
A security expert has discovered that the famous cosmetics company Estée Lauder exposed 440 million records , which were located in an . unprotected online database
The researcher who discovered the exposed database is named Jeremiah Fowler. According to his statements, the database contained 440,336,852 files.
Estée Lauder is an American multinational company engaged in the production and sale of skin and hair care products, makeup products and fragrances. It has many brands distributed around the world, either through online stores or through physical stores.
Fowler discovered the unprotected database on January 30th and tried to notify the company.
“On January 30th, I discovered a database that was not password protected .The database contained a huge amount of files (440,336,852). After research, I found that there was a connection to the New York-based cosmetics company Estée Lauder,” the researcher said in his post. “I could see files containing a large number of email , etc. I immediately sent a notification to Estée Lauder warning them of the exposure.”
According to the expert, there were many user email addresses in plain text, as well as internal addresses, from the @estee.com domain.

The exposed data also includes: technical information, such as IP addresses, ports and other elements, that could be used by attackers to gather information about Estée Lauder's infrastructure.
“There were millions of pieces of evidence about the middleware that Estée Lauder uses. Middleware is software that provides common services and capabilities to applications, beyond what the operating system provides,” he said. “Middleware deals with data management, application services, messaging, authentication, and API management.”
Fowler warns that exposing middleware data could be used by hackers to install malware.
After the incident was revealed, Estée Lauder took immediate action and secured the database. The good news is that there was no payment data or sensitive employee information in these files.
However, the researcher said he doesn't know how long the database was exposed or whether the data was obtained by malicious actors or third-party services.
