THE WHAT? The Estée Lauder Firms has disclosed that worker information was compromised following a cyberattack concentrating on Oracle’s E-Enterprise Suite (EBS), prompting the corporate to inform present and former workers whose data might have been affected.
THE DETAILS The corporate mentioned an unauthorised third get together gained entry to its Oracle EBS system in August 2025, exposing private data together with names, contact particulars, dates of start, Social Safety numbers, passport data, financial institution particulars, well being data and inside HR information. Estée Lauder launched an investigation with exterior cybersecurity specialists, notified legislation enforcement and applied further safety measures. The breach is believed to be linked to a wider marketing campaign exploiting vulnerabilities in Oracle EBS, reportedly related to the Cl0p ransomware group, though Estée Lauder has not confirmed the id of the attackers. The corporate is providing affected workers id monitoring and fraud safety companies.
THE WHY? The incident highlights the rising cybersecurity dangers dealing with international magnificence corporations that depend on third-party enterprise software program, underlining the significance of provide chain safety, speedy incident response and sturdy safety of delicate worker and enterprise information.
Supply: Pc Weekly
