2020 Estée Lauder Companies — unsecured Azure database; ~440M log rows (researcher disclosure)
Data compromised
Emails and extensive internal telemetry/metadata; payment/card data not asserted in researcher’s published sample statements
Technical writeup
Researcher Jeremiah Fowler disclosed a non-password-protected Microsoft Azure dataset tied to Estée Lauder holding on the order of 440 million log/records, including large volumes of email addresses and internal IT logging (production/audit/middleware), reported by Security Discovery and BankInfoSecurity. Estée Lauder characterized the finding as limited non-consumer email from an education platform without consumer payment data; independent researchers contested full categorical boundaries. Access was restricted same day as responsible disclosure per researcher timeline.
Root cause
Cloud datastore exposed to the public internet without adequate access controls