The Estée Lauder Companies (Oracle) Data Breach Notice (Washington Attorney General)
If you were named in this filing, here’s what the filing says was exposed, and what to do about it.
The Estée Lauder Companies (Oracle) notified Washington residents of a data breach in a filing reported to the Washington State Attorney General on July 17, 2026, and the notice lists name, social security number, financial & banking information, full date of birth, passport number, medical information and other among the information exposed. The filing puts the incident itself on August 09, 2025.
The Estée Lauder Companies has notified 2,110 Washington residents that their personal information was exposed in an incident that occurred on August 09, 2025. The company filed the notice with the Washington Attorney General on July 17, 2026 — 342 days later.
If you received a letter from Estée Lauder or its Oracle subsidiary, this filing is about you. The absence of a letter usually means your records were not part of the group that was exposed, though anyone who has moved since August 2025 should contact the company directly to confirm their status.
A Social Security Number, Passport Number, and Date of Birth Are Now in Someone Else’s Hands
The filing lists seven categories of information involved in the incident: name, Social Security number, financial and banking information, full date of birth, passport number, medical information, and other. No passwords were exposed.
That combination of identifiers is particularly valuable to identity thieves. A name paired with a Social Security number and date of birth is the standard set required to open new credit accounts, file fraudulent tax returns, or apply for government benefits in someone else’s name. A passport number adds the ability to impersonate you at borders or with financial institutions that accept international ID.
Medical information increases the risk further. It can be used to file false insurance claims or to build a more convincing synthetic identity. Unlike a credit card, none of these pieces of information can be cancelled or reissued on demand. Once they are out, they remain usable for years.
What the 342-Day Gap Actually Means for You
The breach happened on August 09, 2025. The formal notification to Washington authorities arrived nearly eleven and a half months later. This interval is the single most striking fact in the record. While notification deadlines vary by state and depend on when an investigation concludes, the length of time between the incident and the filing is long enough to matter to anyone whose data was included.
During that period the exposed information could have circulated. You cannot know whether it has already been used, but you can assume the risk window is already open and act accordingly.
Why Financial and Banking Details Make This Breach Different
The presence of financial and banking information alongside government identifiers creates immediate fraud risk. Thieves can combine these details to attempt account takeovers, wire fraudulent transfers, or open new lines of credit using your clean credit history.
Medical information adds another permanent layer. Once health records are linked to your identity in criminal databases, they become a tool for long-term impersonation in healthcare systems. This is not data that expires.
The Records Belong to Patients and Customers
The 2,110 people named in this filing are individuals whose information Estée Lauder or its Oracle systems held. The company is required by law to notify affected Washington residents directly, typically by mail. That letter remains the most reliable way to determine whether you were included.
If you have not received correspondence from Estée Lauder about this matter, it is likely your information was not part of the exposed set. However, if you have changed addresses since the August 2025 incident date, the letter may have gone to an old address. In that case, contact the company to verify your status.
What Remains Under Your Control
While you cannot change your Social Security number, date of birth, or passport number, you can still limit what criminals do with them. The key is rapid, targeted monitoring and proactive fraud controls rather than reactive fixes after damage appears.
Place a freeze on your credit files with all three major bureaus. This prevents new accounts from being opened in your name even if someone presents your exact identifiers. The freeze does not affect your existing accounts or credit score.
Monitor your Explanation of Benefits statements from every health insurer you use. False claims often appear here first. Dispute anything you do not recognize immediately.
Review bank and credit card statements weekly for the next six months. Look for small test charges that criminals sometimes use before attempting larger fraud.
Consider placing an extended fraud alert on your credit reports. This requires lenders to take extra steps to verify your identity before issuing new credit.
The Value of These Records Does Not Fade
Unlike passwords or credit card numbers that can be rotated, the identifiers exposed here have permanent value on the criminal market. A Social Security number combined with a date of birth and passport number does not lose relevance after a few months. The 342-day gap between the incident and notification only increases the chance that the data has already been packaged and sold.
This is why the specific mix of data matters more than the total number of people affected. The filing does not reveal how the information was accessed or whether it involved an active Oracle system or an abandoned instance. Those details remain unknown. What the record does make clear is exactly which categories left the company’s control.
Focus on the exposures you can still influence. Credit freezes, careful monitoring of financial and medical statements, and direct confirmation with Estée Lauder if you suspect a letter may have missed you are the practical steps available today.
The letter is the definitive answer. If it arrives, treat the contents as fact. If it never comes and you have not moved since August 2025, the record suggests you were not among the 2,110 affected Washington residents.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on The Estée Lauder Companies (Oracle).
- Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
- Tell your bank before you do anything else. Account and routing details are the fastest-moving of the fields in this notice. Call the number on the back of your card rather than any number in an email, and ask them to watch the account and reissue the card.
- Read your next explanation of benefits. Medical identity theft shows up as treatment you did not receive, billed to your policy and written into your medical record. Your insurer can flag the policy, and you can request an accounting of disclosures from the provider named here.
- Report the passport number. A compromised passport number can be reported to the US State Department, which will flag it. Replacing it is neither quick nor free, so report it before you need to travel.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
Report details & sourcing
Related breaches
Trezor Shipping Data Breach — 13,689 Hardware Wallet Buyers, Home Addresses Included
ShipMonk, a logistics provider used by Trezor, was breached through a vulnerability in the third-par…
Match Group (Tinder, Hinge, OkCupid) Data Breach — January 2026
ShinyHunters claimed responsibility for stealing over 10 million Match Group user records in early 2…
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…