- Estée Lauder confirms Oracle E‑Business Suite breach from August 2025, only disclosed in June 2026
- Attackers stole extensive personal, financial, health, and employment data from HR management platform
- Breach tied to CVE‑2025‑61882, a critical Oracle EBS RCE flaw exploited across 100+ organizations
If you remember the Oracle E-Business Suite vulnerability that was exploited around October 2025 in numerous attacks, you can now add Estée Lauder to the list of victims.
The cosmetics giant has confirmed having been hit, despite the initial breach happening almost a year ago, following an investigation in mid-June 2026 uncovering the incident.
In a data breach notification letter that is now being sent out, the company said that “on June 19, 2026, we determined through our investigation that, on or around August 9, 2025, an unauthorized third party gained access to the Oracle E-Business Suite system and obtained personal information of certain individuals.”
Latest Videos From
Major remote code execution flaw
Estée Lauder said the platform was used by the holding company “for HR management purposes.”
We don’t know exactly how many people are affected by this incident, but we do know that the attackers obtained full names, postal addresses, email addresses, dates of birth, Social Security numbers (SSN), passport numbers, financial account information (including bank account numbers), health information, and employment information.
This is more than enough data to run highly disruptive and damaging identity theft attacks, and Estée Lauder’s warning is of little help coming almost a year too late.
In early October 2025, cybercriminals started mailing executives at various American organizations, claiming to have stolen sensitive files from their Oracle E-Business Suite systems. At the time, both Oracle and the wider cybersecurity community were not certain if the breaches actually happened, or if this was just a bluff to get the victims to pay a ransom demand.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
However, the claims were soon confirmed, since more than 100 organizations reported falling victim. In early October 2025, Oracle issued an emergency fix to patch CVE-2025-61882, a 9.8/10 (critical) pre-authentication remote code execution (RCE) vulnerability in Oracle EBS.
"This vulnerability is remotely exploitable without authentication, i.e., it may be exploited over a network without the need for a username and password," Oracle said in the advisory. "If successfully exploited, this vulnerability may result in remote code execution."
Via BleepingComputer
The best antivirus for all budgets
Our top picks, based on real-world testing and comparisons
Follow TechRadar on Google News andadd us as a preferred source to get our expert news, reviews, and opinion in your feeds.