Nothing says "beauty industry" like a data breach that got quietly aged in a barrel for ten months before anyone told the people whose Social Security numbers were involved. Estée Lauder just confirmed hackers were rifling through employee HR files since last August — and the company only found out this June.
A Zero-Day That Would Not Quit
Estée Lauder disclosed that an unauthorized party accessed its Oracle E-Business Suite HR system around August 9, 2025, exploiting CVE-2025-61882 — a critical zero-day in Oracle EBS that let attackers run code remotely without so much as a password. The company says it only confirmed the intrusion on June 19, 2026.
The haul is the bad kind of comprehensive: names, addresses, dates of birth, Social Security numbers, passport numbers, bank account details, health records, and even performance reviews and payroll history. Estée Lauder is offering affected employees 24 months of identity monitoring through Kroll.
The Clop Gang's Favorite Punching Bag
This isn't an isolated slip-up — CVE-2025-61882 was mass-exploited across dozens of companies in a campaign widely attributed to the Clop ransomware gang, the same crew behind waves of MOVEit and GoAnywhere breaches. Estée Lauder just joins a long, unglamorous list of household names caught by the same hole.
The real story here isn't the vulnerability — patched software gets exploited before patches land all the time. It's the ten-month gap between breach and disclosure, a reminder that "we take security seriously" often translates to "we found out a while after you'd have wanted us to."
Moisturizer can turn back the clock on fine lines; it apparently can't do much for breach notification timelines.
Source: Help Net Security