Beauty Giant's HR Systems Breached for Nearly a Year Before Discovery
Published on 08/02/2026 at 02:53 | Redaktion boerse-global.de
The cosmetics manufacturer Estée Lauder has confirmed that intruders spent more than ten months inside its human resources infrastructure, making off with everything from salary records to medical files. The company only detected the intrusion in mid-June 2026, despite the fact that a security fix for the exploited vulnerability had been available since October 2025.
Unauthorized access first occurred on 9 August 2025, according to the company's disclosure. Investigators did not spot the breach until 19 June 2026 — a gap of over ten months during which attackers had potential run of the firm's HR databases. The exact number of affected employees worldwide has yet to be determined as the inquiry continues.
The entry point was CVE-2025-61882, a known flaw in Oracle's E-Business Suite (EBS), the enterprise software Estée Lauder relies on for personnel administration. Oracle shipped a patch for this vulnerability on 4 October 2025, but it appears the update was never applied to the compromised systems in time. Security researchers have linked the attack to the Cl0p group, a ransomware operation with a track record of large-scale data theft.
When sensitive employee data is exposed, the fallout can extend well beyond IT — into compliance failures that put your entire organisation at risk. A free toolkit with 41 ready-to-use templates and checklists helps you document workplace risks properly and stay on top of your legal duties. Download the free Risk Assessment Toolkit
What the attackers took is substantial. Names, addresses and email addresses were lifted alongside social security numbers, passport details and bank account information. More sensitive still, the haul includes medical records and detailed compensation and performance reviews — categories that carry special legal protections under German employment law. In response, Estée Lauder has arranged for affected staff to receive identity protection services from Kroll, valid for 24 months through the end of October 2026.
The incident adds to a growing list of concerns around Oracle products. At the end of July 2026, the vendor shipped a record-breaking patch batch closing 1,449 vulnerabilities, 410 of them in the E-Business Suite alone. Nine of those flaws carried the maximum CVSS severity rating of 10.0.
Keeping your workplace compliant means staying ahead of risks before they become liabilities. Over 37,000 UK businesses already use this free Health & Safety Toolkit to meet their legal obligations with ready-made risk assessments and checklists. Get the free Health & Safety Toolkit
Meanwhile, the security monitoring organisation Shadowserver has flagged another critical issue: CVE-2026-46817 in Oracle Payments. Active exploitation attempts have been observed since late June 2026, and roughly 950 instances of the software remain exposed to the internet without protection. The advice to operators is straightforward — audit your systems now and install updates before the next wave of data theft begins.
Disclaimer regarding our articles: No investment advice, no buy or sell recommendation. Information on prices, companies, and markets is provided without guarantee; changes are possible at any time. Stock market transactions can lead to substantial losses. Our articles are created and reviewed in whole or in part automatically with the support of AI.
