Makeup giant Estée Lauder says hackers accessed Social Security numbers
Attackers got the data via Oracle E-Business Suite.

- Estée Lauder disclosed a breach exposing employee Social Security numbers, bank details, health information, and employment records.
- The company discovered the incident on June 19, 2026, but attackers may have accessed systems from August 2025.
- Attackers exploited an Oracle E-Business Suite vulnerability affecting Estée Lauder’s HR management environment.
- Estée Lauder is offering 24 months of identity monitoring as exposed data raises identity theft and phishing risks.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Estée Lauder disclosed a data breach that exposed employees’ Social Security Numbers and bank information.
Recently, the cosmetics giant revealed the cyber incident, saying an unauthorized third party gained access to an Oracle E-Business Suite environment used by the company.
In the notice, which was sent to affected individuals, Estée Lauder said the compromised Oracle system contained a broad range of personal and employment records.
Depending on the individual, the exposed information may include:
- Names
- Postal and email addresses
- Dates of birth
- Social Security numbers
- Passport numbers
- Bank account information
- Health information
- Payroll information
- Employment records, including evaluation of performance
As stated, the company discovered the cybersecurity incident on June 19th, 2026. However, the company's internal investigation showed that attackers were there much earlier – indicators suggest they may have accessed the system around August 9th, 2025.
The notification letter does not reveal the scope of the attack and how many people may be affected.
Oracle HR platform targeted
According to the company, the attackers exploited a vulnerability in Oracle E-Business Suite. Estée Lauder said the affected Oracle environment was used for HR management purposes.
After identifying the issue, the company launched an investigation with the assistance of external cybersecurity experts and notified law enforcement.
"We have put in place additional safeguards to further protect the system," the company said in the notification letter.
Estée Lauder is one of the world's largest cosmetics companies, generating approximately $14.3 billion in annual revenue.
Headquartered in New York, the company employs around 57,000 people and sells its products through online channels and retail stores worldwide.
Stay alert for phishing scams
The compromised details include personal identifiers, financial account details, and employment records. The combination of exposed details puts individuals at a higher risk of identity theft and targeted fraud.
For example, cybercriminals can craft highly convincing phishing attacks impersonating employers or financial institutions. Victims receiving an email with their bank account data, Social Security number, and payroll information will be less likely to spot the fraud.
To mitigate the fallout from the attack, Estée Lauder said it will offer 24 months of complimentary identity monitoring through Kroll. The company also urges affected individuals to monitor their bank accounts for any suspicious activity.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Estée Lauder is a victim of a broader campaign against Oracle
Estée Lauder has not disclosed how attackers gained access, but the reported breach occurred during a period of mass exploitation of the Oracle E-Business Suite vulnerability tracked as CVE-2025-61882.
The vulnerability has a near maximum base severity score of 9.8 out of 10. It lies within the BI Publisher Integration component of the Oracle Concurrent Processing product and allows attackers to remotely execute code without a username or password.
Check if your data has been leaked
“An easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks of this vulnerability can result in takeover of Oracle Concurrent Processing,” the description on the National Vulnerability Database reads.
In 2025, Google threat researchers revealed that the Cl0p ransomware gang had exploited the vulnerability to target multiple organizations worldwide.
Among the victims were Harvard University, Logitech, and the Jeff Bezos-owned newspaper The Washington Post.
Cl0p previously compromised hundreds of companies using the MOVEit zero-day vulnerability.