LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Hallmark Data Breach (2026)

HIGH severityConfirmedHow we verify

Hallmark Data Breach (2026): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·March 31, 2026

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Hallmark Data Breach (2026)

Reported March 31, 2026. Approximately 1.7M people affected.

HIGH
Severity
1.7M
People affected
5
Data types exposed
March 31, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

On March 31, 2026, Hallmark disclosed a data breach that exposed the email addresses, names, phone numbers, physical addresses, and support tickets of 1.7 million individuals. Anyone who has interacted with Hallmark is urged to check for breach notifications and secure their accounts.

Severity & verification
HIGH severityConfirmed
Contact / identity PII exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the Hallmark Data Breach (2026) breach?
1.7M accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In March 2026, Hallmark experienced an alleged breach that resulted in the exposure of records belonging to 1.7 million individuals. The incident involved unauthorized access to data stored in Salesforce, followed by an extortion attempt and the subsequent publication of the material once the deadline passed. The affected records include information associated with both the main Hallmark organization and its Hallmark+ streaming service.

Known details remain limited to the reported date of March 31, 2026, the scale of 1.7 million unique email addresses, and the categories of data that appeared after publication. No further technical specifics, such as the precise method of initial access or the timeline of events inside the environment, have been disclosed publicly.

Breaking down the breach

The reported incident centers on data held within a Salesforce instance. Attackers are said to have obtained access, after which an extortion demand was issued. When that demand was not met, the material was published, revealing 1.7 million unique email addresses along with associated names, phone numbers, physical addresses, and support tickets. The publication covered records from both Hallmark and the Hallmark+ service. No additional information on the volume of records, the exact files involved, or any payment related to the extortion has been confirmed.

How a breach like this happens

Incidents involving customer-relationship platforms such as Salesforce often begin with the compromise of credentials, misconfigured access controls, or the exploitation of third-party integrations. Once inside the environment, an actor may locate and copy large volumes of stored records. In some cases the data is then used in an extortion attempt, with publication occurring if demands are not satisfied. The pattern of initial access followed by data exfiltration and later release is observed across multiple sectors and does not require attribution to any particular group to describe the general sequence.

About Hallmark

Hallmark operates as a consumer-facing company with product lines in greeting cards, gifts, and related merchandise, and it maintains a streaming service under the Hallmark+ brand. Organizations of this type routinely collect contact details and interaction records to manage customer accounts, process orders, and provide support. A breach that exposes such records can affect both direct customers and subscribers to the streaming platform, increasing the scope of individuals whose information becomes publicly available.

The information in question

The published material is reported to contain email addresses, names, phone numbers, physical addresses, and support tickets. These categories align with the types of records commonly stored in customer-service and subscription-management systems. The exact contents of any individual record or the full scope of fields beyond those listed remain unconfirmed outside the published dataset itself.

The real-world impact

Individuals whose records appeared may face an increased volume of unsolicited contact and a higher likelihood that their details will be used in future phishing or social-engineering attempts. Support-ticket information can sometimes reveal account-specific details that assist further targeting. For the organization, the incident adds to the body of publicly documented exposures involving widely used cloud platforms and may prompt reviews of access controls and data-retention practices.

What to do if you're exposed

People who believe their information may have been included can begin by monitoring their email accounts for unusual login attempts and by using unique passwords or passphrases for each service. Enabling multi-factor authentication on accounts that support it reduces the value of exposed credentials. A free exposure scan of an email address against known breach datasets can indicate whether the address has appeared in previously published collections, providing a starting point for further checks.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyHallmark security record
70/100
DoxxScan™ · Moderate doxx risk
C- 62Below-average record

1 reported incident on record.

See Hallmark’s full breach history →

More recent breaches

Moody Bible Institute Data Breach (2026)June 15, 2026Sysco Data Breach (2026)June 15, 2026American Tower Data Breach (2026)June 12, 2026JCPenney Data Breach (2026)June 12, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Hallmark Data Breach (2026) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram