← The Estée Lauder Companies

2020 Estée Lauder Companies — unsecured Azure database; ~440M log rows (researcher disclosure)

2020 440.3M records affected Share on X

Data compromised

Emails and extensive internal telemetry/metadata; payment/card data not asserted in researcher’s published sample statements

Technical writeup

Researcher Jeremiah Fowler disclosed a non-password-protected Microsoft Azure dataset tied to Estée Lauder holding on the order of 440 million log/records, including large volumes of email addresses and internal IT logging (production/audit/middleware), reported by Security Discovery and BankInfoSecurity. Estée Lauder characterized the finding as limited non-consumer email from an education platform without consumer payment data; independent researchers contested full categorical boundaries. Access was restricted same day as responsible disclosure per researcher timeline.

Root cause

Cloud datastore exposed to the public internet without adequate access controls

References