THE ESTEE LAUDER COMPANIES INC.
bd_e073c9131d35a119 · schema v1 · pii pii-v1
Full breach record for THE ESTEE LAUDER COMPANIES INC. →5 incidents on fileThe Estée Lauder Companies Inc. reported a cybersecurity incident to the Washington AG on August 31, 2023. Unauthorized access occurred around July 11, 2023, affecting approximately 150,535 Washington residents. Consumer data included names, DOBs, and purchase details. Employee data included names, emails, and hashed/clear-text passwords. The company engaged forensic experts and law enforcement.
J jump to incidentP pin to compareR raw source
Incident timeline
Jul 11, 2023
Begins
Jul 11, 2023
Discovered
Aug 31, 2023
Filed
vs. sector median
on median
Linked disclosures
Why this link?Ransomware claims (2)
- Leak Sitecl0pbd_a40c32bc2fe400a42023-07-19 · +43dVerified
- Leak Sitealphvbd_222b45685f496a632023-07-18 · +44dVerified by operator
Regulatory filings (3) · sorted by filing gap
- SEC 8-Kbd_029686f81d388b6c2023-07-19 · +43dVerified by operator
- Washington State AGbd_6f12f71586422ae62023-10-18 · +48dCandidate
- Maine State AGbd_a9dea68820cb2a8e2023-10-19 · +49dVerified by operator
Filing propagation · 4 filings · 2 states
View merged incident ↗Pattern: first filing Jul 19, last Oct 19 (ME) — a 92-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.