See's Candies data breach: what was taken and whether it affects you
If you are a customer of See's Candies, here’s what is being claimed, and what it would mean for you.
See's Candies confirmed that in April 2026 someone got into its computer systems, copied files, and that some of those files later showed up on the dark web. The files included people's names, and notices to Massachusetts residents also list Social Security numbers. The company has not said how many people were affected and says it knows of no identity theft from this incident.
— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Editor’s note: The claims described below originate from a ransomware group’s leak-site posting and have not been independently verified by GalaxyWarden. A listing of this kind is an assertion made by the group during an extortion attempt. It is not evidence that a breach occurred, and we report it as a claim rather than as a finding.
See's Candies customer?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
Here for work? Check a company domain’s exposure.
See's Candies has confirmed that an unauthorized person accessed parts of its computer systems from April 11 to April 13, 2026. On April 12, the company was told that this person had reached certain systems and locked files on some servers so See's could not use them. See's hired outside investigators and notified law enforcement.
The company later found that the person copied some files before locking them, and that at least some of those files were put on the dark web. A review of the files found personal information, including names. In a letter to Massachusetts residents, See's specified first name, last name, and Social Security number. Individual notices went out around September 2, 2026, signed by CEO Pat Egan, and sample letters were filed with California and Massachusetts regulators in August and September 2026. See's has not said how many people were affected, has not posted this on its own website, and says it is unaware of any identity theft or fraud from the incident. It describes this as a one-time event.
The locked computers were See's problem. The copies are yours.
The official story is easy to read as a company IT problem that got handled: some servers locked, an investigation, law enforcement told, no known fraud, and a free year of identity monitoring. Those points come from See's own letters. They are also the part that is least useful if you are trying to decide whether this follows you.
- Every indexed leak tied to your address — all of them, named and dated
- A deeper search of collected breach data — the kinds of your information it holds, where it finds you
- What this kind of incident typically exposes
- A ten-minute lock list written for this kind of organisation
The person who got in did not only freeze See's systems. They took copies first. See's itself says at least some of those copies were then posted where stolen records are traded. If your information was in the files, the live issue is not whether the shops got their computers back. It is that a real name — and, at least for some people, a Social Security number sitting next to that name — may now be outside See's control. The company cannot pull that back. Twelve months of watching your credit file, or twenty-four months if you are in Massachusetts, is not an expiration date on a Social Security number.
Advertisement
Know the day any company files a breach.
Every SEC 8-K Item 1.05 and state breach notification — dated, sourced, and delivered by email + a JSON API the day it posts. Track any company, not just the ones in the news.
GalaxyWarden Signals and RecentBreaches share common ownership.
See's is a chocolate company, so a Social Security number can feel like it cannot apply to you. The letters do not say whether the files were about customers, employees, job applicants, or someone else. You do not hand over an SSN with a box of candy. You do hand one over for payroll, taxes, benefits, and some identity checks. Some later write-ups list extra categories such as medical records, driver's licenses, addresses, or payment cards. Those extras are not in the company's own notices, which confirm names and, in the Massachusetts letter, Social Security numbers. If you are only worrying about a credit card used at the counter, you may be worrying about the wrong thing. "We are unaware of identity theft" is also not proof the copies are unused; See's would often not be the first to find out.
There is no public list of whose information was in the files, and there is no reliable website or scan that can tell you whether you were in this specific incident. A clean result in a lookup is not an all-clear.
What to actually expect
- If See's identified you in its review, the notice is a letter from around early September 2026, signed by CEO Pat Egan, offering Experian IdentityWorks — 12 months in the general version, 24 months in the Massachusetts version. The enrollment code and deadline are in that letter, not on the company's website.
- Do not expect a headcount, a public list of names, or a statement on See's own site. The confirmation is the letter itself and the filings with California and Massachusetts regulators. Law firms have already announced investigations; that does not take the files down and does not mean you are included.
- Because some files were posted on the dark web months before most people were told (the intrusion was in April; letters went out in late summer), the practical risk is someone using a name and Social Security number to open credit, file a tax return, or claim a benefit — not a fake charge at a candy counter. If that happens, it can show up later, including in tax season, not only the week you hear about this.
- If you never get a letter, treat that as unknown, not as proof you were spared. The file review was still going on when the notices were sent. Silence from See's is not the same as "you were not in this."
What you can and cannot fix
If your name and Social Security number were in the files that were copied, that cannot be undone. A Social Security number that is out is out. It cannot be recalled from the dark web, See's cannot un-publish it, and a monitoring membership does not take it back. When the free period ends, the number is still the same number.
- If you received the See's letter, enroll in the Experian IdentityWorks offer in it. Use the code and deadline in your own notice. That service watches for some kinds of new-account fraud. It is not a freeze, and it is not permanent.
- Freeze your credit at Equifax, Experian, and TransUnion. A freeze is the step that actually blocks most new credit in your name. Monitoring only alerts you after someone has already tried. That matters here because the confirmed data is names and, at least for some people, Social Security numbers — the pair used to open accounts.
- If a Social Security number may have been involved, set up an IRS Identity Protection PIN. That PIN is what stops someone else from filing a federal tax return in your name. Tax-refund fraud is one of the main uses of a stolen SSN, and it often appears in filing season, not the week of a breach letter.
- Remove what you can from people-search sites. A leaked record, if it is yours, is a name and possibly an SSN. That pairing becomes much easier to use when it is joined to listings that add relatives, phone numbers, employers, and previous addresses. Those people-search listings, unlike the stolen files, can actually be taken down. That is the lever still in your hands: make it harder to turn a bare stolen record into a full picture of you. You cannot delete the breach itself.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on See's Candies.
- Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
For security and vendor-risk teams: get an alert the day a vendor you watch files a breach with a US regulator or the SEC — the filing itself, dated and sourced, plus an API. GalaxyWarden Signals →
A staff address in a leak usually means a third party was breached, not you — check your own domain’s exposure. Exposure Monitoring →
Report details & sourcing
Related breaches
Navia Benefits Administration Breach — March 2026
2.7 million individuals had names, SSNs, DOBs, contact information, and benefits administration data…
PayPal SSN Exposure Lasting Six Months — February 2026
A code change at PayPal allowed unauthorized access to Social Security Numbers and account details f…
Malaysia National Registration Department 22.5 Million — May 2022
A breach of Malaysia's National Registration Department exposed ~22.5 million citizen records, inclu…