Hallmark Breach: 1.7M Emails & Addresses Exposed (2026)
In March 2026, Hallmark suffered an alleged breach and subsequent extortion after attackers gained access to data stored within Salesforce. The data was later published after the extortion deadline passed, exposing 1.7M unique email addresses across both Hallmark and the Hallmark+ streaming service,...
Overview
In March 2026, Hallmark suffered a significant data breach after attackers compromised data stored within its Salesforce system. The company was allegedly extorted, and when the deadline passed, the attackers published the stolen data. The breach impacted approximately 1.7 million unique email addresses associated with both Hallmark and its Hallmark+ streaming service.
What Was Exposed
The published dataset contains extensive personal information. For each affected account, the following details were exposed:
- Email Addresses: The primary contact identifier.
- Full Names: Personal identification data.
- Phone Numbers: Direct contact information.
- Physical Addresses: Home or mailing addresses.
- Support Tickets: Details of past customer service interactions.
Potential Impact
The exposure of this combination of data significantly elevates the risk for affected individuals. With names, addresses, and phone numbers, criminals can execute highly targeted phishing attacks, impersonate Hallmark or other trusted entities, and attempt account takeovers on other services. The physical address data also raises concerns about potential stalking, harassment, or targeted physical scams. This breach provides scammers with a rich toolkit for social engineering, making any communication claiming to be from Hallmark particularly suspicious.
Recommendations
If you have ever had an account with Hallmark or Hallmark+, take these steps immediately:
- Change Your Hallmark Password: Use a strong, unique password that you do not use anywhere else.
- Enable 2FA: If Hallmark offers two-factor authentication (2FA), enable it on your account.
- Beware of Targeted Phishing: Be extremely cautious of emails, texts, or calls referencing your name, address, or past support issues. Do not click on links or provide further information. Verify communications directly through Hallmark’s official website.
- Monitor Financial Statements: While payment data was not listed in this leak, remain vigilant for any unauthorized transactions.
- Consider a Credit Freeze: Given the exposure of sufficient personal data for identity theft, placing a freeze on your credit reports is a prudent defensive step.
How to Check If You’re Affected
The breach has been reported to the free service Have I Been Pwned. You can visit https://haveibeenpwned.com/Breach/Hallmark and enter your email address to check if it was included in this data leak. It is recommended to check all email addresses you may have used with Hallmark services.
Security Insight
This breach highlights the critical risk of third-party platform security, as the attack vector was Hallmark’s instance of Salesforce, not necessarily its core systems. It mirrors incidents in other retail and media sectors where customer relationship management (CRM) databases become high-value targets. The publication of support ticket data is a particularly invasive detail, suggesting the compromised system contained deeply integrated customer records, a common finding in recent cybersecurity news on supply chain attacks.
Further Reading
Investigate Breaches Safely with NordVPN
Researching exposed data, paste sites, or threat actor infrastructure? Route your OSINT traffic through a VPN to avoid attribution and keep your investigation IP separate from your corporate network.
Get NordVPN for ResearchAffiliate link — we may earn a commission at no extra cost to you.
Never miss a data breach report
Get real-time security alerts delivered to your preferred platform.
Related Breach Reports
In April 2026, the hacking group ShinyHunters claimed they had breached Amtrak . The group typically compromises organisations' Salesforce instances before demanding a ransom and later, if not paid, dumping the data publicly. They subsequently published the alleged data which contained over 2M uniqu...
In March 2026, the anime streaming service Crunchyroll suffered a data breach alleged to have impacted 6.8M users . The exposed data is reported to have originated from the company's Zendesk support system where "name, login name, email address, IP address, general geographic location and the conten...
In February, the AI-powered comic generation platform KomikoAI suffered a data breach . The incident exposed 1M unique email addresses along with names, user posts and the AI prompts used to generate content. The exposed data enables the mapping of individual AI prompts to specific email addresses.
In February 2026, Dutch telco Odido was the victim of a data breach and subsequent extortion attempt . Following the incident, 1M records containing 317k unique email addresses were published, with the attackers threatening to leak additional data in the following days. That threat was subsequently ...