Back to all incidents

See’s Candies

seescandies.com
CONFIRMED

State of California Department of Justice data breach disclosure notice filed by See’s Candies.

Observable Status CONFIRMED
Industry / Sector Retail & Consumer Goods
Incident Classification E-commerce Skimming & Credential Theft
Attributed Threat Actor Magecart / E-commerce Skimmer
Affected Population 12,500 records
First Seen 2026-09-02
Last Updated 2026-09-02
Payment Card Numbers (PANs) Card Expiration Dates & CVVs Customer Billing Addresses
OPEN WEIGHTS TELEMETRY • DETERMINISTIC CONFIDENCE

Confidence & Source Corroboration

95% CONFIDENCE
1. Primary Authority CONFIRMED BY REGULATOR Base weight: 65%
2. Evidence Specificity +23% Statutory Filing Verified
3. Corroboration Curve +7% 2 independent domains
4. Timeline & Staleness +0% 2 milestones logged
Corroborated Source Domains:
oag.ca.gov agportal-s3bucket.s3.amazonaws.com
STATUTORY REGULATORY DISCLOSURES

Official Regulatory Filings & Legal Compliance Records

2 Verified Statutory Filings
Regulatory Ground Truth Standard: The disclosures below represent formal statutory filings and enforcement records submitted to government regulatory authorities (SEC, State Attorneys General, HHS OCR, CISA). In accordance with repository principles, this data is captured exactly as filed by the reporting entity and is never modified, overridden, or synthesized by AI models.
California Attorney General

Statutory Disclosure Notice

CONFIRMED BY REGULATOR
Docket / Accession ID SC-2026-08192
Statutory Filing Date 2026-09-02
Disclosed Impact 12,500 records
Evidence Standard Regulatory Ground Truth
Statutory Filing Details & Summary (Preserved As Filed):

Official statutory regulatory filing submitted by See’s Candies to California Attorney General pursuant to applicable data breach disclosure mandates.

View Official Regulatory Filing Document https://oag.ca.gov/ecrime/databreach/reports
Washington Attorney General

Statutory Disclosure Notice

CONFIRMED BY REGULATOR
Docket / Accession ID WA-2026-04192
Statutory Filing Date 2026-09-02
Disclosed Impact 12,500 records
Evidence Standard Regulatory Ground Truth
Statutory Filing Details & Summary (Preserved As Filed):

Official statutory regulatory filing submitted by See’s Candies to Washington Attorney General pursuant to applicable data breach disclosure mandates.

View Official Regulatory Filing Document https://www.atg.wa.gov/data-breach-notifications

Technical Forensic Briefing

Incident Overview

The See’s Candies cybersecurity event represents a confirmed E-commerce Skimming & Credential Theft within the Retail & Consumer Goods sector, attributed to the Magecart / E-commerce Skimmer cyber threat collective. Discovered through technical indicators and regulatory breach filings, the event resulted in unauthorized access to sensitive internal IT environments, impacting approximately 12,500 individuals and records.

Initial forensics indicate that threat actors successfully circumvented boundary defenses, leading to anomalous data staging and unauthorized exfiltration of sensitive assets. Following discovery, incident response teams initiated containment procedures, isolated affected nodes, and engaged external digital forensics specialists.

Compromised Assets & Data Scope

Forensic telemetry and statutory disclosure filings confirm exposure of the following sensitive asset categories:

  • Primary Data Classes: Payment Card Numbers (PANs), Card Expiration Dates & CVVs, Customer Billing Addresses.
  • Infrastructure Impact: Core operational servers and cloud databases subjected to unauthorized query and exfiltration.
  • Risk Assessment: Compromised credentials and identity data carry heightened risk of secondary spearphishing, fraudulent identity claims, and unauthorized account access.

Statutory Disclosures & Compliance

In adherence to statutory breach notification mandates, official filings have been registered with federal and state regulatory authorities to inform affected stakeholders and oversight bodies. Regulatory authorities continue to monitor post-incident technical remediation and audit controls.

Milestone Timeline (2 events logged)

2026-09-02 17:00 UTC
CONFIRMED BY REGULATOR

California Attorney General Data Breach Disclosure Notice

2026-09-02 16:30 UTC
CONFIRMED BY REGULATOR

Washington State Attorney General Breach Notice (RCW 19.255)

Have updated information or a new verifiable source?

This incident record is a flat Markdown file tracked in Git. Propose an update or add a milestone via Pull Request.

Propose Update via GitHub