Estée Lauder Confirms Employee Data Stolen in Oracle EBS Zero-Day Attack
Estée Lauder has begun notifying employees that their personal data was lifted from its Oracle E-Business Suite systems last year, confirming what had been an open secret for months.
The breach traces back to early August 2025, when Cl0p started weaponising CVE-2025-61882, a zero-day in Oracle EBS that allowed unauthenticated remote code execution. The group used the flaw to hoover up data from a large number of organisations before a patch arrived in early October. CrowdStrike later pinpointed exploitation beginning on August 9, the same date Estée Lauder was hit.
Cl0p did what Cl0p does. By November, over 100 companies were named on its leak site. By March 2026, Estée Lauder was among a small handful of major firms still refusing to formally acknowledge the impact. Cl0p had already published 870GB of files it claimed came from the cosmetics company, so the silence was awkward at best.
The notification letter, filed with the California Attorney General's Office, says the company's investigation concluded in June that data had indeed been stolen from its EBS instance, which was being used for HR management. The compromised records include names, addresses, dates of birth, Social Security numbers, passport numbers, bank account details, health information, and payroll data. Not a trivial haul.
Affected individuals are being offered 24 months of free identity monitoring. The company says it has reported the breach to law enforcement and taken steps to tighten up its systems.
Estée Lauder has not disclosed how many people are affected. Whether that number is embarrassingly large or they simply prefer opacity is unclear. We have reached out for comment.