Estée Lauder Companies (ELC) was hit by a data breach targeting the US beauty giant’s HR operations system last year, revealed following an internal investigation.
The breach in August 2025 was tied to the Clinique-owner’s Oracle E-Business Suite (EBS), according to a notice issued by ELC required by California, US, local laws to inform affected individuals and filed with the state’s Attorney General.
This allowed for access to the personal information of certain employees.
This included names, postal and email addresses, dates of birth, Social Security numbers, passport numbers, financial account information (bank account numbers), and health information.
Employment-related information, such as performance evaluations and payroll information, was also affected.
An ELC spokesperson told Cosmetics Business: “In November 2025, The Estée Lauder Companies notified employees of a cybersecurity concern involving a vulnerability in the Oracle E-Business Suite system used for certain human resources management purposes.