THE ESTEE LAUDER COMPANIES INC.
bd_6f12f71586422ae6 · schema v1 · pii pii-v1
Full breach record for THE ESTEE LAUDER COMPANIES INC. →5 incidents on fileThe Estée Lauder Companies Inc. notified Washington AG of a cyberattack involving its third-party vendor Progress Software's MOVEit Transfer solution. Unauthorized access occurred May 30-June 1, 2023. The company discovered the issue on May 31, 2023. Approximately 1,453 Washington residents' names, emails, addresses, and DOBs were accessed. The incident is contained.
J jump to incidentP pin to compareR raw source
Incident timeline
May 30, 2023
Begins
May 31, 2023
Discovered
Oct 18, 2023
Filed
vs. sector median
+12 wks slower
Linked disclosures
Why this link?Ransomware claims (2)
- Leak Sitecl0pbd_a40c32bc2fe400a42023-07-19 · +91dVerified
- Leak Sitealphvbd_222b45685f496a632023-07-18 · +92dVerified by operator
Regulatory filings (3) · sorted by filing gap
- Maine State AGbd_a9dea68820cb2a8e2023-10-19 · +1dVerified by operator
- Washington State AGbd_e073c9131d35a1192023-08-31 · +48dVerified by operator
- SEC 8-Kbd_029686f81d388b6c2023-07-19 · +91dVerified by operator
Filing propagation · 4 filings · 2 states
View merged incident ↗Pattern: first filing Jul 19, last Oct 19 (ME) — a 92-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.