If you've ever had an account or relationship with Sephora, it's worth checking whether your personal data was exposed in this incident. Here's what happened, what data was involved, and what to do about it.
What Happened
Unlike a traditional hack, Sephora's case was a data privacy enforcement action. In August 2022, the California Attorney General announced a $1.2 million settlement with Sephora after finding that the retailer had installed tracking technologies (such as analytics and advertising trackers) on its website that shared customer data with third-party companies for targeted advertising and analytics purposes, without properly disclosing this as a "sale" of data or offering California customers a clear way to opt out, as required under the California Consumer Privacy Act (CCPA).
What Data Was Exposed
The shared data related to customers' browsing activity, purchase history, and other behavioral data collected via tracking technologies embedded on Sephora's website, which was passed to third-party advertising and analytics companies.
Why This Still Matters
Exposed data doesn't expire. It's sold, traded, and reused for years, fueling credential stuffing attacks — automated attempts to reuse your email and password combination across other sites. If you reused a password anywhere, one old exposure can compromise several current accounts.
How to Check If You Were Affected
Use our free breach checker below — enter your email and we'll scan it against known breach databases instantly, no signup required.
What to Do If You Were Affected
- Change any reused password immediately, starting with your most sensitive accounts.
- Enable two-factor authentication wherever it's offered.
- Monitor financial and health accounts closely if that kind of data was involved.
- Watch for phishing — exposed data is often used to craft convincing scam messages.
- Freeze your credit if your SSN or government ID number was exposed.
👉 Check your own exposure in 30 seconds → scan your email free.
Frequently Asked Questions
Was Sephora hacked?
No, this was not a hack or data breach in the traditional sense. It was a privacy law enforcement case: California's Attorney General found Sephora shared customer tracking data with third parties without proper disclosure or opt-out mechanisms, violating the CCPA.
What data did Sephora share with third parties?
Data related to customers' website browsing behavior, purchase activity, and other behavioral information collected through tracking technologies was shared with third-party advertising and analytics companies without adequate opt-out options.
Why was Sephora fined?
California's Attorney General found that Sephora's practice of sharing this tracking data qualified as a 'sale' of personal information under the CCPA, and that Sephora failed to honor Global Privacy Control opt-out signals and did not properly disclose or allow opt-out of this practice, resulting in a $1.2 million settlement in August 2022.
Does this affect my personal Sephora account security?
This case was about undisclosed data sharing practices rather than stolen account credentials or payment information, so it does not indicate your Sephora login was compromised. It's still worth reviewing your privacy settings and any accounts where you reused a password.
What changed at Sephora after this settlement?
As part of the settlement, Sephora agreed to clearly disclose its data sharing practices, honor consumer opt-out requests including Global Privacy Control signals, and implement a program to assess and monitor its service providers and business partners.