Estée Lauder discloses data breach tied to Oracle EBS vulnerability
Cosmetics giant Estée Lauder has revealed a data breach linked to an unpatched vulnerability in Oracle E-Business Suite (EBS), which was used for internal HR operations. The breach occurred on or around August 9, 2025, when an unauthorized party accessed the system and stole sensitive personal and financial information from some individuals. The incident is connected to the exploitation of CVE-2025-61882, a critical flaw allowing remote code execution without authentication. Oracle issued patches for this vulnerability on October 4, 2025, but many organizations remained vulnerable during the active exploitation period. Estée Lauder has engaged cybersecurity experts, informed authorities, and is providing two years of free identity monitoring to affected individuals.