The Estée Lauder Companies (Oracle) Data Breach Notice (Washington Attorney General): What Was Exposed & What To Do
The Estée Lauder Companies (Oracle) disclosed a data breach on July 17, 2026, affecting 2,110 individuals whose personal information was exposed after an incident that occurred on August 9, 2025. The compromised data included names, Social Security numbers, financial and banking information, full dates of birth, and passport numbers. Individuals are advised to check their status and take protective steps if their information was involved.
The Estée Lauder Companies notified Washington residents of a data breach in a filing reported to the Washington State Attorney General on July 17, 2026. The notice states that the incident itself occurred on August 09, 2025, and that 2,110 people were affected. Among the information listed as exposed are names, Social Security numbers, financial and banking information, full dates of birth, passport numbers, medical information, and other data.
The disclosure comes through a state regulator filing rather than a detailed public technical report, so many operational specifics remain limited. For those whose records may be involved, the combination of identity, financial, and medical data raises concrete risks of fraud and misuse that warrant careful attention.
Inside the incident
According to the Washington Attorney General filing, The Estée Lauder Companies (Oracle) experienced a data breach dated August 09, 2025. The company later provided notice to affected Washington residents, with the filing itself reported on July 17, 2026. The notice identifies 2,110 people as affected and enumerates the categories of information exposed: name, Social Security number, financial and banking information, full date of birth, passport number, medical information, and other data.
Public detail beyond these points is limited. The filing does not describe the technical method of intrusion, the systems involved, how long unauthorized access lasted, or whether data was exfiltrated in bulk or selectively. No dollar amounts, file counts, or forensic findings appear in the disclosed summary. Attribution to any specific threat actor is absent. What is established is the organization’s formal notification, the incident date, the headcount of affected individuals in the filing, and the listed data types.
How a breach like this happens
Incidents that expose employee, customer, or partner records held in enterprise systems often follow recognizable patterns, though none can be confirmed for this case. Attackers commonly gain an initial foothold through stolen or guessed credentials, phishing messages that harvest logins, unpatched software vulnerabilities, or misconfigured cloud and database services. Once inside, they may move laterally, locate repositories containing identity and financial files, and copy data for later use or sale.
In environments that rely on large enterprise platforms—sometimes including third-party or legacy database systems—access controls, logging, and segmentation determine how far an intrusion can spread. When monitoring is incomplete or privileged accounts are over-permissioned, detection can lag. Organizations typically discover such events through internal alerts, unusual outbound traffic, law-enforcement tips, or external notifications. After containment, they assess what records were accessible, identify affected individuals, and issue legally required notices. None of these general steps is asserted as the sequence here; they simply describe how breaches of comparable scope often unfold when detailed technical disclosures are not yet public.
About The Estée Lauder Companies (Oracle)
The Estée Lauder Companies is a major global manufacturer and marketer of prestige beauty, skincare, makeup, fragrance, and hair-care products. It operates numerous brands sold through department stores, specialty retailers, e-commerce channels, and company-owned outlets worldwide. Like other large consumer-goods firms, it maintains extensive records on employees, contractors, customers, loyalty-program members, and business partners.
The parenthetical reference to Oracle in the breach notice indicates involvement of Oracle-related systems or services in the environment where the incident occurred, though the filing does not elaborate on the precise architecture. Organizations of this scale routinely hold human-resources files, payroll and benefits data, customer purchase and payment information, and, in some cases, health-related or travel documents tied to benefits or international work. A breach affecting even a few thousand individuals can therefore touch sensitive personal identifiers that are difficult to change and valuable to criminals. The consequential nature of the event stems less from brand visibility alone than from the sensitivity of the data categories listed in the notice.
The information in question
The Washington filing explicitly names the following as exposed: name, Social Security number, financial and banking information, full date of birth, passport number, medical information, and other. These categories are stated in the company’s notice to the Attorney General and are therefore treated as confirmed for the affected population of 2,110 people referenced in that filing.
“Other” is not further defined in the available summary, so its exact contents remain undisclosed. No additional data elements—such as email addresses, phone numbers, driver’s license numbers, or specific account numbers—are itemized beyond the listed types. Readers should rely only on the categories the organization itself reported rather than assuming a broader inventory.
Why it matters
When names are paired with Social Security numbers, dates of birth, and passport numbers, the material can support identity theft, fraudulent credit applications, tax-refund fraud, and the creation of synthetic identities. Financial and banking information increases the risk of unauthorized account access or payment fraud. Medical information can be misused for insurance fraud or targeted social-engineering attempts that reference real health details to appear legitimate.
For the organization, the incident carries regulatory notification duties, potential credit-monitoring costs, reputational effects, and the operational burden of investigation and remediation. For affected individuals, the harm is personal and lasting: Social Security numbers and passport data cannot be casually replaced, and misuse may surface months or years later. Because the filing covers Washington residents specifically, people outside that group cannot assume they were or were not included without further notice from the company. The concrete risk is the long-term exposure of high-value personal identifiers rather than any single dramatic event.
What to do if you're exposed
If you believe you may be among those notified, begin by reading any letter or email from The Estée Lauder Companies carefully and retaining it. Place a fraud alert or credit freeze with the major credit bureaus, and review credit reports and bank and card statements for unfamiliar activity. Consider requesting a new Social Security card or monitoring tax transcripts if your SSN was involved, and follow official guidance on passport replacement if that document number was exposed. Be alert to phishing that references the breach or your medical or financial details.
Document any suspicious contacts and report confirmed fraud to the Federal Trade Commission and local law enforcement as appropriate. You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets, which can help you prioritize further monitoring.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Chelan County, WA Data Breach Notice (Washington Attorney General)Kovack Financial, LLC Data Breach Notice (Washington Attorney General)Golden Opportunities And Local Support, LLC Data Breach Notice (Washington Attorney General)American Addiction Centers Data Breach Notice (Washington Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.