The Estée Lauder Companies Data Breach Investigation

Data Breach Blog

Data Breach

The Estée Lauder Companies Data Breach Investigation

Almeida Law Group Calendar Icon

Date of data breach:

July 17, 2026

by: Almeida Law Group

Almeida Law Group is investigating a data breach at The Estée Lauder Companies. The breach occurred on August 9th, 2025. If you were affected, contact Almeida Law Group.

About The Estée Lauder Companies

The Estée Lauder Companies Inc. is an American multinational cosmetics company and the second largest cosmetics company in the world after L’Oréal. Headquartered at 767 Fifth Avenue in New York, NY, the company manufactures, markets, and distributes skin care, makeup, fragrance, and hair care products sold in approximately 150 countries under brands including Estée Lauder, Clinique, MAC, La Mer, Jo Malone London, Aveda, Bobbi Brown, Too Faced, and Tom Ford Beauty, among others. As of June 2025, the company employed approximately 57,000 people worldwide. The breach involved employee and HR data, including highly sensitive categories such as Social Security numbers, passport numbers, and financial and health information.

What Happened?

The Estée Lauder Companies was listed in a California Attorney General sample breach notice filed on July 17th, 2026. According to the company’s breach notice, an unauthorized third party exploited a vulnerability in the Oracle E-Business Suite system that The Estée Lauder Companies uses for HR management. The company determined on June 19th, 2026 that the intrusion occurred on or around August 9th, 2025—nearly ten months before the breach was discovered. The affected information included names, postal addresses, email addresses, dates of birth, Social Security numbers, passport numbers, financial account information (bank account numbers), health information, and employment-related information such as performance evaluations and payroll data. The specific data involved varied by individual. The company notified law enforcement and engaged outside cybersecurity experts to investigate. Kroll identity monitoring is being offered at no cost for 24 months, with an enrollment deadline of October 31st, 2026.

In November 2025, Z2Data reported that the Cl0p ransomware group claimed to have exploited a zero-day vulnerability in Oracle’s E-Business Suite affecting dozens of large corporations, and that Cl0p was allegedly seeking payouts from companies said to include The Estée Lauder Companies. This is an attacker-side claim and has not been independently confirmed by The Estée Lauder Companies as connected to the breach notice described here, though the attack vector and timeframe are consistent. The company also has a prior breach history: in July 2023, two separate ransomware groups—Cl0p (via the MOVEit Transfer zero-day) and ALPHV/BlackCat—each claimed to have exfiltrated approximately 130GB of data. The Estée Lauder Companies confirmed a cybersecurity incident at that time involving unauthorized access and data exfiltration. A Canadian class action related to the 2023 incidents reached a proposed settlement of CAD $1.515 million, with a court hearing scheduled for June 3rd, 2026; the company denied all allegations and liability in that case. No class action has been filed yet for the current 2025–2026 incident, though attorneys are actively investigating and soliciting affected individuals for a potential claim.

Key Facts at a Glance

  • Company or Organization: The Estée Lauder Companies
  • Industry: Prestige beauty / cosmetics / consumer goods
  • Location: 767 Fifth Avenue, New York, NY 10153
  • Incident type: Unauthorized access via Oracle E-Business Suite vulnerability
  • Date of breach: August 9th, 2025
  • Date breach discovered: June 19th, 2026
  • Date of consumer notification: July 17th, 2026
  • Identity theft protection offered: 24 months of Kroll identity monitoring at no cost
  • Enrollment deadline: October 31st, 2026
  • Prior breach: July 2023 Cl0p/MOVEit and ALPHV/BlackCat ransomware incidents; Canadian class action settled for CAD $1.515 million (proposed)
  • Litigation status: No class action filed yet for this incident; attorneys are actively investigating a potential class action
  • Source: California Attorney General sample breach notice (https://oag.ca.gov/ecrime/databreach/reports/sb24-626688); Z2Data (https://www.z2data.com/insights/everything-you-need-to-know-about-the-oracle-data-breach/); ClassAction.org (https://www.classaction.org/data-breach-lawsuits/the-estee-lauder-companies-july-2026); BleepingComputer (https://www.bleepingcomputer.com/news/security/est-e-lauder-beauty-giant-breached-by-two-ransomware-gangs/); Lex Group (https://www.lexgroup.ca/classaction/estee-lauder-data-breach-class-action/)

What Should You Do?

If you received a notice from The Estée Lauder Companies, enroll in the free Kroll identity monitoring at https://enroll.krollmonitoring.com before the October 31st, 2026 deadline using the membership number provided in your letter. Because Social Security numbers, passport numbers, and financial account information were among the data exposed, consider placing a fraud alert or credit freeze with the three major credit bureaus—Equifax, Experian, and TransUnion—to help prevent new accounts from being opened in your name. Monitor your bank and financial accounts closely for any unauthorized transactions, and review your free annual credit reports at AnnualCreditReport.com or by calling 1-877-322-8228. Because health information was also involved in this breach, review any Explanation of Benefits statements from your health insurer and check your medical records for services you did not receive. If you notice anything suspicious, report it at IdentityTheft.gov, which can help you create a personalized recovery plan.

Your Legal Rights

If your personal or health information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.

Were You a Victim of a Data Breach?

"*" indicates required fields

By clicking the SEND button and submitting this form, I consent to receive communications from Almeida Law Group LLC and their co-counsel by phone call, email, and/or SMS regarding this matter and other potential legal matters. I understand that message and data rates may apply and that consent to such contact is not required for use of these services. Message frequency varies. Reply STOP to opt-out and HELP for help. I also agree to the Privacy Policy. I understand that my information may be shared with advertising partners to deliver targeted advertisements and optimize outreach efforts. I confirm that I am at least 18 years old. I have read and understand the disclaimer above. I agree my use of this site and the information provided here is not intended to create and does not create an attorney client relationship with the Almeida Law Group and/or attorneys employed by the Firm. No attorney client relationship is intended or created unless and until an engagement agreement is signed by all relevant parties. The contents of this site constitute attorney advertising and not legal advice; therefore you should not act or rely upon any information contained herein, and should always seek the advice of an attorney.

Resourceful. Resilient. Relentless.

Contact us today to get the justice you and your family deserve.