THE ESTEE LAUDER COMPANIES INC.
bd_2fec812c019f031d · schema v1 · pii pii-v1
Full breach record for THE ESTEE LAUDER COMPANIES INC. →5 incidents on fileThe Estée Lauder Companies notified the California AG of a data breach involving an unauthorized third party gaining access to their Oracle E-Business Suite HR system on or around August 9, 2025. The incident, discovered via investigation on June 19, 2026, exposed employee personal information including names, addresses, SSNs, passport numbers, bank account numbers, health information, and employment records. The company engaged cybersecurity experts, notified law enforcement, and offered 24 months of identity monitoring via Kroll.
J jump to incidentP pin to compareR raw source
Incident timeline
Aug 9, 2025
Begins
Jul 17, 2026
Filed
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Sitecl0pbd_43a79f8803ec83502025-11-21 · +237dVerified
Regulatory filings (7) · sorted by filing gap
- Washington State AGbd_609ad332bd2107932026-07-17Verified
- Nebraska State AGbd_6c3036d8fedc23172026-07-17Verified
- Massachusetts State AGbd_ed3611601cbbcae42026-07-17Verified
- New Hampshire State AGbd_0591fad0aab37df12026-07-20 · +3dVerified
Show 3 more filings ↓Show fewer ↑up to 16d gap
- Texas State AGbd_addb107ce7f347662026-07-21 · +4dVerified
- Vermont State AGbd_eccf3e0cae9b9b662026-07-10 · +7dVerified
- Illinois State AGbd_fea9064666f821a32026-07-01 · +16dCandidate
Filing propagation · 8 filings · 8 states
View merged incident ↗Pattern: first filing Jul 1 (IL), last Jul 21 (TX) — a 20-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.