If you were affected, free legal review is available — no obligation.
Learn how to participate in the class action and what compensation you may be entitled to.
Join the Class Action →Use our verification tool to confirm your letter matches this official AG filing.
Verify My Notice LetterThis case file references a public filing made with the state filing in TX. This website is not affiliated with, endorsed by, or operated by any state government agency.
The Estée Lauder Companies was the subject of a data breach notification filed with the TX Attorney General. The AG filing was recorded on July 21, 2026. The breach or discovery date reported in the filing is August 9, 2025.
From the AG filing description
The Estée Lauder Companies stands as a global leader in the prestige beauty and cosmetics industry, manufacturing and distributing high-end skincare, makeup, fragrance, and hair care products through an extensive network of iconic brands, e-commerce platforms, and brick-and-mortar retail channels. To support its vast direct-to-consumer operations, loyalty programs, and global supply chain, the company collects, processes, and stores vast volumes of sensitive consumer and employee data. This repository includes extensive personal identifiable information, billing details, profile histories, and internal corporate records, making the enterprise a lucrative target for cybercriminals seeking to exploit digital assets. The 2026 security incident reported to the Texas Attorney General highlights the persistent vulnerabilities facing major multinational retailers operating complex digital infrastructures. While specific operational details continue to emerge, retail and e-commerce data breaches of this scale typically involve sophisticated cyberattacks such as credential stuffing, unauthorized database access, or compromises of third-party vendor applications integrated into online checkout systems. In many instances, malicious actors manage to bypass perimeter defenses to infiltrate internal networks, potentially exfiltrating sensitive customer profiles, proprietary operational data, and administrative credentials before detection occurs. The exposure of consumer and employee information in a retail data breach creates immediate, multi-faceted risks for affected individuals. Typically, compromised categories include full names, billing and shipping addresses, email addresses, hashed passwords, purchase and order histories, and payment card details. When malicious actors obtain this combination of personal and transactional data, victims face heightened threats of targeted phishing scams, credential stuffing attacks across other online accounts, unauthorized financial transactions, and identity theft. The loss of private purchasing profiles and contact details deprives consumers of their fundamental right to digital privacy and leaves them vulnerable to prolonged exploitation. Under state consumer protection frameworks and federal standards, including the Texas Identity Theft Enforcement and Protection Act and Section 5 of the Federal Trade Commission Act, major corporations like The Estée Lauder Companies have a strict legal duty to implement and maintain reasonable security measures to safeguard private consumer and employee data. These obligations mandate the use of robust encryption, continuous network monitoring, rigorous third-party vendor vetting, and timely patch management. A breach of this magnitude serves as prima facie evidence of a potential failure to satisfy these statutory standards of care, suggesting that existing cybersecurity protocols were inadequate to counter foreseeable threats. For consumers who have received a data notification letter from The Estée Lauder Companies, this correspondence represents formal legal acknowledgment that their private information was compromised due to corporate negligence. Legally, the receipt of this notice establishes the necessary standing to participate in a class action lawsuit aimed at holding the company accountable for its security lapses. Affected individuals should note that they do not need to demonstrate actual financial loss to join a legal claim, as the increased risk of future identity theft and the loss of privacy constitute actionable harm. Our firm evaluates these cases on a strict contingency fee basis, meaning clients pay no upfront costs or out-of-pocket expenses unless a financial recovery is successfully secured on their behalf.
Under the Texas Identity Theft Enforcement and Protection Act, you may have a legal claim against The Estée Lauder Companies if any of the following apply:
Based on the data types reported in this filing:
Phone numbers exposed in breaches are used for SIM swapping attacks — hijacking your number to bypass two-factor authentication on financial accounts.
Common categories of compensation in data breach class actions
Courts recognize that the time spent monitoring accounts, placing credit freezes, and dealing with the aftermath of a breach has real economic value. This category of damages is recoverable even without direct financial loss.
Direct financial losses resulting from the breach — unauthorized charges, fraudulent transfers, or fees incurred through fraud — are recoverable as compensatory damages. Banks may reverse some charges; a class action recovers the remainder and associated costs.
When login credentials are exposed, the costs of downstream account compromises — password managers, security audits, and recovery costs for hijacked downstream accounts — can be recovered. Courts in recent class actions have awarded damages for credential exposure even without proven misuse.
Several state data breach laws provide for statutory minimum damages — fixed amounts recoverable per affected individual regardless of actual loss. These provisions exist specifically to make legal action viable for victims who have not yet experienced direct harm.
Note: an attorney general breach filing does not by itself establish a settlement fund, a payment amount, or a claim deadline. If an official settlement notice is later issued, rely on that notice for payment details and deadlines.
No. Under Texas Identity Theft Enforcement and Protection Act and federal law, the unauthorized exposure of your personal data — regardless of whether it has been actively misused — can be sufficient grounds for a claim. The breach itself is the injury.
Nothing. The Law Office of David S. Harris handles data breach cases on contingency — you pay zero upfront and owe nothing unless compensation is recovered.
Banks may reverse fraudulent charges, but they are not obligated to compensate you for time lost, stress, or indirect damages. A class action claim against the breached company can recover those additional categories of harm.
State statutes of limitations for data breach claims typically run 2–4 years from the date of the breach or its discovery. Because this breach was recently disclosed, the window is open — but acting early preserves your options and strengthens the case.
Accepting free credit monitoring from The Estée Lauder Companies does not waive your right to pursue legal action unless you signed a specific release waiving claims. In most cases, victims who accepted monitoring can still file.
Not necessarily. Many data breach victims are never notified directly. If your personal information was held by The Estée Lauder Companies during the relevant period, you may still qualify even without receiving a letter. A free eligibility review can confirm your status.
Most data breach class actions resolve within 18 to 36 months, though timelines vary by court and complexity. Your participation requires minimal effort — typically completing a claim form. Our office handles all litigation; you are notified when a settlement is reached.
Applicable State Law
This breach was reported under the Texas Identity Theft Enforcement and Protection Act, which mandates notification and establishes your right to seek damages.
The Estée Lauder Companies breach?
Free case review · No fee unless you win