Estée Lauder Discloses Impact From Oracle E-Business Suite Zero-Day Breach
Another Oracle EBS customer disclosure lands: Estée Lauder confirms the theft of employees' personal, financial, and health data from its Oracle E-Business Suite HR system, closing one of the last gaps in the 2025 Oracle zero-day cycle.
Another Oracle EBS disclosure closes one of the last gaps in the 2025 zero-day cycle — this time, an HR system full of employee data.
NEW YORK — The Estée Lauder Companies has begun notifying employees that their personal, financial, and health information was stolen from an Oracle E-Business Suite (EBS) system the cosmetics giant used for human resources operations, according to a breach notification the company disclosed on July 21, 2026. The confirmation places Estée Lauder among the organizations swept up in the 2025 zero-day campaign against Oracle E-Business Suite, and it closes one of the last remaining gaps in that months-long wave of corporate disclosures.
Estée Lauder determined the scope in June 2026, roughly ten months after attackers first reached the system. Reporting from SecurityWeek and Help Net Security ties the intrusion to the exploitation of CVE-2025-61882, an Oracle E-Business Suite zero-day patched in October 2025 and attributed to the Cl0p extortion group. For defenders, the disclosure is less a new threat than a case study in how long the tail of a single enterprise-software zero-day can run.
What Estée Lauder Disclosed
In a notification letter filed with the California Attorney General's Office, Estée Lauder said it became aware of a cybersecurity issue involving a vulnerability in the Oracle E-Business Suite system it uses for HR management. The company determined on June 19, 2026 that, on or around August 9, 2025, an unauthorized third party gained access to the system and obtained personal information of certain individuals.
The data varied by person but reportedly included names, postal and email addresses, dates of birth, Social Security numbers, passport numbers, bank account numbers, health information, and employment records such as performance evaluations and payroll history. Estée Lauder has not disclosed how many people were affected. The company said it engaged outside cybersecurity experts, notified law enforcement, and added safeguards to the affected system, and is offering 24 months of free identity monitoring through Kroll with an enrollment deadline of October 31, 2026.
The Oracle Vulnerability Cycle in Context
The intrusion traces to CVE-2025-61882, a zero-day in Oracle E-Business Suite that allowed unauthenticated attackers with network access to execute code remotely over HTTP. Oracle shipped a fix on October 4, 2025, but researchers later established that in-the-wild exploitation had begun on August 9 — the same day Estée Lauder was hit — roughly two months before the patch. Reporting attributes the broader campaign to the Cl0p extortion group, which listed more than 100 organizations on its leak site in November 2025.
The episode sits alongside a run of Oracle-related coverage CyberSignal has tracked through 2026, including a separate Oracle EBS Payments flaw under active exploitation and a PeopleSoft zero-day used against higher-education targets. It also parallels the employee-data breach disclosed by Nissan and the wider PeopleSoft campaign against roughly 100 organizations, though those strands are attributed to distinct activity and have not been tied to the Cl0p EBS campaign.
Affected-Employee Notification and Health-Data Implications
For the people being notified, the combination of stolen data is unusually sensitive. Social Security numbers, passport numbers, and bank account details support long-term identity fraud, while the inclusion of health information and payroll history pushes the exposure beyond a typical HR-system incident. Because the source was an internal HR platform rather than a customer database, the affected population is Estée Lauder's own workforce — a group that cannot simply close an account and walk away the way a consumer might.
That durability is why the 24-month Kroll monitoring offer, with its October 31, 2026 enrollment deadline, matters more than it would for a lower-sensitivity breach. Health data held in an employment context can also draw scrutiny under state and sector privacy regimes, and organizations that hold similar records should treat HR-system breaches in their incident-response planning as carrying regulatory weight comparable to healthcare or financial exposures — not as routine back-office events.
Sector-Advisory Posture for Oracle EBS Customers
For other Oracle E-Business Suite operators, the Estée Lauder disclosure is a reminder that the 2025 zero-day campaign is not closed history. The fix for CVE-2025-61882 has been available since October 2025, so the immediate work is verification rather than discovery: confirming that every EBS instance — the vulnerable range spans versions 12.2.3 through 12.2.14 — has actually applied it, not merely that a patch was released. Because large EBS estates often include older or forgotten instances, a single representative build does not speak for the whole footprint.
The exposure question is equally worth revisiting. The vulnerable functionality is reachable over HTTP, so confirming whether an EBS interface needs to face untrusted networks at all is a durable hardening step that outlasts any one CVE. Treating patch management across the Oracle estate as a continuous, verified process rather than a one-time response is the lesson this cycle keeps teaching.
Open Questions
Several points remain unresolved. Estée Lauder has not published the number of affected individuals, and its notification does not name the threat actor, though the timing aligns with the Cl0p campaign identified by Google and Mandiant. The company's earlier reported appearance on the Cl0p leak site — where roughly 870GB of files were allegedly listed — has not been independently reconciled with the confirmed notification, and CyberSignal treats those leak-site claims as reported rather than established.
The precise regulatory posture beyond the California filing is not yet clear, and whether this activity connects to the Council of Europe investigation or other strands of the Oracle cycle remains unconfirmed. What is settled is enough to act on: a confirmed theft of employee personal, financial, and health data via a known Oracle E-Business Suite zero-day, with a patch that has been available since October 2025.
The CyberSignal Analysis
The facts above come from Estée Lauder's notification and the outlets tracking the Oracle EBS campaign; what follows is The CyberSignal's editorial reading of what defenders should take from them, not new reporting.
Signal 01 — The Long Tail of a Single Zero-Day
The most instructive feature of this disclosure is its timing. The intrusion happened in August 2025, the patch shipped that October, and the confirmed notification did not arrive until July 2026 — nearly a year after the fact. Our reading is that the disclosure cycle for enterprise-software zero-days is measured in quarters, not days: forensic scope-setting, legal review, and staggered notifications mean the true impact of a campaign keeps surfacing long after the initial headlines fade. Defenders tracking their own exposure to CVE-2025-61882 should assume the victim list is still incomplete.
Signal 02 — HR Systems Are High-Value Targets, Not Back Offices
The breach lands in an HR platform, and the stolen data — Social Security and passport numbers, bank details, health information, payroll history — is exactly the concentration attackers optimize against. Our assessment is that organizations still tend to secure customer-facing systems more rigorously than internal HR estates, even though the latter often hold richer per-record data. A flaw in an enterprise module that handles human resources deserves the same patch urgency and monitoring as any internet-facing customer system, because the payoff for an attacker is at least as high.
Signal 03 — Patch Availability Is Not Patch Assurance
CVE-2025-61882 has had a fix since October 2025, yet disclosures tied to it are still arriving in mid-2026. The gap is not the absence of a patch but the difficulty of confirming it landed everywhere. Our takeaway for EBS owners is to treat the campaign as an open verification task: maintain an accurate inventory of every instance and version, know which components are network-reachable, and confirm remediation across the entire estate rather than sampling a representative build. The organizations that close that gap are the ones that stop appearing on leak sites months later.