
Estée Lauder Customer Information Stolen in Data Breach
The cosmetics company says hackers accessed customer data through a flaw in their HR software system.
Source
BleepingComputer
Original headline: Estée Lauder discloses data breach via Oracle E-Business flaw
Plain-English summary by GetCyberRight. Read the full report at the source above.
Estée Lauder, the company behind cosmetics brands like Clinique, MAC, and La Mer, is notifying customers about a data breach. Hackers exploited a security flaw in Oracle E-Business Suite software that the company used for human resources operations. The breach allowed unauthorized access to customer information stored in their systems.
If you have purchased products from Estée Lauder or its brands, your personal information may have been accessed. This could include your name, contact information, purchase history, and potentially payment details. The company has not specified exactly which customer data was stolen or how many people are affected.
Stay one step ahead of scammers
Weekly cybersecurity briefings for families. No spam, just the threats that matter and what to do about them.
If you have an online account with any Estée Lauder brand, you should assume your information may be at risk.
Take these steps immediately:
- Watch for an official notification from Estée Lauder. Read it carefully to understand what specific information was taken.
- If you used a credit or debit card for purchases, monitor your bank statements closely for any unauthorized charges. Report suspicious activity to your bank right away.
- Change your password on any Estée Lauder brand websites where you have an account. Make sure the new password is unique and not used anywhere else.
- Be alert for phishing emails. Scammers often follow data breaches by sending fake emails pretending to be from the company. Use this as a reminder to practice good security habits for all online shopping. Never reuse passwords across different websites. Consider using a password manager to create and store unique passwords for each site. Check your credit card statements regularly, not just after a breach. The sooner you spot fraud, the easier it is to resolve.
Curated from trusted cybersecurity sources by GetCyberRight
Source: BleepingComputerStay ahead of cyber threats
Get our free weekly digest. Real threats, plain language, what to do about them. No spam, ever.
More articles

Estée Lauder Customer Information Stolen Through Software Vulnerability
The cosmetics company had a security flaw in its employee systems that hackers used to access customer data. If you shop there, here is what to do.
2 min read
Business VPN Security Breach: Steps for Remote Workers and Small Business Owners
Hackers exploited flaws in SonicWall business VPN devices for weeks, installing malware. Remote workers and small businesses using these devices need to take action.
2 min read
Business VPN Devices Attacked With Custom Malware: Is Your Home Network Safe?
SonicWall business VPN devices were targeted by hackers installing malware. Home networks using different equipment are not affected by this attack.
2 min readBusiness Security Flaw Exposed: What Families Working From Home Should Know
A security flaw in business VPN equipment was exploited for weeks before a fix was available. This mainly affects people who work from home using company networks.
2 min read