Skip to main content
    Estée Lauder Customer Information Stolen Through Software Vulnerability
    Action Needed
    2 min read

    Estée Lauder Customer Information Stolen Through Software Vulnerability

    The cosmetics company had a security flaw in its employee systems that hackers used to access customer data. If you shop there, here is what to do.

    Source

    BleepingComputer

    Original headline: Estée Lauder discloses data breach via Oracle E-Business flaw

    Plain-English summary by GetCyberRight. Read the full report at the source above.

    Published Monday, July 20, 2026Updated Tuesday, July 21, 20262 min read
    Share:

    Estée Lauder announced that hackers exploited a security vulnerability in Oracle E-Business Suite software used for human resources operations. The cosmetics company is now notifying customers that their personal information was accessed during this breach. The flaw in the Oracle software gave hackers an entry point into systems that contained customer data.

    If you have purchased products from Estée Lauder, its website, or related brands, your information may have been exposed. This could include your name, email address, shipping address, and possibly payment information depending on what the company stored in the affected systems. Estée Lauder should be sending direct notification to affected customers, but you should not wait for that notification to take action.

    Stay one step ahead of scammers

    Weekly cybersecurity briefings for families. No spam, just the threats that matter and what to do about them.

    Take these steps right away to protect yourself. First, change your password on the Estée Lauder website and any other shopping sites where you used the same password. Second, monitor your credit card and bank statements closely for any unauthorized charges. If you see anything suspicious, contact your bank immediately. Third, watch your email for phishing attempts. Scammers often follow data breaches by sending fake emails pretending to be from the company. Fourth, if you receive a notification letter from Estée Lauder, read it carefully for specific details about what information was exposed and any identity protection services they may offer. For ongoing protection, use different passwords for different shopping websites. Consider using a password manager to keep track of unique passwords. Enable account alerts from your credit card company so you receive notifications about every transaction. Be skeptical of any emails asking you to click links or provide personal information, even if they appear to come from companies you do business with. Type website addresses directly into your browser instead of clicking email links.

    Protect Yourself

    Use our Breach Monitor to check if you're affected and take action.

    Found this useful?

    Share it with someone who could use a heads-up.

    Share:

    Curated from trusted cybersecurity sources by GetCyberRight

    Source: BleepingComputer

    Discussion

    0

    Sign in to join the discussion.

    Stay ahead of cyber threats

    Get our free weekly digest. Real threats, plain language, what to do about them. No spam, ever.