
Estée Lauder Customer Information Stolen Through Software Vulnerability
The cosmetics company had a security flaw in its employee systems that hackers used to access customer data. If you shop there, here is what to do.
Source
BleepingComputer
Original headline: Estée Lauder discloses data breach via Oracle E-Business flaw
Plain-English summary by GetCyberRight. Read the full report at the source above.
Estée Lauder announced that hackers exploited a security vulnerability in Oracle E-Business Suite software used for human resources operations. The cosmetics company is now notifying customers that their personal information was accessed during this breach. The flaw in the Oracle software gave hackers an entry point into systems that contained customer data.
If you have purchased products from Estée Lauder, its website, or related brands, your information may have been exposed. This could include your name, email address, shipping address, and possibly payment information depending on what the company stored in the affected systems. Estée Lauder should be sending direct notification to affected customers, but you should not wait for that notification to take action.
Stay one step ahead of scammers
Weekly cybersecurity briefings for families. No spam, just the threats that matter and what to do about them.
Take these steps right away to protect yourself. First, change your password on the Estée Lauder website and any other shopping sites where you used the same password. Second, monitor your credit card and bank statements closely for any unauthorized charges. If you see anything suspicious, contact your bank immediately. Third, watch your email for phishing attempts. Scammers often follow data breaches by sending fake emails pretending to be from the company. Fourth, if you receive a notification letter from Estée Lauder, read it carefully for specific details about what information was exposed and any identity protection services they may offer. For ongoing protection, use different passwords for different shopping websites. Consider using a password manager to keep track of unique passwords. Enable account alerts from your credit card company so you receive notifications about every transaction. Be skeptical of any emails asking you to click links or provide personal information, even if they appear to come from companies you do business with. Type website addresses directly into your browser instead of clicking email links.
Curated from trusted cybersecurity sources by GetCyberRight
Source: BleepingComputerStay ahead of cyber threats
Get our free weekly digest. Real threats, plain language, what to do about them. No spam, ever.
More articles

Estée Lauder Customer Information Stolen in Data Breach
The cosmetics company says hackers accessed customer data through a flaw in their HR software system.
2 min read
Business VPN Security Breach: Steps for Remote Workers and Small Business Owners
Hackers exploited flaws in SonicWall business VPN devices for weeks, installing malware. Remote workers and small businesses using these devices need to take action.
2 min read
Business VPN Devices Attacked With Custom Malware: Is Your Home Network Safe?
SonicWall business VPN devices were targeted by hackers installing malware. Home networks using different equipment are not affected by this attack.
2 min readBusiness Security Flaw Exposed: What Families Working From Home Should Know
A security flaw in business VPN equipment was exploited for weeks before a fix was available. This mainly affects people who work from home using company networks.
2 min read