The Estée Lauder Companies Data Breach

The Estée Lauder Companies filed a data breach notification with the California Attorney General’s office, referencing incident dates of 08/09/2025 and 08/12/2025. The official notification document is a scanned image, so no machine-readable text could be pulled from it for this summary. Because of that, we can’t confirm from the filing itself how the breach happened, and the attack vector is listed as unknown until a readable version of the notice becomes available.

The filing does not include a stated number of affected individuals or a clear description of exactly who received notice. What we do know is that the company reported the incident to California regulators, which generally means at least one California resident was affected. If you received a letter directly from Estée Lauder, that letter should contain the specific details about your situation that this public filing does not.

What information was exposed?
  • The specific types of personal information involved were not disclosed in the readable portion of this filing.
  • If you received a direct letter from the company, check it closely — it should list exactly which of your data elements were involved.

Because the readable filing does not mention any offer of free credit monitoring or identity protection services, we can’t confirm whether Estée Lauder is providing this to affected individuals. Check any letter you received directly for this information, since companies often include enrollment instructions and deadlines in the individual notification even when they aren’t visible in the public regulatory filing.

What should you do now?
  • Watch your email, mail, and phone for any direct notification from Estée Lauder that names the specific data types involved and any protections offered.
  • Review your bank and credit card statements regularly for charges you don’t recognize, even if you’re not sure financial data was involved.
  • Be cautious of unexpected emails, texts, or calls claiming to be from Estée Lauder — verify any request for personal information through the company’s official channels before responding.
  • Consider signing up for a service like Aura or LifeLock, which can alert you if your information appears elsewhere, especially useful when the exact scope of a breach isn’t yet clear.
  • Use unique, strong passwords for any accounts tied to the company, and enable two-factor authentication where it’s offered.
  • Check your credit reports periodically at annualcreditreport.com, and consider a fraud alert or credit freeze if you later learn sensitive identifiers like your Social Security number were involved.

Leave a Comment