HackingVulnerability ExploitEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICEMPLOYMENTMediumContained
ESTEE LAUDER COMPANIES INC
bd_2fec812c019f031d · schema v1 · pii pii-v1
Full breach record for ESTEE LAUDER COMPANIES INC →The Estée Lauder Companies notified the California AG of a data breach involving an unauthorized third party gaining access to their Oracle E-Business Suite HR system on or around August 9, 2025. The incident, discovered via investigation on June 19, 2026, exposed employee personal information including names, addresses, SSNs, passport numbers, bank account numbers, health information, and employment records. The company engaged cybersecurity experts, notified law enforcement, and offered 24 months of identity monitoring via Kroll.
California clockConsumers notified Jul 17, 2026 → AG copy submitted Jul 17, 20260d ✓ CA AG copy ≤15d
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_addb107ce7f34766Texas State AGfiled 2026-07-21(4d gap)Verified
- bd_eccf3e0cae9b9b66Vermont State AGfiled 2026-07-10(7d gap)Verified
- bd_ed3611601cbbcae4Massachusetts State AGfiled 2026-07-01(16d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-626688
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 17, 2026
- Raw hash
- c4633a098140b0aee113ad3d06432f7117c4f60d71aa790a25515659a2591b06
Reporting entity
- Name
- ESTEE LAUDER COMPANIES INCnorm: estee lauder companies
- Domain
- esteelauder.com
Victim entity
- Name
- ESTEE LAUDER COMPANIES INCnorm: estee lauder companies
- Domain
- esteelauder.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Jul 17, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICEMPLOYMENT
- Attack vector
- Unknown
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- CA AG copy ≤15d · 0d
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status California Consumers notified: Jul 17, 2026→ AG copy submitted: Jul 17, 20260d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.