Estée Lauder discloses that it suffered a data breach after hackers exploited a vulnerability in Oracle E-Business Suite (EBS), which the company uses for human resources operations. Multiple outlets report that the incident involves the Oracle EBS environment used by Estée Lauder Companies for HR management. According to the company’s disclosure, hackers were able to access and exfiltrate data from the system, including personal information. Reports also indicate the stolen data includes financial and health-related information, though the specific categories and affected fields are described in broad terms across the coverage. The breach is dated to August 2025, but the company only became aware of the issue later and is only now notifying customers. The reporting describes the event as a zero-day or security flaw affecting Oracle EBS, without attributing the attack to a named threat actor. The company’s customer communications focus on informing impacted individuals and describing the nature of the cybersecurity issue and potential exposure resulting from the exploited Oracle vulnerability.