A letter dated 17 July about a Saturday in August
The letter went out from 767 Fifth Avenue in New York on 17 July 2026. It is four pages, plainly written, and it tells the reader that on 19 June 2026 The Estee Lauder Companies determined through its investigation that, on or around 9 August 2025, an unauthorized third party gained access to the Oracle E-Business Suite system and obtained personal information of certain individuals. The system, the letter says, is used by the company for HR management purposes.
Read the two dates together. The access happened on a Saturday in August 2025. The company established that it had happened on a Friday in June 2026. Between those two facts sit 314 days in which the data was gone and nobody knew. The letter is not evasive about this. It states both dates in the same sentence, which is more candour than most notifications manage.
Estee Lauder did what a competent responder does once it knew: launched an investigation with outside experts, notified law enforcement, put additional safeguards on the system, and offered 24 months of identity monitoring through Kroll with an enrolment deadline of 31 October 2026. None of that is the interesting part. The interesting part is the 314 days, and what they were made of.
Patch speed was never the variable here
The fix did not exist yet. The intrusion aligns with the mass-exploitation campaign against Oracle E-Business Suite through CVE-2025-61882, later attributed to the Clop extortion group. Oracle released the fix on 4 October 2025. Count back to 9 August 2025 and you get 56 days. The attacker was inside the building eight weeks before the vendor shipped the lock.
This matters because of what most boards are shown. The security slide in a quarterly pack is usually a patch-compliance figure: percentage of critical patches applied within the SLA. It is a real number and it measures a real discipline. It also had no bearing whatsoever on this outcome. A company at 100 percent patch compliance on a 14-day SLA would have been breached on exactly the same Saturday, because on that Saturday there was nothing to apply.
Yes, but the vulnerability was reachable. Oracle described the flaw as allowing unauthenticated attackers with network access to remotely execute code over HTTP, affecting E-Business Suite versions 12.2.3 through 12.2.14. That is the decision that was actually available in advance: not how fast you patch, but whether an HR module inside an ERP should have been answering HTTP requests from a network segment an unauthenticated stranger could reach. Nobody makes that decision during an incident. It is made years earlier, usually by whoever wanted the integration to work by Friday.
What the HR module was actually holding
The letter lists what the third party obtained: names, postal and email addresses, dates of birth, Social Security numbers, passport numbers, financial account information in the form of bank account numbers, health information, and employment-related information such as performance evaluation and payroll data. The letter notes that the impacted data varied for each affected individual.
That is not an HR system's reputation. Ask most executives to name the crown jewels and they will say the customer database, the source code, the finance ledger. The HR module rarely makes the list, because it is filed mentally as an administrative tool. In practice it is the single place in most companies where identity documents, bank details and health records sit in one schema, indexed by employee number, retained for a decade because employment law says so.
The asymmetry is worth stating plainly. A customer record leaks an email address and a purchase history. This record leaks the documents a person uses to prove they exist. You can reissue a password. Reissuing a passport number takes a government.
The 314 days were a discovery problem, not a response problem
Split the timeline into the three intervals it actually contains. From 9 August 2025 to 19 June 2026 is 314 days of undetected loss. From 19 June to the letter of 17 July 2026 is 28 days of investigation, scoping and legal review. And before all of it sits the architecture decision that put a reachable ERP module in front of the internet.
Only two of those three are within your gift. The 28 days are process, and process is tunable: you can decide today who drafts the notification, who signs it, and what the legal review costs in days. The architecture is capital and time, and it is where the leverage actually sits. The 314 days are the residue. They are what happens when a system is important enough to hold passports and unimportant enough that nobody watches its logs.
The bottom line. Detection is not a tool you buy, it is a consequence of what you decided to monitor, and monitoring follows classification. Estee Lauder did not fail to react. It reacted within days of knowing. The failure, if the word applies at all, happened on whatever quiet afternoon someone classified an HR module as low criticality and moved on. That decision was reversible for ten months and free to reverse for most of them.
Three questions to put to your own ERP this week
First, the inventory question. List every system holding identity documents, bank details or health data that your asset register does not currently classify as critical. In most European companies the answer includes at least one HR or payroll module, and often a legacy expenses tool. That list is your real crown-jewel register, and it is usually shorter than people fear and different from what they expected.
Second, the reachability question. For each of those systems, who can reach it without authenticating, and from where. Not who is supposed to. Who can. Under GDPR the controller obligation attaches to that data regardless of which internal department owns the budget, and a 72-hour notification clock does not care that the module was somebody else's project.
Third, the evidence question. If someone reached that system today, what would tell you, and how long would the telling take. If the honest answer is a vendor advisory or a call from law enforcement, then your detection interval for that system is measured in the same units as Estee Lauder's, and you have known that since you finished reading this sentence.
Read next: OpenSSL Fixed It in June Without a CVE | One Commissioner Stalled a 2 Gigawatt Campus



