Enterprise resource planning systems are among the most sensitive and least watched software in a large company. They hold payroll, identity documents and banking details for everyone on staff, and they are frequently exempted from the monitoring applied to customer-facing systems on the grounds that they are internal.
Estée Lauder has reported exploitation of an Oracle E-Business Suite vulnerability dating to August 2025, discovered in June 2026. The data described includes employee Social Security numbers, passport numbers, bank account information and health records.
The Gap Is The Finding
Ten months is longer than the retention period most organisations apply to the log sources that would show ERP access anomalies. By the time a detection of this kind lands, the evidence needed to bound it has often already aged out — which is why disclosures in this pattern describe what was accessible rather than what was taken.
The affected population here is staff, not customers, and that changes the dynamics. Employees cannot take their data elsewhere, are usually informed through an internal channel, and rarely appear in the totals that drive public attention. The exposure is no less complete for that.
We grade this medium. The exploitation route and the field list are consistently reported, but the affected count has not been disclosed and we cannot bound the exposure from public material.
Compiled from public reporting, listed below. The affected population has not been disclosed and we are not estimating one. Corrections: corrections@forensicpost.com.
- Data breach roundup (July 17–23, 2026)Privacy Guides