Clustered 4 filings across 4 jurisdictions · filing window Jul 1, 2026 → Jul 21, 2026. View entity profile → Other incidents for this victim →
incident inc_5a19a090f5d245d5 · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Identity (basic) · Government ID · Financial account
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
CA MA TX VT
all State AG
Earliest sighting first · deep chronology in Litigation Timeline
Aug 9, 2025
When the intrusion reportedly occurred, per the linked filings
Jun 19, 2026
Reported by MASSACHUSETTS AG, TEXAS AG filings
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
The Estee Lauder Companies disclosed a cybersecurity incident involving its Oracle E-Business Suite HR system. An unauthorized third party gained access on or around August 9, 2025, and the breach was discovered on June 19, 2026. Affected data included names, SSNs, passport numbers, financial account info, health info, and employment records. The company engaged forensic experts, notified law enforcement, and provided 24 months of Kroll identity monitoring to affected individuals.
The Estee Lauder Companies reported a data breach to the Vermont Attorney General. The breach was reported to the AGO on 2026-07-10. The reporting organization type is Other Commercial. 7 Vermont residents were affected. Categories of data breached: Social Security Numbers, Financial Account Codes, Credit and Debit Account Info, Government ID Numbers, Health Records.
The Estée Lauder Companies notified the California AG of a data breach involving an unauthorized third party gaining access to their Oracle E-Business Suite HR system on or around August 9, 2025. The incident, discovered via investigation on June 19, 2026, exposed employee personal information including names, addresses, SSNs, passport numbers, bank account numbers, health information, and employment records. The company engaged cybersecurity experts, notified law enforcement, and offered 24 months of identity monitoring via Kroll.
The Estée Lauder Companies based in New York, New York, a business – retail or merchant entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-06-19 and reported on 2026-07-21. 1,959 Texas residents were affected. 31,859 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Government-issued ID number (e.g. passport, state ID card);Financial Information (e.g. account number, credit or debit card number);Medical Information;Other;Date of Birth. Consumers were notified via U.S. Mail.
Affected (this filing): 1,959