What happened?
Not the kind of glamour news anyone wanted: Estée Lauder says attackers got into one of its HR systems and walked out with sensitive data. The intruders accessed the companys Oracle E-Business Suite HR environment around August 9, 2025, and the issue was identified during an investigation concluded on June 19, 2026.
Although the company didnt spoon-feed every technical detail, the timing matches a well-known campaign that abused a critical E-Business Suite vulnerability (tracked as a 2025 EBS zero-day) which let attackers bypass authentication and run code remotely through the BI Publisher integration. Criminal groups were actively exploiting that hole in mid-2025.
What was exposed and what to do
Estée Lauders notification says certain people had data stolen. Heres the neat and unhelpful list of personal goodies those crooks might now have:
- Full names
- Postal addresses
- Email addresses
- Dates of birth
- Social Security numbers (SSNs)
- Passport numbers
- Bank account and other financial information
- Health-related information
- Employment details, including payroll and performance notes
The company is offering complimentary identity monitoring for recipients of the notice and recommends watching for unusual activity. If youre one of the potentially affected people, consider freezing your credit, enabling multi-factor authentication everywhere you can, and keeping a close eye on financial statements and tax filings. Also be VERY suspicious of unexpected emails or calls asking for detailsthats classic follow-up phishing fodder.
For security teams and admins: patching and hardening EBS instances should be top priority, especially the BI Publisher integration component if you run those versions. Regularly test your detection controls and incident playbooks so an intrusion doesnt linger like a bad lipstick stain.
Estée Lauder has been hit by related incidents in the past, so this is an unwelcome repeat performance for the brand. The takeaways are dull but useful: keep systems patched, limit needless access to HR data, and treat identity protection like hygiene rather than an optional spa day.