2026 Estée Lauder — Oracle EBS HR breach (Aug 2025); employee SSNs, payroll, health records
Data compromised
Per California and trade-press notification letters: names, addresses, DOB, SSNs, government IDs, bank account information, payroll and employment records, performance evaluations, and health records for current/former employees; nationwide count not publicly attested
Technical writeup
Verified employee data breach — public notices July 2026. The Estée Lauder Companies Inc. notified current and former employees that personal information was stolen after attackers accessed its Oracle E-Business Suite human-resources environment on or around August 9, 2025; the company confirmed employee-data access on June 19, 2026 during an investigation into Oracle EBS vulnerabilities. Notification letters summarized by BleepingComputer and CyberInsider cite names, addresses, dates of birth, Social Security numbers, government IDs, bank account information, payroll and employment records, performance evaluations, and health records. The timing aligns with the Cl0p ransomware group's mass-exploitation campaign against Oracle E-Business Suite, including CVE-2025-61882. Estée Lauder offered 24 months of Kroll identity monitoring. A nationwide affected-individual count had not been publicly attested at indexing time; BreachHistory retains recordsAffected 0 pending a regulator or company total.
Root cause
Unauthorized access to Oracle E-Business Suite HR environment on or around Aug. 9, 2025, linked to Cl0p mass-exploitation of Oracle EBS flaws including CVE-2025-61882
References
- https://www.bleepingcomputer.com/news/security/est-e-lauder-discloses-data-breach-via-oracle-e-business-flaw/
- https://cyberinsider.com/estee-lauder-discloses-data-breach-tied-to-oracle-e-business-suite-attacks/
- https://oag.ca.gov/system/files/ELC%20-%20U.S.%20Individual%20Notification%20Letter.pdf
- https://ago.vermont.gov/categories/security-breach-notices
- https://www.elcompanies.com/