Between April 11 and April 13, 2026, See's Candies experienced a ransomware attack by the Qilin group, which gained unauthorized access to parts of the company's network. The attackers encrypted files and acquired certain data before posting it on the dark web on April 30, 2026. See's Candies disclosed the breach to the California Attorney General on August 13, 2026, and subsequently began notifying affected individuals and law enforcement. The breach may have exposed various data types, including names, Social Security Numbers, dates of birth, addresses, government IDs, medical information, financial information, email addresses, mailing addresses, phone numbers, payment card information, purchase/order history, and password or credential hashes. The exact number of affected individuals has not been publicly disclosed. The incident affected residents of California. Additional details about the incident may emerge as investigations continue, and consumer notification efforts proceed. Notices to affected individuals may be delayed as the company completes its review.