DataBreachCaseFile.com
Investigation OpenCA AG filing · July 17, 2026

The Estée Lauder Companies Reports Breach to California Regulators

The Estée Lauder Companies has reported a data breach to California authorities concerning an incident discovered on August 9, 2025. The specific details regarding the type of breach and the categories of personal information involved remain unspecified in public filings. The company is currently investigating the incident.

State
CA
Breach date
August 9, 2025
Reported
July 17, 2026

The Estée Lauder Companies, a global leader in prestige beauty products, has formally filed notice of a data incident with regulatory bodies in California. This disclosure indicates that the company identified a security event affecting its systems on August 9, 2025.

The specifics of how the breach occurred, including the method or nature of the unauthorized access, have not been publicly detailed in the available regulatory documents. Similarly, the precise types of personal information compromised during this incident are not specified, with filings referring only to general personal data.

As of the filing date of July 17, 2026, The Estée Lauder Companies has stated that an investigation into the breach is ongoing. The number of individuals potentially affected by this security incident has also not been disclosed in the public record.

Individuals who receive notification about this breach should carefully review the information provided by The Estée Lauder Companies for any specific instructions. It is generally advisable to remain vigilant for any unusual activity involving your personal accounts, such as unexplained statements or communications. Consider monitoring your accounts for suspicious transactions.

While the full scope of the incident is still being investigated, maintaining strong, unique passwords for online accounts and being wary of unsolicited communications, especially those requesting personal details, are general protective measures. All available information regarding this incident is derived from public regulatory filings.

Source: CA Attorney General filing

More CA data breach cases