On November 9, 2025, Beckett Collectibles suffered a data breach that exposed the personal information of roughly 1 million customers. The incident also included defacement of the company’s website. Names, email addresses, usernames, phone numbers, and physical addresses were taken. The stolen records later appeared for sale on a prominent hacking forum, with more than 500,000 email addresses from North American customers released first, followed by a larger set of over 1 million addresses the next month.
Named in this incident?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Beckett Collectibles
Get alerted the next time Beckett Collectibles files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Beckett Collectibles’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates the breach occurred in November 2025. The data exposed included names, usernames, phone numbers, physical addresses, and email addresses. Initial leaks focused on more than 500,000 North American email addresses before the full corpus exceeding 1 million records circulated publicly. Available reporting describes website defacement occurring alongside the theft. The records were advertised for sale on a well-known hacking forum, after which portions were released openly.
Why This Matters for You and Your Family
When a company holding your name, home address, phone number, email, and username loses that information, it creates immediate risks. Identity thieves can use the combination to attempt account takeovers on other services where you reuse credentials. Scammers may also craft convincing phishing calls or texts that reference your recent purchases or family details. For households with children who share the same address or email domain, the exposure can extend to their accounts as well. The public release of this data means anyone with internet access can search and obtain it, increasing the chance of harassment, spam, or targeted fraud against you or family members.
The Doxxing and Identity-Chain Implications
Once names and addresses are paired with usernames and emails, attackers can quickly map additional online profiles. A gaming username leaked here can be linked to the same person’s social media or shopping accounts. These connections form identity chains that allow doxxing—publicly exposing someone’s full personal details. Credential leaks like this one often cascade into account takeovers on gaming platforms, where children’s accounts may be targeted because they frequently reuse passwords or share family contact information. The combination of physical address and online handles makes it easier for malicious actors to harass families or sell the compiled dossiers on underground markets.