CybersecurityJuly 21, 2026· via BleepingComputer

Estée Lauder hit by Oracle flaw, customer data exposed

Estée Lauder hit by Oracle flaw, customer data exposed

Image : BleepingComputer

Cosmetics giant Estée Lauder has disclosed a data breach after attackers exploited a known vulnerability in Oracle E-Business Suite, a platform the company used for human resources operations. The incident exposed customer data, prompting the firm to notify affected individuals.

A familiar flaw resurfaces

The breach stemmed from a security gap in Oracle E-Business Suite, a widely used enterprise resource planning system. Hackers leveraged the flaw to gain unauthorized access to systems handling HR data, including customer information. Oracle has previously addressed similar vulnerabilities, but delays in patching can leave organizations exposed.

Supply chain risk in enterprise tech

The incident underscores the ripple effects of third-party software flaws. Even companies with robust security postures can be compromised if their vendors’ systems are vulnerable. Estée Lauder’s use of Oracle E-Business Suite highlights how interconnected modern business operations are—and how a single weak link can compromise customer trust.

What customers should know

Estée Lauder has begun notifying affected customers and is offering support, including credit monitoring where appropriate. The company has not detailed the full scope of data exposed, but typical HR-related breaches involve names, contact details, or employment records. Customers should remain vigilant for unusual activity and follow any guidance provided by the company.

Why it matters

This breach illustrates the cascading risks of enterprise software vulnerabilities, where a flaw in a widely used HR platform can spill over into customer data. For businesses, it’s a reminder to prioritize timely patching and third-party risk assessments. For customers, it reinforces the importance of monitoring personal data and responding promptly to breach notifications—because even household names aren’t immune to supply-chain-driven cyber threats.


Source: BleepingComputer. AI-assisted editorial synthesis — TechnoExpress.

Read the original source on BleepingComputer →

← Back to home