On April 1, 2026, Publishers Clearing House appeared on the leak site of the Anubis ransomware group, confirming that internal files had been exfiltrated during a ransomware attack on the well-known sweepstakes company.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Publishers Clearing House
Get alerted the next time Publishers Clearing House files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Publishers Clearing House’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that Anubis listed Publishers Clearing House on its dark-web portal and began publishing samples of stolen data. The exposed material consists of internal files taken during the intrusion. The exact number of people whose personal information appears in the files remains unknown, and the company has not yet issued a detailed public statement on the volume or sensitivity of the records. Available reporting describes the incident as a classic ransomware double-extortion case in which the attackers first encrypt systems and then threaten to release the stolen data unless a ransom is paid.
Why This Matters for You and Your Family
If your name, address, email, phone number, or payment details have ever been associated with Publishers Clearing House, those records may now sit in a criminal data store. Sweepstakes entries often require real contact information, prize-claim forms ask for Social Security numbers, and marketing databases link households across years of mailings. Once such data leaves a company’s control, it can be sold, traded, or used to build profiles that make every member of your family an easier target for identity theft, phishing, and scams. April 1, 2026 marks the public confirmation date; any delay in response gives attackers more time to exploit what they took.
The Doxxing and Identity-Chain Risk
Stolen internal files rarely contain only one data point. A single spreadsheet can link your email address to a physical address, phone number, date of birth, and names of other household members. Attackers then cross-reference these details with usernames from gaming platforms, social media, and older breaches. The result is an identity chain that can lead to doxxing, account takeovers, and targeted harassment. Credential leaks like this one frequently cascade into gaming account compromises because children and teens often reuse the same email or password they used to enter a sweepstakes years earlier.