Skip to content
cisonews.net

Incident · 8-K Item 8.01

Estée Lauder reports an unauthorized third party accessed some systems and obtained data

Compiled 2026-09-27 from public records. By the cisonews.net Desk.

The Estée Lauder Companies disclosed on July 19, 2023 that an unauthorized third party had gained access to some of its systems and obtained data. The company proactively took down some systems, and it said the incident had disrupted, and would keep disrupting, parts of its business.

What the company said

The 8-K attached a July 18 press release. On data, the release was preliminary.

The release said the company was coordinating with law enforcement and working with outside cybersecurity experts, and that remediation, including restoring systems and services, was under way.

What the filing omits

The disclosure gives no detection date, does not describe the type of data or the type of attack, and makes no statement about financial materiality. This log holds no follow-up 8-K for the incident.

Sources

  1. 2023-07-19 · AThe Estée Lauder Companies Inc., Form 8-K (SEC EDGAR), published July 19, 2023
  2. 2023-07-18 · AThe Estée Lauder Companies Inc., press release (Exhibit 99.1, SEC EDGAR), published July 18, 2023

Tier A: the organization itself, a regulator or SEC EDGAR. Tier B: established press. Each fact on this page carries its supporting passage in the page source.

See an error? Corrections are made on the page and logged on the corrections page. Send them through contact.