See’s Candies says hackers encrypted its files in April and later posted some of them on the dark web. Months later, the company still hasn’t told the public which categories of personal information were actually exposed.
See’s Candies, Inc., the California confectioner owned by Berkshire Hathaway, notified individuals of a data breach after an unauthorized user accessed portions of its network and encrypted files on a subset of its servers. See’s Candies says the unauthorized access occurred between April 11 and April 13, 2026, and that it was notified of the intrusion on April 12, 2026. Independent breach-tracking reporting places the discovery around May 1, 2026 and attributes the intrusion to the Qilin ransomware group.
Source: Breachsense, See’s Candies Data Breach coverage (discovery ~05/01/2026; Qilin ransomware group attribution).
Months Later, No Word on What Was Taken
See’s Candies initially could not determine whether any files had been taken. It later learned that the unauthorized user acquired certain files before encrypting them, and that at least some of those files were made available on the dark web. See’s Candies reported the breach to the California Attorney General on August 13, 2026, roughly four months after the intrusion and about three and a half months after independent reporting places its discovery. As of this writing, See’s Candies has not publicly specified which categories of personal information were involved, only that impacted files contain a person’s name and other information the company has not itemized in any public source reviewed.
What Information Was Exposed?
See’s Candies has not disclosed which categories of personal information beyond a person’s name were involved. If you received a notice letter, it should specify the categories of information specific to you; review it carefully and keep a copy for your records.
How Many People Are Affected?
See’s Candies has not disclosed a total number of affected individuals. See’s Candies operates a large retail and mail-order customer base in addition to its own workforce, so the affected population could be substantial, but no figure has been made public.
What Is See’s Candies Offering Affected Individuals?
See’s Candies is offering complimentary access to Experian IdentityWorks for 12 months, including credit monitoring, an Experian credit report at signup, identity restoration support, and up to $1 million in identity theft insurance. The company’s notice letter includes an enrollment deadline and activation code specific to each recipient; See’s Candies has not disclosed a general enrollment deadline. Affected individuals can also call 1.833.918.0882 with questions.
Your Information Is at Risk
Even without a confirmed list of data types, a breach that includes files posted to the dark web carries real risk. Names combined with any additional personal or financial details can be used for identity theft, phishing, or fraud, especially once that information starts circulating outside a company’s own systems. Affected individuals should watch financial accounts for unfamiliar activity, pull a free credit report, and enroll in the Experian IdentityWorks monitoring See’s Candies is offering.
Do You Have Legal Options?
Companies that collect and store customer and employee personal information have a legal duty to secure that data and to notify affected individuals without unreasonable delay, and to give them an accurate account of what was taken.
Contact the Data Breach Attorneys at Emery | Reddy today for a Free Case Review if you received a notice letter from See’s Candies.
Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.
Residents of California may be entitled to additional protections under the California Consumer Privacy Act (CCPA), which provides enhanced rights regarding the collection, use, and safeguarding of personal information.
FAQ
Who is affected by the See’s Candies data breach?
Individuals whose information was in files an unauthorized user accessed and encrypted between April 11 and April 13, 2026, and some of which were later posted to the dark web. See’s Candies has not disclosed a total number of affected individuals.
What information was exposed?
See’s Candies has not publicly specified the categories of personal information involved beyond confirming that affected files contain a person’s name. If you received a notice letter, it should list the categories specific to you.
Why did it take so long to report this breach?
See’s Candies says the breach occurred April 11-13, 2026, and independent reporting places discovery around May 1, 2026. The company did not report the incident to the California Attorney General until August 13, 2026, roughly four months after the breach. See’s Candies has not explained the reason for the gap.
Is See’s Candies offering credit monitoring?
Yes. See’s Candies is offering 12 months of complimentary Experian IdentityWorks, including credit monitoring and identity restoration support, through an activation code included in each recipient’s letter.
Has my information actually been misused?
See’s Candies says it is not aware of any identity theft or fraud resulting from this incident. That does not mean the underlying exposure didn’t happen, only that no confirmed misuse has been reported yet.
Do I have a legal claim?
Companies that collect and store customer and employee personal information have a legal duty to secure that data and to notify affected individuals without unreasonable delay. If you received a notice from See’s Candies, contact the Data Breach Attorneys at Emery | Reddy at 206.207.8929 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.