Hallmark Data Breach (2026): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
On March 31, 2026, Hallmark disclosed a data breach that exposed the email addresses, names, phone numbers, physical addresses, and support tickets of 1.7 million individuals. Anyone who has interacted with Hallmark is urged to check for breach notifications and secure their accounts.
Known details remain limited to the reported date of March 31, 2026, the scale of 1.7 million unique email addresses, and the categories of data that appeared after publication. No further technical specifics, such as the precise method of initial access or the timeline of events inside the environment, have been disclosed publicly.
Breaking down the breach
The reported incident centers on data held within a Salesforce instance. Attackers are said to have obtained access, after which an extortion demand was issued. When that demand was not met, the material was published, revealing 1.7 million unique email addresses along with associated names, phone numbers, physical addresses, and support tickets. The publication covered records from both Hallmark and the Hallmark+ service. No additional information on the volume of records, the exact files involved, or any payment related to the extortion has been confirmed.
How a breach like this happens
Incidents involving customer-relationship platforms such as Salesforce often begin with the compromise of credentials, misconfigured access controls, or the exploitation of third-party integrations. Once inside the environment, an actor may locate and copy large volumes of stored records. In some cases the data is then used in an extortion attempt, with publication occurring if demands are not satisfied. The pattern of initial access followed by data exfiltration and later release is observed across multiple sectors and does not require attribution to any particular group to describe the general sequence.
About Hallmark
Hallmark operates as a consumer-facing company with product lines in greeting cards, gifts, and related merchandise, and it maintains a streaming service under the Hallmark+ brand. Organizations of this type routinely collect contact details and interaction records to manage customer accounts, process orders, and provide support. A breach that exposes such records can affect both direct customers and subscribers to the streaming platform, increasing the scope of individuals whose information becomes publicly available.
The information in question
The published material is reported to contain email addresses, names, phone numbers, physical addresses, and support tickets. These categories align with the types of records commonly stored in customer-service and subscription-management systems. The exact contents of any individual record or the full scope of fields beyond those listed remain unconfirmed outside the published dataset itself.
The real-world impact
Individuals whose records appeared may face an increased volume of unsolicited contact and a higher likelihood that their details will be used in future phishing or social-engineering attempts. Support-ticket information can sometimes reveal account-specific details that assist further targeting. For the organization, the incident adds to the body of publicly documented exposures involving widely used cloud platforms and may prompt reviews of access controls and data-retention practices.
What to do if you're exposed
People who believe their information may have been included can begin by monitoring their email accounts for unusual login attempts and by using unique passwords or passphrases for each service. Enabling multi-factor authentication on accounts that support it reduces the value of exposed credentials. A free exposure scan of an email address against known breach datasets can indicate whether the address has appeared in previously published collections, providing a starting point for further checks.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Moody Bible Institute Data Breach (2026)Sysco Data Breach (2026)American Tower Data Breach (2026)JCPenney Data Breach (2026)Latest breaches
Read GalaxyWarden’s full analysis of the Hallmark Data Breach (2026) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.