HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICEMPLOYMENTMediumContained
ESTEE LAUDER COMPANIES INC
bd_ed3611601cbbcae4 · schema v1 · pii pii-v1
Full breach record for ESTEE LAUDER COMPANIES INC →The Estee Lauder Companies disclosed a cybersecurity incident involving its Oracle E-Business Suite HR system. An unauthorized third party gained access on or around August 9, 2025, and the breach was discovered on June 19, 2026. Affected data included names, SSNs, passport numbers, financial account info, health info, and employment records. The company engaged forensic experts, notified law enforcement, and provided 24 months of Kroll identity monitoring to affected individuals.
Massachusetts clock✓ MA AG ≤30d12 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_eccf3e0cae9b9b66Vermont State AGfiled 2026-07-10(9d gap)Verified
- bd_2fec812c019f031dCalifornia State AGfiled 2026-07-17(16d gap)Candidate
- bd_addb107ce7f34766Texas State AGfiled 2026-07-21(20d gap)Verified
Source provenance
- Source URL
- https://www.mass.gov/doc/2026-1179-the-estee-lauder-companies/download
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 1, 2026
- Raw hash
- f181170a6a240034010e7c0b19cad7d6d1f44290f652a29e3ee28ec8117aa1c2
Reporting entity
- Name
- ESTEE LAUDER COMPANIES INCnorm: estee lauder companies
- Domain
- esteelauder.com
Victim entity
- Name
- ESTEE LAUDER COMPANIES INCnorm: estee lauder companies
- Domain
- esteelauder.com
Incident
- Discovered
- Jun 19, 2026
- Materiality determined
- —
- Notification sent
- Jul 17, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICEMPLOYMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- notified law enforcement authorities
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 12 days(12 days from discovery to filing)
- Compliance flags
- MA AG ≤30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.