Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Jul 22, 2026 · 7 min read

Estée Lauder Sat on an Oracle Breach for 10 Months

Clop hackers exploited a critical Oracle E-Business Suite flaw to reach Estée Lauder's HR systems on August 9, 2025. The company didn't confirm the breach until June 19, 2026, and didn't tell affected employees until July 20 — the longest confirmed detection gap yet in a campaign that has already hit more than 100 companies.

The Estée Lauder Companies has confirmed a data breach that exposed Social Security numbers, passport numbers, bank account details, and health information belonging to employees, after hackers linked to the Clop extortion gang exploited a critical flaw in Oracle E-Business Suite. According to breach notification letters reported by BleepingComputer, the intrusion began on August 9, 2025. Estée Lauder says it did not determine that unauthorized access had occurred until June 19, 2026, and did not notify affected individuals until July 20, 2026, nearly a full year after the attackers first got in.

That gap sets Estée Lauder apart even within a campaign already known for slow disclosures. The flaw attackers used, CVE-2025-61882, was exploited against more than 100 organizations starting in the same week of August 2025, and several of those victims took months to confirm what happened. None took as long as Estée Lauder.

Key Takeaways

  • Estée Lauder confirmed on July 20, 2026 that Clop hackers exploited CVE-2025-61882 in Oracle E-Business Suite to access HR systems as far back as August 9, 2025.
  • The company did not determine that unauthorized access had occurred until June 19, 2026, a gap of roughly 10 months between exploitation and detection.
  • Exposed data includes Social Security numbers, passport numbers, bank account information, health records, and payroll and performance data for employees.
  • Oracle patched CVE-2025-61882 on October 4, 2025, five months before Estée Lauder says it even knew it had been compromised.
  • This is the second time Clop has breached Estée Lauder; the company was also caught up in the gang's 2023 MOVEit Transfer campaign.
Blank document folders in a dim office filing cabinet drawer with a subtle digital overlay, representing the Estée Lauder Oracle E-Business Suite data breach

How Did Hackers Get Into Estée Lauder's HR Systems?

Attackers exploited CVE-2025-61882, a critical flaw in the Concurrent Processing component of Oracle E-Business Suite, to remotely execute code without needing valid credentials first. The bug carries a near maximum severity score of 9.8 out of 10 and reaches through EBS's BI Publisher Integration, according to the National Vulnerability Database entry for CVE-2025-61882, which lists Oracle EBS versions 12.2.3 through 12.2.14 as affected.

CrowdStrike's research traces the campaign back to a dark web listing that offered an EBS exploit for roughly $70,000 in June 2025, weeks before Clop began using it against live targets. Oracle issued an emergency patch on October 4, 2025, and CISA added the flaw to its Known Exploited Vulnerabilities catalog two days later. Estée Lauder's own systems had already been sitting open to the exploit for close to two months by the time that patch existed.

Why Did It Take 10 Months to Confirm the Breach?

Estée Lauder has not explained, in its public notice, what triggered the discovery on June 19, 2026, or why nearly a year passed between the intrusion and that finding. The company's own language describes the June date as when it "determined" unauthorized access had occurred, phrasing that suggests the activity sat unnoticed in logs or backups rather than being flagged by active monitoring in real time.

The gap is unusual even by the standards of recent corporate breaches. EY disclosed a client data breach roughly three months after detecting it, a delay that drew scrutiny from plaintiffs' lawyers. Estée Lauder's detection to disclosure window was shorter, about one month, but its exploitation to detection window was more than three times longer than EY's entire delay. Different failure, same result: employees and clients went roughly a year without knowing their most sensitive records were already out of the company's control.

What Data Did the Attackers Steal?

The stolen records go well beyond the usual name and Social Security number combination. According to TechRadar's reporting on the notification letters, exposed data includes full names, home addresses, dates of birth, Social Security numbers, passport numbers, bank account numbers, health information, and payroll and performance records. Passport numbers are a notable addition. They point to Estée Lauder's international workforce, since passport data typically enters HR systems through visa sponsorship, relocation, or global mobility programs rather than routine domestic payroll.

Estée Lauder is offering 24 months of complimentary identity monitoring through Kroll to those affected. The company has not disclosed how many employees or former employees were included in the exposure, and it is not the first time Clop has gotten into its systems. Estée Lauder was also swept up in Clop's 2023 MOVEit Transfer campaign, one of the largest mass exploitation events on record. Two breaches from the same extortion group within three years suggests the gap this time was not simply bad luck.

One CVE, Dozens of Companies, Wildly Different Timelines

Estée Lauder is the latest confirmed victim in a campaign that has already touched more than 100 organizations, and the spread between how quickly each one came forward is striking. Madison Square Garden disclosed its Oracle EBS breach on February 26, 2026, roughly six and a half months after its own intrusion began. Michelin confirmed it was hit by the same campaign on March 11, 2026. Estée Lauder's confirmation came on July 20, 2026, nearly a full year after the exploitation began.

That widening spread matters more than any single company's timeline. A single unpatched flaw, exploited in one concentrated window in August 2025, is still producing fresh breach notifications almost a year later. If organizations are still confirming exposure this far out, the true victim count from this one campaign is probably still incomplete, and other companies running old EBS deployments may not yet know what their own logs from last August would show.

Why Email Users Should Care

A breach like this one rarely stays contained to the stolen file itself. Names, dates of birth, Social Security numbers, and payroll details are exactly the ingredients scammers use to craft convincing, personalized phishing emails aimed at the same employees whose data was exposed, often sent to their work Gmail or Outlook inbox months after the original theft. A message that references a real payroll detail or benefits enrollment date is far more likely to get a click than a generic scam.

HR and payroll staff are a favorite target for this kind of follow up fraud, since a single successful email can redirect an entire paycheck or trigger a fraudulent W-2 request. That risk is compounding as attackers lean on automation: AI tools now write the large majority of phishing emails hitting inboxes, which means breached employee data can be turned into a tailored lure within minutes of a leak surfacing, not weeks. Anyone notified about the Estée Lauder breach should expect follow up emails that reference their real personal details, and should treat every unexpected HR, benefits, or payroll message with more suspicion than usual for the next year, not just the next few weeks.

What Should Affected Employees Do Now?

Estée Lauder's identity monitoring offer is a reasonable starting point, but a few additional steps matter more for anyone whose Social Security number, passport number, or health data was involved:

  • Place a credit freeze with all three major credit bureaus, which blocks new accounts from being opened even with a stolen Social Security number. The FTC's identitytheft.gov walks through the process step by step.
  • Watch for phishing emails that reference real payroll, benefits, or HR details, since stolen data is routinely reused to make follow up scams convincing.
  • Enroll in the Kroll monitoring Estée Lauder is offering, but treat it as a backstop rather than a substitute for a credit freeze.
  • Contact your health insurer if you notice unfamiliar claims, since exposed health information can be used for medical identity theft that a credit freeze won't catch.
  • Report any suspicious activity involving your passport number, since a stolen passport number combined with other identity details can support fraudulent travel document applications.

Estée Lauder has closed the specific access point Clop used, but it still has not explained why a breach that began in August 2025 sat undetected until the middle of 2026. Until it does, the safest assumption for anyone who worked at or with the company during that window is that their personal information has already changed hands more than once.

Sources: BleepingComputer, NIST National Vulnerability Database, CrowdStrike, and TechRadar.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.