2026 See's Candies — Apr 11–13 ransomware; files acquired and posted to dark web (CA AG)
Data compromised
Personal information categories vary by individual (variable fields in CA sample notice); company reviewing impacted files posted online
Technical writeup
Verified company notice via California AG filing sb24-629221 — September 2, 2026. See's Candies said that on April 12, 2026 it was notified an unauthorized user accessed portions of its network and encrypted files on a subset of servers. Investigation determined unauthorized access from April 11–13, 2026; the actor acquired certain files before encrypting them, and at least some files later appeared on the dark web. See's engaged outside cybersecurity experts, notified law enforcement, and is offering 12 months of identity-protection services while continuing file review. Nationwide victim census not stated in the CA sample letter. recordsAffected 0 pending attested count; companyConfirmed true.
Root cause
Unauthorized user accessed portions of See’s Candies network and encrypted a subset of servers April 11–13, 2026; investigation later found files were acquired before encryption and some appeared on the dark web