THE ESTEE LAUDER COMPANIES INC.
bd_6c3036d8fedc2317 · schema v1 · pii pii-v1
Full breach record for THE ESTEE LAUDER COMPANIES INC. →5 incidents on fileThe Estee Lauder Companies notified Nebraska AG of a data breach involving its Oracle E-Business Suite HR system. Unauthorized access occurred on or around August 9, 2025. The breach exposed names, SSNs, passport numbers, financial account info, health data, and employment records. The company engaged Kroll for 24 months of identity monitoring and notified law enforcement. Notices were sent on July 17, 2026.
J jump to incidentP pin to compareR raw source
Incident timeline
Aug 9, 2025
Begins
Jul 17, 2026
Filed
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Sitecl0pbd_43a79f8803ec83502025-11-21 · +237dVerified
Regulatory filings (7) · sorted by filing gap
- California State AGbd_2fec812c019f031d2026-07-17Verified
- Washington State AGbd_609ad332bd2107932026-07-17Verified
- Massachusetts State AGbd_ed3611601cbbcae42026-07-17Verified
- New Hampshire State AGbd_0591fad0aab37df12026-07-20 · +3dVerified
Show 3 more filings ↓Show fewer ↑up to 16d gap
- Texas State AGbd_addb107ce7f347662026-07-21 · +4dVerified
- Vermont State AGbd_eccf3e0cae9b9b662026-07-10 · +7dVerified
- Illinois State AGbd_fea9064666f821a32026-07-01 · +16dCandidate
Filing propagation · 8 filings · 8 states
View merged incident ↗Pattern: first filing Jul 1 (IL), last Jul 21 (TX) — a 20-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.