See's Candies Data Breach Notice (Oregon Attorney General)
If you received a notice from See's Candies, here’s what the filing says was exposed, and what to do about it.
See's Candies notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on September 14, 2026. The filing puts the incident itself on April 11, 2026.
The personal information of an unknown number of Oregon residents was exposed in a breach at See's Candies that occurred on April 11, 2026. The company filed its notification with the Oregon Department of Justice on September 14, 2026 — an interval of 156 days, or roughly 5.1 months.
If you received a letter from See's Candies, this filing is about you
The organisation is required to notify affected individuals directly, usually by post. If you have not received such a letter, it is likely your information was not included. However, if you have moved since April 11, 2026, you should contact See's Candies directly to confirm whether your records were involved. Absence of a letter is usually meaningful, but last-known-address mail is not perfect.
What the exposed personal information actually means for you
The filing lists personal information as the category exposed in the incident. No passwords, no financial or banking details, no Social Security numbers, no driver's license numbers, and no medical information appear in the record. This is genuinely good news: the breach does not give anyone the ability to take over your See's Candies account or to open new accounts in your name using government identifiers.
What remains exposed is information that many people consider ordinary — names, addresses, dates of birth, and similar biographical details. While these pieces cannot be reissued like a credit card, they retain long-term value to identity thieves. Criminals can combine them with data from other breaches to build stronger profiles, attempt account takeover on services that use knowledge-based authentication, or file fraudulent tax returns or unemployment claims.
The 156-day gap between incident and notification
The breach happened on April 11, 2026. The notification reached Oregon authorities on September 14, 2026. That five-month interval is the most striking fact in the filing. Notification timelines vary by state law and by when an investigation concludes, so the record does not establish whether this delay was required or avoidable. It does, however, give you a clear picture of how long the company took to reach this stage after the incident date.
Why this exposure cannot be undone — and what still can
Once personal information leaves a company's systems, it cannot be retrieved. The people whose records were included now face an elevated risk of fraud that may appear months or years from now. The absence of permanent government identifiers in the exposed categories limits the most dangerous forms of identity theft, but the remaining data still supports targeted phishing, impersonation, and synthetic identity attempts when combined with information obtained elsewhere.
No evidence in the filing suggests customer accounts at See's Candies were directly compromised. Because no passwords or credentials were exposed, there is no need to change your See's Candies password as a result of this incident. That particular worry does not apply here.
What you should watch for in the coming months
Monitor your credit reports and bank accounts for unexpected activity. Be especially wary of unsolicited calls, emails, or letters that appear to come from See's Candies, government agencies, or retailers asking you to "verify" personal details. Criminals who possess even partial biographical information often use it to sound legitimate.
Consider placing a fraud alert with the three major credit bureaus if you have not done so recently. A fraud alert requires businesses to take extra steps to verify your identity before opening new accounts. It is free, lasts one year, and can be renewed.
Continue using unique, strong passwords on every site and enable two-factor authentication wherever it is offered. While this breach does not require you to rotate your See's Candies password, the broader pattern of personal-information exposure across many companies makes good credential hygiene more important than ever.
If you are contacted by someone claiming to represent See's Candies about this incident, do not provide additional information. Hang up or delete the message and call the company using a verified phone number from its official website.
The filing does not disclose the root cause, whether data was exfiltrated, or the exact number of people affected. It simply records that personal information was involved in an incident on April 11, 2026, and that notification to Oregon residents occurred 156 days later. Everything beyond those facts remains unknown to the public.
Report details & sourcing
Related breaches
Accela, Inc. Data Breach Notice (California Attorney General)
Accela, Inc. notified California residents of a data breach in a filing reported to the California A…
Score Services LLC d/b/a Score Capital Data Breach Notice (Vermont Attorney General)
Score Services LLC d/b/a Score Capital notified Vermont residents of a data breach in a filing repo…
Midkiff Data Breach Notice (Vermont Attorney General)
Midkiff notified Vermont residents of a data breach in a filing reported to the Vermont Attorney Gen…