← Back to Tech & Science

Estée Lauder Discloses Data Breach Affecting Employee Records via Oracle Flaw

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

NEW YORK — The Estée Lauder Companies Inc. disclosed on Sunday that hackers exploited a vulnerability in its human resources software to access personal employee data, marking a significant security incident for the global cosmetics giant.

The breach was detected after unauthorized actors gained entry to the company's HR systems by targeting a known flaw within Oracle E-Business Suite, an enterprise resource planning platform widely used for workforce management. The intruders accessed sensitive information belonging to current and former employees, though the company has not yet specified if customer data or financial records were compromised.

Estée Lauder confirmed that the incident occurred over a period leading up to Sunday's announcement. In response to the discovery, the cosmetics manufacturer immediately engaged cybersecurity experts to contain the breach, secure its networks, and investigate the full scope of the intrusion. The company stated it is cooperating with relevant law enforcement agencies as part of the ongoing investigation.

The compromised data reportedly includes names, social security numbers, dates of birth, and home addresses for affected individuals. In some cases, employment history and salary information may also have been accessed. Estée Lauder emphasized that no evidence suggests credit card details or bank account information were taken during this specific incident.

Oracle E-Business Suite has faced scrutiny in recent years regarding security patches and configuration vulnerabilities across various industries. The exploitation of such flaws often allows attackers to bypass standard authentication measures, granting them administrative access to internal databases without triggering immediate alarms.

The company notified affected employees directly via email or postal mail, providing guidance on credit monitoring services and identity theft protection resources at no cost for a specified period. Estée Lauder also established a dedicated support center to assist individuals with questions regarding the breach.

While the initial containment measures appear successful, investigators are still determining whether the attackers exfiltrated data beyond what has been identified or if they maintained persistent access within the network after being detected. The full extent of the damage and any potential long-term implications for employee privacy remain under review.

Estée Lauder shares this vulnerability with many large corporations that rely on legacy enterprise systems, raising questions about the speed at which security patches are applied across global supply chains. As the investigation continues, the company has pledged to implement additional safeguards to prevent similar incidents in the future and is working closely with Oracle to address the underlying software defect.

The incident underscores the growing risks faced by multinational corporations as cybercriminals increasingly target HR systems for high-value personal data used in identity fraud schemes.

Discussion

0 / 2000