If you've ever had an account or relationship with Sephora, it's worth checking whether your personal data was exposed in this incident. Here's what happened, what data was involved, and what to do about it.

What Happened

Unlike a traditional hack, Sephora's case was a data privacy enforcement action. In August 2022, the California Attorney General announced a $1.2 million settlement with Sephora after finding that the retailer had installed tracking technologies (such as analytics and advertising trackers) on its website that shared customer data with third-party companies for targeted advertising and analytics purposes, without properly disclosing this as a "sale" of data or offering California customers a clear way to opt out, as required under the California Consumer Privacy Act (CCPA).

What Data Was Exposed

The shared data related to customers' browsing activity, purchase history, and other behavioral data collected via tracking technologies embedded on Sephora's website, which was passed to third-party advertising and analytics companies.

Why This Still Matters

Exposed data doesn't expire. It's sold, traded, and reused for years, fueling credential stuffing attacks — automated attempts to reuse your email and password combination across other sites. If you reused a password anywhere, one old exposure can compromise several current accounts.

How to Check If You Were Affected

Use our free breach checker below — enter your email and we'll scan it against known breach databases instantly, no signup required.

What to Do If You Were Affected

👉 Check your own exposure in 30 seconds → scan your email free.

Frequently Asked Questions

Was Sephora hacked?

No, this was not a hack or data breach in the traditional sense. It was a privacy law enforcement case: California's Attorney General found Sephora shared customer tracking data with third parties without proper disclosure or opt-out mechanisms, violating the CCPA.

What data did Sephora share with third parties?

Data related to customers' website browsing behavior, purchase activity, and other behavioral information collected through tracking technologies was shared with third-party advertising and analytics companies without adequate opt-out options.

Why was Sephora fined?

California's Attorney General found that Sephora's practice of sharing this tracking data qualified as a 'sale' of personal information under the CCPA, and that Sephora failed to honor Global Privacy Control opt-out signals and did not properly disclose or allow opt-out of this practice, resulting in a $1.2 million settlement in August 2022.

Does this affect my personal Sephora account security?

This case was about undisclosed data sharing practices rather than stolen account credentials or payment information, so it does not indicate your Sephora login was compromised. It's still worth reviewing your privacy settings and any accounts where you reused a password.

What changed at Sephora after this settlement?

As part of the settlement, Sephora agreed to clearly disclose its data sharing practices, honor consumer opt-out requests including Global Privacy Control signals, and implement a program to assess and monitor its service providers and business partners.

Sources

Related Reading