THE ESTEE LAUDER COMPANIES INC.
bd_609ad332bd210793 · schema v1 · pii pii-v1
Full breach record for THE ESTEE LAUDER COMPANIES INC. →5 incidents on fileThe Estée Lauder Companies disclosed a cybersecurity incident involving its Oracle E-Business Suite HR system. Unauthorized access occurred between August 9-12, 2025, and was discovered on June 19, 2026. The breach exposed personal information including names, SSNs, passport numbers, financial account details, health information, and employment records. 2,110 Washington residents were affected. The company engaged forensic experts, notified law enforcement, and provided 24 months of identity monitoring via Kroll.
J jump to incidentP pin to compareR raw source
Incident timeline
Aug 9, 2025
Begins
Jun 19, 2026
Discovered
Jul 17, 2026
Filed
vs. sector median
4 wks faster
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Sitecl0pbd_43a79f8803ec83502025-11-21 · +237dVerified
Regulatory filings (7) · sorted by filing gap
- California State AGbd_2fec812c019f031d2026-07-17Verified
- Nebraska State AGbd_6c3036d8fedc23172026-07-17Verified
- Massachusetts State AGbd_ed3611601cbbcae42026-07-17Verified
- New Hampshire State AGbd_0591fad0aab37df12026-07-20 · +3dVerified
Show 3 more filings ↓Show fewer ↑up to 16d gap
- Texas State AGbd_addb107ce7f347662026-07-21 · +4dVerified
- Vermont State AGbd_eccf3e0cae9b9b662026-07-10 · +7dVerified
- Illinois State AGbd_fea9064666f821a32026-07-01 · +16dCandidate
Filing propagation · 8 filings · 8 states
View merged incident ↗Pattern: first filing Jul 1 (IL), last Jul 21 (TX) — a 20-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.