sh
Back to the feed
data-breach

Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack

High
Summary

Estée Lauder has been hit by a zero-day vulnerability in Oracle EBS, allowing the Cl0p cybercrime group to steal a massive amount of sensitive data, including personal information and payroll details. The breach, discovered in June 2026, exposed data of potentially thousands of employees and led to the company notifying affected individuals and offering 24 months of identity monitoring.

Estée Lauder has been the target of a significant data breach stemming from a zero-day vulnerability in its Oracle E-Business Suite (EBS) system. The incident occurred in early August 2026, when the Cl0p cybercrime group exploited CVE-2025-61882, a remote code execution (RCE) flaw, to exfiltrate data from numerous companies. By November 2026, Cl0p publicly listed over 100 companies impacted by the campaign, with Estée Lauder and several others remaining unacknowledged until June 2026.

Estée Lauder’s investigation revealed that the breach resulted in the theft of 870GB of archive files containing sensitive information, including names, addresses, dates of birth, Social Security numbers, passport numbers, bank account numbers, and health information. The company’s HR management system, utilizing EBS, was the primary target.

In a notification letter to affected employees, Estée Lauder stated that the breach impacted their HR management system and that the stolen data included payroll information. The company is providing 24 months of free identity monitoring services to those affected and advises vigilance against phishing attempts.

Estée Lauder has notified law enforcement and implemented measures to bolster system security. The exact number of impacted individuals remains undisclosed, though the company is working to determine it.

Related articles discuss similar data breaches involving Meta and Clover Health Investments.

Read the full article at SecurityWeek