Data breach
Hallmark Cards, Inc. & Hallmark Plus
- Records
- 1,503,893
- Breach date
- 31 March 2026Estimated
- Added
- 13 April 2026
What was exposed
5 types of data
- Email addresses1,503,893
- Names1,280,321
- Phone numbers563,482
- Street addresses367,252
- Dates of birth82,304
About this breach
ShinyHunters, a threat group known for extorting companies over stolen cloud data, leaked customer records from Hallmark Cards, Inc. and the Hallmark+ streaming service after the company missed an extortion deadline in early April 2026. According to our investigation team, the indexed dataset contains 1,503,893 rows and is estimated to have been breached on March 31, 2026. Independent reporting and security researchers traced the theft to Hallmark's Salesforce environment, which the attackers accessed through a third-party integration rather than Salesforce's own platform. Salesforce told Salesforce Ben that it had no indication the issue came from a vulnerability in its core platform.
March 9, 2026: Reporting by gblock dates the initial intrusion into a Salesforce environment shared by Hallmark Cards and Hallmark Plus to this date.
March 31, 2026: ShinyHunters posted a public ransom note giving Hallmark until April 2 to respond, claiming just under 8 million Salesforce records, per Salesforce Ben.
April 2, 2026: The extortion deadline passed with no response from Hallmark, according to Salesforce Ben's reporting.
April 12, 2026: The leaked dataset, which researchers measured at 9.59 GB, was indexed and analyzed; analysts confirmed roughly 1.7 million unique customer email addresses, per TechNadu and gblock.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses (1,503,893), names (1,280,321), phone numbers (563,482), street addresses (367,252), and birthdays (82,304).
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The combination of names, email addresses, phone numbers, and home addresses gives scammers the raw material for convincing phishing emails, smishing texts, and phone calls that appear to come from Hallmark or its customer service team. Where support ticket contents were included in the leak, attackers could reference real past complaints or orders to make their messages seem legitimate. Dates of birth add another layer that identity thieves can use when answering security questions or opening accounts. People who reused passwords tied to their Hallmark or Hallmark+ email addresses should assume those credentials could be targeted in credential stuffing attacks, even though no passwords appear in the indexed data types we reviewed.
What Is Hallmark Cards, Inc. & Hallmark Plus Doing in Response?
Reporting from April 2026, including Proton's Data Breach Observatory, likewise noted that Hallmark had not released an official statement confirming the breach. If you believe you are affected, watch for any direct notification from the company and rely on information published through its official channels rather than unsolicited emails or calls.
What Should You Do If You Were Affected?
Treat any email, text, or phone call claiming to be from Hallmark as suspicious, especially if it references a past order, complaint, or support ticket. Verify by contacting Hallmark through the phone number or website listed on its official site, not through links in the message.
Change the password on your Hallmark or Hallmark+ account, and change it anywhere else you reused it.
Turn on multi-factor authentication for your email and financial accounts. This is the strongest defense against phishing-driven account takeovers.
Watch your financial statements and credit reports for unexplained activity. You can request free credit reports from the three major bureaus and consider a fraud alert or credit freeze.
Be cautious with personalized scams. Knowing your name, address, or phone number does not make a caller legitimate.
In the news
- TechNadu: Hallmark Data Breach Exposes 1.7 Million Customers via Salesforce Compromisetechnadu.com (opens in a new tab)
- Salesforce Ben: ShinyHunters Claim Hallmark as Next Victimsalesforceben.com (opens in a new tab)
- gblock: Hallmark Refused to Pay, ShinyHunters Leaked 1.7M Recordsgblock.app (opens in a new tab)
- Proton Data Breach Observatoryproton.me (opens in a new tab)
