
The Estée Lauder Companies Inc., a global prestige beauty company headquartered in New York City, disclosed a data breach that occurred in August 2025. So far, 1,959 residents of Texas were impacted and 336 of Massachusetts.
An unauthorized third party exploited a vulnerability in the Oracle E-Business Suite system. The Estée Lauder Companies uses this system for human resources management purposes.
The unauthorized access began on or around Aug. 9, 2025, and continued through Aug. 12, 2025.
On June 19, 2026, an investigation into the incident determined that the unauthorized third party had gained access to the system and obtained personal information of certain individuals.
The types of personal information exposed included names, postal addresses, email addresses, dates of birth, Social Security numbers, passport numbers, financial account information (including bank account numbers), health information and employment-related information such as performance evaluations and payroll data.
The breach was disclosed to the attorneys general offices of California and Vermont. Affected individuasls were notified by notification letters on July 17, 2026.
The company has arranged identity monitoring services for affected individuals. The Estée Lauder Companies engaged the services of Kroll to provide 24 months of free identity monitoring.
Affected individuals can enroll through Kroll's website using the unique membership number included in their notification letter. The deadline to activate these services is Oct. 31, 2026.
The company also recommended that individuals remain alert for suspicious emails, text messages and phone calls, since contact information was among the data exposed in the breach.
For individuals with questions, the company has set up a dedicated phone line through HR Services. The numbers are 1-928-212-9893 and 1-844-472-8352, available Monday through Friday from 9 a.m. to 5 p.m. EST.








.webp)
.webp)
.webp)

.webp)
.webp)
.webp)
.webp)