Estée Lauder's HR system was breached in August 2025 - employees found out 10 months later
Your passport details, financial information, and employment history were stolen. You found out about it almost a year later.
Estée Lauder confirmed in June 2026 that attackers had accessed its Oracle E-Business Suite HR environment in August 2025. Names, passport details, financial account information, employment history. Ten months between breach and notification.
In those ten months, affected employees had no reason to monitor for identity fraud. No reason to place a fraud alert. No reason to be suspicious of unusually personalized phishing attempts. The attackers had a ten-month head start on people who didn't know they were in a race.
The data combination matters. Passport details plus employment history plus financial information isn't a data breach - it's an identity fraud starter kit. Enough to open financial accounts, pass KYC checks, craft deeply convincing social engineering attacks, all while the victim has no idea their data is in play.
GDPR mandates breach notification within 72 hours of discovery. The US has no federal equivalent. Notification timelines vary by state and "discovery" is loosely defined - which means the gap between when companies know and when they tell you is effectively unregulated. That gap is where most of the damage happens.
If you're a current or former Estée Lauder employee: monitor your financial accounts and treat any outreach that references your employment history with unusual accuracy as a red flag, not a coincidence.
should companies face automatic financial penalties for every month they delay breach notification — or does that just incentivize them to define "discovery" even more loosely