All Breaches
August 9, 2025 Verified Sensitive Record Consumer Goods

Estée Lauder 2025 Data Breach

The Estée Lauder 2025 data breach resulted from unauthorized access to an Oracle E-Business Suite system used by The Estée Lauder Companies for human-resources management. According to the company's official notice, a third party entered the system around August 9, 2025 and obtained personal information belonging to certain individuals. The company determined through its investigation on June 19, 2026 that data had been taken.

Estée Lauder confirmed the event in a notification letter dated July 17, 2026. Because no total number of affected people was published, this record presents the count as unknown. The incident primarily concerns human-resources data, so recipients may be employees, former employees, or others with an employment relationship; it does not establish that ordinary cosmetics customers were automatically affected.

What Information Was Affected?

The affected data varied by person and included names, postal and email addresses, dates of birth, Social security numbers, and passport numbers. Bank-account numbers, health information, and employment records such as performance evaluations and payroll history could also appear in the obtained files. The data classes in this entry are limited to the fields that the company explicitly named in its notice.

The company did not say that every affected person had every listed field exposed. Full payment-card numbers, passwords, and online-store order history were not among the types described in the notice and are not added to this record. The combination of identity, financial, health, and employment information nevertheless raises the risk of identity theft, new-account fraud, targeted scams, and social engineering aimed at workers.

The Oracle E-Business Suite Vulnerability

The company said the incident involved a vulnerability in the Oracle E-Business Suite system used for HR, but its notification did not name a CVE or identify the attacker. Security researchers observed that the access date overlaps a broad 2025 data-theft campaign against Oracle EBS installations in which several flaws, including CVE-2025-61882, were exploited.

That timing does not prove that the group known as Cl0p was responsible for the Estée Lauder event. This record therefore separates the company-confirmed Oracle EBS vulnerability and data access from the unconfirmed context about a particular actor or CVE. Although a flaw in a vendor product was involved, the affected installation supported Estée Lauder's HR operations and the company issued the breach notification.

The Company's Response

Estée Lauder said that after learning of the issue it launched an investigation with leading outside cybersecurity specialists to determine the nature, scope, and affected information. It notified law enforcement and implemented additional safeguards intended to protect the system. The letter does not state that the intruder retained continuing access or that the information was published publicly.

The company offered eligible US recipients 24 months of free identity monitoring, fraud consultation, and identity-theft restoration through Kroll. The enrollment deadline in the official letter is October 31, 2026. Recipients should use the membership number from their genuine individual notice and should not submit personal details through an enrollment link found in search results or an unexpected message.

Identity and Financial Protection

People whose Social Security number or birth date was affected should inspect reports at all three nationwide credit bureaus and consider a free security freeze to reduce new-credit fraud. A freeze must be placed separately with each bureau. If you find an unfamiliar account, inquiry, or address change, dispute it in writing with the relevant organization, retain the records, and follow the identity-theft reporting process.

If a bank-account number was involved, contact the financial institution using its known official number to assess whether the account should be replaced and enable transaction alerts. Seek passport guidance from the official issuing authority, and do not send an image or number to someone who requests it by email. Regularly reviewing account statements, payroll deposits, and tax records provides stronger continuing protection than a one-time credit check.

Scams Using Health and Employment Data

Health and employment records can help a scammer impersonate human resources, a payroll provider, a health plan, or an executive. A message containing an accurate performance detail, job title, or salary history may still be fraudulent. Verify any request for a bank-account change, urgent transfer, document upload, or one-time code through a known company channel rather than the contact information in the message.

Criminals may imitate incident notices with themes such as “complete your Kroll enrollment” or “verify your payroll account.” Do not trust the sender's display name; inspect the domain, notice date, and recipient-specific reference. End unexpected calls that request a password, complete Social Security number, bank login, or verification code, then contact HR Services or the financial institution yourself.

How to Interpret This LeakData Record

The zero shown for this record does not mean that nobody was affected; it means Estée Lauder did not publish a verified total number of people or records. No individual-level rows were imported into LeakData, so the absence of an email-search match cannot prove that you were unaffected. People who receive a direct company notice should rely on the data types listed in their own letter.

This entry covers unauthorized access around August 9, 2025; the June 2026 investigative determination and July 2026 notification are separate dates. Other past Estée Lauder cyber incidents and other companies in the Oracle EBS campaign are not part of this record. If authorities later publish an affected-person count, a definitive CVE, or attacker attribution, the content should be revised only to reflect that newly verified evidence.

0
Affected Accounts
9
Data Types
Low
Severity
Yes
Verification

Exposed Data Types

9
Names
Postal addresses
Email addresses
Dates of birth
Social security numbers
Passport numbers
Bank account numbers
Health information
Employment records

Additional Information

Added DateJuly 26, 2026
Breach DateAugust 9, 2025
Domainelcompanies.com
SourceWebsite hack
Last Content UpdateJuly 26, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information