The cosmetics giant Estée Lauder is notifying staff of a data breach after hackers slipped into the Oracle software it uses to run human resources. BleepingComputer first reported the disclosure.

Nearly a year in the dark

The timeline is the uncomfortable part. According to the company’s notification letter, an intruder reached its Oracle E-Business Suite system on or around 9 August 2025. Estée Lauder says it only confirmed the theft on 19 June 2026. The letters went out on 17 July. That is close to a year of exposure.

The haul is broad. The stolen records include full names, postal and email addresses, dates of birth, social-security numbers, passport numbers, bank account details, health information, and employment data such as payroll and performance reviews. The company is offering affected staff two years of free identity monitoring through Kroll.

One flaw, a hundred victims

Estée Lauder does not name the bug in its letter. The dates, though, line up with a mass-exploitation campaign against Oracle E-Business Suite through a flaw known as CVE-2025-61882.

The 💜 of EU tech

The latest rumblings from the EU tech scene, a story from our wise ol' founder Boris, and some questionable AI art. It's free, every week, in your inbox. Sign up now!

That flaw is serious. It is a critical, pre-authentication vulnerability that lets an attacker run code on the system with no username or password. Oracle patched it on 4 October 2025. By then the Clop ransomware gang had already been exploiting it as a zero-day since early August, according to security researchers.

Estée Lauder is far from alone. More than 100 organisations were caught in the same wave. Named victims include Harvard, the University of Pennsylvania, The Washington Post, Logitech, and Cox Enterprises.

A familiar pattern

The case shows a soft spot the industry keeps hitting: trusted third-party business software. Attackers do not need to break down the front door if they can walk through a vendor’s. One unpatched flaw in a shared platform turns into dozens of data breaches at once.

Estée Lauder has been here before.

Clop also hit the company in 2023, that time through a zero-day in the MOVEit file-transfer tool. The bigger worry is the gap. A breach in August that surfaces the following summer gives criminals a long, quiet head start, and gives victims almost no warning before their data is already in play.

As TechRadar noted, a warning this late is of limited help. It is also a preview of how these extortion campaigns will keep playing out.