Estée Lauder, a leading cosmetics company, is in the process of notifying its employees about a significant data breach that occurred last year. This breach exploited a zero-day vulnerability in Oracle's E-Business Suite, identified as CVE-2025-61882, which allowed unauthorized remote code execution. The breach was initiated by the notorious Cl0p cybercrime group in early August 2025. This vulnerability facilitated the exfiltration of sensitive information from multiple organizations.
In March 2026, Estée Lauder was among the last major firms to disclose the impact of this cyberattack, following reports that Cl0p had released 870GB of archived data allegedly taken from the company. The compromised data included personal information such as names, addresses, dates of birth, Social Security numbers, and sensitive employment-related data. The company has assured affected individuals of 24 months of free identity monitoring services and has urged them to be cautious about any suspicious communications.
Estée Lauder has reported this incident to law enforcement and is actively working to bolster its cybersecurity measures. Although the exact number of affected individuals remains undisclosed, the company is committed to transparency and protection as it navigates this breach. SecurityWeek has reached out for further details and will provide updates as they become available.


