Estée Lauder has begun notifying employees that their personal data was stolen from its Oracle E-Business Suite (EBS) system in August 2025, when the Cl0p cybercrime group exploited a zero-day vulnerability (CVE-2025-61882) enabling unauthenticated remote code execution. The compromised data includes sensitive information such as Social Security numbers, passport numbers, bank account details, health information, and payroll data. The company is offering affected individuals 24 months of free identity monitoring and has notified law enforcement, though it has not disclosed how many people were impacted.