Data Breach & Privacy
Blog > Data Breach & Privacy
See’s Candies Data Breach: What Affected Individuals Need to Know
See’s Candies is notifying individuals that an unauthorized user accessed portions of its network in April 2026 and encrypted files on some servers, and that some of the files taken were made available on the dark web. Here is what the company has disclosed and what you can consider doing.

Who May Be Affected by the See's Candies Breach
Individuals whose information See's Candies maintained
See’s Candies is a California-based confectioner headquartered in South San Francisco, with retail shops and operations across many states. The company’s notices do not specify whether the affected individuals are customers, employees, or both, and a total number of affected individuals has not been published. Because the information reported to be involved includes Social Security numbers — data not typically collected in a routine retail purchase — the affected population may include individuals with an employment or similar relationship to the company, though See’s Candies has not confirmed this.
The notification letters include state-specific notices for residents of California, Massachusetts, Connecticut, the District of Columbia, Iowa, Kentucky, Maryland, New Mexico, New York, North Carolina, Oregon, Rhode Island, and other states, suggesting affected individuals are spread across the country. If you received a letter from See’s Candies referencing this incident or an Experian IdentityWorks activation code, that notice may indicate your information was among the data reported to have been affected.
How See's Candies Responded and What Protections Are Offered
Free Experian IdentityWorks membership and identity restoration
See’s Candies reports that, upon learning of the incident, it launched an investigation, notified law enforcement, took steps to block unauthorized access to its network, and implemented measures intended to help prevent a similar incident. The company states it is continuing to review the impacted files for personal information and, based on its investigation so far, believes the incident was limited to a one-time event.
Out of what it describes as an abundance of caution, See’s Candies is offering affected individuals complimentary access to Experian IdentityWorks — 12 months under some notices and 24 months under others, depending on the letter received. The service is described as including credit monitoring, Identity Restoration support, Experian’s ExtendCARE continued restoration assistance, and a $1,000,000 identity theft insurance policy. Individuals must enroll themselves using the activation code in their letter, and the September 2026 notices list an enrollment deadline of December 31, 2026, after which the code will not work. Recipients should follow the deadline printed in their own letter.
Steps You Can Take to Protect Yourself
Practical precautions while the review continues
While See’s Candies has reported no known misuse, the company’s own acknowledgment that files reached the dark web makes precautionary steps worth considering:
- Enroll in the Experian IdentityWorks offer. If your letter includes an activation code, consider enrolling before the deadline printed in your letter (December 31, 2026 in the September 2026 notices); Identity Restoration support is described as available immediately without enrollment.
- Consider a credit freeze or fraud alert. Both are free through Equifax, Experian, and TransUnion, and a freeze can help prevent new accounts from being opened with a stolen Social Security number.
- Review your accounts and credit reports. You are entitled to free credit reports at annualcreditreport.com; watch for accounts, inquiries, or charges you do not recognize.
- Be alert to phishing. See’s Candies’ own notice warns never to provide personal information in response to an electronic communication about the incident. Verify any outreach through official channels.
- Refresh your online security. Consider updating passwords and security questions, especially for accounts that reuse the same credentials.
This information is a general overview and is not legal advice; your situation may differ, and consulting a legal professional can help you understand rights that may apply to you.
Talk to Wilshire Law Firm
Were you affected by the See's Candies data breach?
If your personal information may have been involved in the See’s Candies data breach, do you know what your options are? Our nationally recognized, award-winning team is here to help you understand your rights. Wilshire Law Firm offers free consultations and free case reviews with a legal professional, and we are available 24/7. Because we work on a contingency basis, there are no fees unless you get paid.
Contact Wilshire Law Firm today to schedule your free case review and get your questions answered.
FAQs
According to See’s Candies, the company was notified on April 12, 2026, that an unauthorized user had accessed portions of its network, and its investigation determined the unauthorized access occurred from April 11, 2026, to April 13, 2026. Notification letters were reported to the California Attorney General on August 13, 2026, and September 2, 2026.
See’s Candies states that an unauthorized user accessed certain portions of its network and encrypted files on a subset of its servers, acquiring certain files before encrypting them. Reporting describes the incident as a ransomware attack and indicates a ransomware group has claimed responsibility, but See’s Candies has not publicly confirmed the attribution.
See’s Candies reports the affected files contain names along with additional personal information that varies by individual. The version of the notice filed with the Massachusetts Attorney General specifies first name, last name, and Social Security number.
Yes, according to the company. See’s Candies states that it later learned the unauthorized user acquired certain files before encrypting them and that at least some of those files were made available on the dark web.
See’s Candies has not published a total number of affected individuals. The company filed notices with the California and Massachusetts Attorneys General, and its letters include state-specific information for residents of many other states, indicating a multi-state notification.
Yes. See’s Candies reports that it is offering complimentary Experian IdentityWorks membership — 12 or 24 months depending on the notice received — including credit monitoring, Identity Restoration, ExtendCARE, and a $1,000,000 identity theft insurance policy. Individuals must enroll with the activation code in their letter by the deadline it states, which is December 31, 2026 in the September 2026 notices.
Individuals who believe they were affected may have legal options, and data breaches involving Social Security numbers and dark web exposure can sometimes lead to class action litigation. Whether a claim may apply to you depends on the specific facts. A free case review with a legal professional can help you understand your potential rights.

