THE ESTEE LAUDER COMPANIES INC.
ent_019e24258ef1a87fdcbca5d156c58bdb
Disclosures
18
State AG · Leak Site · SEC 8-K · 11 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
150,535
as filed · State AG WA
Leak-site claims
4
unverified actor claims
Identity resolution
- Canonical name
- THE ESTEE LAUDER COMPANIES INC.
- Normalized
- the estee lauder companies— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300VFZ8XJ9NUPU221
- SEC EDGAR CIK
- 0001001250
- Domain
- esteelauder.com
Disclosure history (18)newest first
- Texas State AGas victim2026-07-21
The Estée Lauder Companies based in New York, New York, a business – retail or merchant entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-06-19 and reported on 2026-07-21. 1,959 Texas residents were affected. 31,859 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Government-issued ID number (e.g. passport, state ID card);Financial Information (e.g. account number, credit or debit card number);Medical Information;Other;Date of Birth. Consumers were notified via U.S. Mail.
- New Hampshire State AGas victim2026-07-20
The Estee Lauder Companies notified the NH AG of a cybersecurity incident involving a zero-day vulnerability in Oracle E-Business Suite. An unauthorized third party exploited this vulnerability to access and exfiltrate personal data from August 9-12, 2025. Affected data for ~72 NH residents includes names, SSNs, passport numbers, bank account numbers, health info, and employment records. The company patched the vulnerability, engaged forensic experts, notified law enforcement, and is offering 24 months of credit monitoring.
- California State AGas victim2026-07-17
The Estée Lauder Companies notified the California AG of a data breach involving an unauthorized third party gaining access to their Oracle E-Business Suite HR system on or around August 9, 2025. The incident, discovered via investigation on June 19, 2026, exposed employee personal information including names, addresses, SSNs, passport numbers, bank account numbers, health information, and employment records. The company engaged cybersecurity experts, notified law enforcement, and offered 24 months of identity monitoring via Kroll.
- Washington State AGas victim2026-07-17
The Estée Lauder Companies disclosed a cybersecurity incident involving its Oracle E-Business Suite HR system. Unauthorized access occurred between August 9-12, 2025, and was discovered on June 19, 2026. The breach exposed personal information including names, SSNs, passport numbers, financial account details, health information, and employment records. 2,110 Washington residents were affected. The company engaged forensic experts, notified law enforcement, and provided 24 months of identity monitoring via Kroll.
- Nebraska State AGas victim2026-07-17
The Estee Lauder Companies notified Nebraska AG of a data breach involving its Oracle E-Business Suite HR system. Unauthorized access occurred on or around August 9, 2025. The breach exposed names, SSNs, passport numbers, financial account info, health data, and employment records. The company engaged Kroll for 24 months of identity monitoring and notified law enforcement. Notices were sent on July 17, 2026.
- Massachusetts State AGas victim2026-07-17
The Estee Lauder Companies disclosed a cybersecurity incident involving its Oracle E-Business Suite HR system. An unauthorized third party gained access on or around August 9, 2025, and the breach was discovered on June 19, 2026. Affected data included names, SSNs, passport numbers, financial account info, health info, and employment records. The company engaged forensic experts, notified law enforcement, and provided 24 months of Kroll identity monitoring to affected individuals.
- Vermont State AGas victim2026-07-10
The Estee Lauder Companies reported a data breach to the Vermont Attorney General. The breach was reported to the AGO on 2026-07-10. The reporting organization type is Other Commercial. 7 Vermont residents were affected. Categories of data breached: Social Security Numbers, Financial Account Codes, Credit and Debit Account Info, Government ID Numbers, Health Records.
- Illinois State AGas victim2026-07-01
THE ESTÉE LAUDER COMPANIES filed a data-breach notice with the Illinois Attorney General in July 2026 (case 26-07-1322). The register records the breach as discovered on June 19, 2026. Personal information types reported: financial account number, medical information, passport number, ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- GLOBALLeak Siteas victim2025-11-21
ELCOMPANIES.COM is the official website for The Estée Lauder Companies Inc., a multinational manufacturer and marketer of prestige skincare, makeup, fragrance, and hair care products. The company owns a diverse portfolio of brands, distributed internationally through both digital commerce and retail channels. It was founded in 1946 by Estée Lauder and her husband Joseph Lauder.
- Maine State AGas victim2023-10-19
The Estée Lauder Companies Inc. reported a data breach to the Maine Attorney General, which was discovered on September 20, 2023, and occurred between May 30, 2023, and June 1, 2023. The breach was an external system breach (hacking) that affected one Maine resident, compromising their name and Driver's License or Non-Driver Identification Card Number. The company offered the affected individual two years of complimentary credit monitoring and identity protection services through Kroll.
- Washington State AGas victim2023-10-18
The Estée Lauder Companies Inc. notified Washington AG of a cyberattack involving its third-party vendor Progress Software's MOVEit Transfer solution. Unauthorized access occurred May 30-June 1, 2023. The company discovered the issue on May 31, 2023. Approximately 1,453 Washington residents' names, emails, addresses, and DOBs were accessed. The incident is contained.
- Washington State AGas victim2023-08-31
The Estée Lauder Companies Inc. reported a cybersecurity incident to the Washington AG on August 31, 2023. Unauthorized access occurred around July 11, 2023, affecting approximately 150,535 Washington residents. Consumer data included names, DOBs, and purchase details. Employee data included names, emails, and hashed/clear-text passwords. The company engaged forensic experts and law enforcement.
- FEDERALSEC 8-Kas victim2023-07-19
The Estée Lauder Companies Inc. reported a cybersecurity incident involving an unauthorized third party that gained access to some of the Company's systems; based on the current status of its investigation the Company believes the unauthorized party obtained some data from its systems and is working to understand the nature and scope of that data. The Company took down some of its systems, began an investigation with third-party cybersecurity experts and is coordinating with law enforcement, and states that the incident has caused, and is expected to continue to cause, disruption to parts of its business operations. The filing does not state the data types affected or the number of individuals impacted.
- GLOBALLeak Siteas victim2023-07-19
Estée Lauder | Beauty Products, Skin Care & Makeup
- GLOBALLeak Siteas victim2023-07-18
The Estée Lauder Companies Inc. is an American multinational cosmetics company, a manufacturer and marketer of makeup, skincare, fragrance and hair care products, based in Midtown Manhattan, New York City. It is the second largest cosmetics company in the world after L'Oréal.
- GLOBALLeak Siteas victim2020-06-17
esteelauder.com
- Massachusetts State AGas victim2017-07-14
The Estee Lauder Companies, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-07-14. 2 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2011-07-18
The Estee Lauder Companies, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2011-07-18. 8 Massachusetts residents were affected. The report records the breach type as electronic.
Subsidiary disclosures (3)filed by group companies
◈ These filings were made by or about subsidiaries of THE ESTEE LAUDER COMPANIES INC. — not by THE ESTEE LAUDER COMPANIES INC. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- Massachusetts State AGvia GlamGlow LLC2015-10-13
GlamGlow LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2015-10-13. 33 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGvia GlamGlow LLC2015-10-08
GlamGlow, LLC notified the NH Attorney General of a data breach affecting 2 NH residents. Unauthorized access to glamglowmud.com occurred between Sept 2014 and May 2015, exposing names, addresses, payment card info, and passwords. Notification sent Oct 8, 2015, offering 1 year of credit monitoring.
- California State AGvia GlamGlow LLC2015-10-08
GlamGlow LLC reported unauthorized access to its glamglowmud.com website. The incident occurred in two windows: approximately September 19–21, 2014 and May 12–15, 2015 (mail letter), or approximately May 18, 2014 to May 20, 2015 (email letter). Compromised data included names, addresses, phone numbers, payment card numbers/expiration dates/security codes, email addresses, and account passwords. GlamGlow engaged outside experts, secured the site, and offered one year of free Equifax credit monitoring.