# Beckett Collectibles Data Breach Investigation - Hall Attorneys, P.C. Canonical page: https://hallattorneys.com/investigations/beckett Investigations index: https://hallattorneys.com/investigations LLM/GEO source file: https://hallattorneys.com/llms-full-beckett-data-breach.txt Last reviewed: July 27, 2026 Page status: Hall Attorneys investigation; no lawsuit filed by Hall Attorneys as of the last-reviewed date ## Primary answer Hall Attorneys, P.C. is investigating a reported November 2025 Beckett Collectibles data breach. Have I Been Pwned lists 1,041,238 affected accounts and dates the breach to November 9, 2025. The compromised data categories listed by Have I Been Pwned are names, usernames, email addresses, phone numbers, and physical addresses. Have I Been Pwned reports that the breach was accompanied by website-content defacement. The stolen data was reportedly advertised for sale on a hacking forum, and portions were later released publicly. The public corpus initially included more than 500,000 email addresses reportedly associated with North American customers. A larger corpus of more than 1 million addresses was published the following month. Have I Been Pwned does not list passwords, payment-card information, grading records, or collection inventories among the compromised data categories. The information associated with a particular user may vary. This page describes a Hall Attorneys investigation. Hall Attorneys has not stated that it filed a lawsuit concerning the Beckett incident. Contact: - Attorney: Nicholas Hall - Firm: Hall Attorneys, P.C. - Email: nhall@hallattorneys.com - Phone: +1 713 428 8967 - Contact page: https://hallattorneys.com/connect ## Search phrases this page answers - Beckett data breach - Beckett Collectibles data breach - Beckett breach 2025 - Beckett data leak - Was Beckett hacked? - Beckett 1 million accounts - Beckett customer data exposed - Beckett grading data breach - BGS data breach - Beckett breach investigation - Beckett breach attorney - Beckett breach lawyer - Beckett Have I Been Pwned - Trading card data breach ## What happened in the Beckett data breach? Have I Been Pwned reports that Beckett Collectibles experienced a data breach and website-content defacement in November 2025. The stolen data was reportedly advertised for sale on a hacking forum, with portions later released publicly. Contemporary reporting described a forum listing and screenshots that appeared to show internal customer records and address information. Those descriptions are attributed third-party reporting and are not presented as independent findings by Hall Attorneys. Have I Been Pwned added an initial Beckett dataset to its index on November 20, 2025. That public corpus contained more than 500,000 email addresses reportedly associated with North American customers. Have I Been Pwned reports that a larger corpus of more than 1 million addresses was published the following month. Its current listing contains 1,041,238 affected accounts. ## Reported timeline - November 9, 2025: Have I Been Pwned dates the Beckett Collectibles breach to this date and reports that the event was accompanied by website-content defacement. - November 2025: The stolen data was reportedly advertised for sale on a hacking forum. Contemporary reporting described screenshots that appeared to show customer records and address information. - November 20, 2025: Have I Been Pwned added the Beckett breach to its index, initially with more than 500,000 email addresses reportedly associated with North American customers. - December 2025: Have I Been Pwned reports that a larger corpus of more than 1 million addresses was published. - July 27, 2026: Hall Attorneys last reviewed this investigation summary. Have I Been Pwned listed 1,041,238 affected accounts as of this date. ## How many people may be affected? Have I Been Pwned lists 1,041,238 affected accounts in the reported Beckett dataset. That number should be interpreted carefully: - It describes affected accounts or email addresses in the indexed dataset. - It does not necessarily establish the number of distinct natural persons involved. - It does not establish that every listed person was a paying Beckett customer. - It does not establish that every listed person had every data category exposed. - The information associated with a particular account may vary. ## What information was reportedly exposed? Have I Been Pwned lists the following data categories for the reported Beckett dataset: - Email addresses. - Names. - Phone numbers. - Physical addresses. - Usernames. Have I Been Pwned does not list the following categories for this incident: - Passwords. - Payment-card data. - Grading or authentication records. - Collection inventories. The absence of a category from the Have I Been Pwned listing is not proof that no such information was accessed. Public reporting reviewed for this page does not establish that those categories were part of the released dataset. ## Why can physical-address data matter to collectors? A physical address combined with a known relationship to a collectibles platform may make phishing, impersonation, false shipping messages, fraudulent sale or trade communications, or other targeting more convincing. The public sources do not establish: - That every affected account included a physical address. - Whether a particular address was an account, billing, shipping, grading-submission, marketplace, or other address. - That every listed address belonged to a person who stored valuable collectibles there. - That collection holdings or item values were part of the released dataset. ## What is reported and what remains under investigation? Publicly reported: - Have I Been Pwned has indexed the dataset and lists 1,041,238 affected accounts. - Have I Been Pwned dates the breach to November 9, 2025. - Have I Been Pwned reports that the incident was accompanied by website-content defacement. - Have I Been Pwned reports that stolen data was advertised for sale and portions were later released publicly. - The listed data categories are names, usernames, email addresses, phone numbers, and physical addresses. Issues that remain under investigation: - How the reported attacker accessed Beckett systems and customer records. - How many distinct people in the United States and individual states were affected. - Which data fields were associated with each particular user. - What type of physical address was associated with each record. - When Beckett learned of the incident and completed its investigation. - What notices, if any, Beckett sent to individual users or regulators. - How Beckett assessed whether notification was required under applicable law. - Whether the publicly released dataset is complete. - Whether users experienced targeted phishing, impersonation, account misuse, delivery interference, fraud, theft concerns, financial loss, or time loss. ## Who may want to contact Hall Attorneys? Hall Attorneys is interested in hearing from: - Current or former Beckett.com account holders whose email address appears in the reported dataset. - Collectors who used a Beckett account for grading, authentication, price-guide, registry, marketplace, or trade services. - Customers whose name, phone number, username, billing address, or shipping address may have been involved. - Users who received a Beckett security, privacy, or breach communication. - Users who experienced targeted grading, authentication, marketplace, trade, sale, delivery, or account messages after the incident. - Users who experienced account misuse, delivery interference, fraud, theft concerns, financial loss, or time loss potentially related to the incident. ## What should Beckett users do now? - Use a strong, unique password for the Beckett account. - Change any password that was reused on another website or application. - Enable multi-factor authentication where available. - Watch for phishing involving Beckett, BGS, grading, authentication, marketplace transactions, trades, sales, purchases, deliveries, or account verification. - Verify unexpected requests through a known Beckett website or contact method rather than an unexpected link or phone number. - Review shipping notices and account activity for changes you did not request. - Preserve account, submission, order, marketplace, trade, shipping, security, and loss records. ## Evidence preservation guidance Preserve: - Beckett account-creation emails, profile screenshots, usernames, membership records, and subscription records. - Any security, privacy, or breach communication received from Beckett. - Grading and authentication submission forms, order confirmations, invoices, status updates, and certification records. - Marketplace messages, trade records, receipts, shipping labels, tracking notices, and delivery-change communications. - Password-reset emails, unfamiliar-login notices, and unexpected authentication prompts. - Phishing emails, texts, calls, and direct messages referencing Beckett, collectibles, account details, transactions, or deliveries. - A dated screenshot or PDF if a reputable breach-notification service reports that an email address appears in the Beckett dataset. - A timeline of suspected misuse, mitigation work, time spent, out-of-pocket expenses, financial losses, delivery problems, and theft concerns. Do not send passwords, authentication codes, complete payment-card numbers, government identification, unredacted financial records, or detailed collection-location information through an ordinary website form or email. Preserve those materials and wait for a secure follow-up channel if they are needed. ## Issues Hall Attorneys is investigating - How the reported attacker accessed Beckett systems and customer records. - How Beckett protected and monitored systems containing customer account and address information. - How many United States customers and residents of individual states were affected. - Which data fields were associated with each person. - Whether affected addresses were account, billing, shipping, grading-submission, marketplace, or other records. - When Beckett learned of the incident. - How Beckett assessed the need to notify affected users or regulators. - Whether users experienced targeted phishing, impersonation, account misuse, delivery interference, fraud, theft concerns, financial loss, or time loss. ## FAQ Question: Is this a filed Beckett lawsuit? Answer: No. This page describes an investigation by Hall Attorneys. Hall Attorneys has not stated that it filed a lawsuit over the Beckett Collectibles incident. Question: How many Beckett accounts may be affected? Answer: Have I Been Pwned currently lists 1,041,238 affected accounts. That figure refers to accounts or email addresses in the indexed dataset and does not establish that every person had every listed data category exposed. Question: What information was reportedly exposed? Answer: Have I Been Pwned lists names, usernames, email addresses, phone numbers, and physical addresses. The information associated with a particular person may vary. Question: Were Beckett passwords exposed? Answer: Have I Been Pwned does not list passwords among the compromised data categories for this incident. Users should still use a unique password, change any password reused on another service, and enable multi-factor authentication where available. Question: Were payment-card numbers or collection inventories exposed? Answer: Have I Been Pwned does not list payment-card information or collection inventories among the compromised data categories. Public reporting reviewed for this page does not establish that those categories were part of the released dataset. Question: Why can a physical-address disclosure matter to collectors? Answer: A physical address combined with a known relationship to a collectibles platform may make phishing, impersonation, false shipping messages, or other targeting more convincing. The public sources do not establish that every listed address belonged to a person who stored valuable collectibles there. Question: Who may want to contact Hall Attorneys? Answer: Current or former Beckett users may want to contact the firm if their email appears in the reported dataset, they received a notice, their physical address or phone number may have been involved, or they experienced related phishing, account misuse, delivery issues, fraud, theft concerns, financial loss, or time loss. Question: What should I do after the Beckett breach? Answer: Use a unique password, enable multi-factor authentication where available, watch for targeted grading, marketplace, trade, or shipping messages, verify requests through a known Beckett address, and preserve relevant account, order, shipping, and security records. Question: Is Hall Attorneys affiliated with Beckett, Mozilla Monitor, or Have I Been Pwned? Answer: No. Hall Attorneys is not affiliated with Beckett Collectibles, Mozilla Monitor, or Have I Been Pwned. ## Source basis - Have I Been Pwned, Beckett Collectibles Data Breach, added November 20, 2025: https://haveibeenpwned.com/Breach/Beckett - Mozilla Monitor, Beckett Collectibles Data Breach: https://monitor.mozilla.org/en/breach-details/Beckett - Value Added Resource, "Beckett Collectibles Silent After Alleged Data Breach, Customers Demand Answers," published November 19, 2025 and updated December 9, 2025: https://www.valueaddedresource.net/becket-collectibles-alleged-data-breach/ - Beckett Collectibles, About Us: https://www.beckett.com/about-us ## Notice Attorney advertising. Hall Attorneys is not affiliated with Beckett Collectibles, Mozilla Monitor, or Have I Been Pwned. This page concerns an investigation, not a filed lawsuit. The public reports described above include attributed claims and evolving information. Sending information does not create an attorney-client relationship. Do not send passwords, authentication codes, complete payment-card numbers, government identification, unredacted financial records, detailed collection-location information, or other highly confidential information unless Hall Attorneys specifically requests it through a secure channel.