Beckett Collectibles 2025 Data Breach

Beckett Collectibles Sports Card Marketplace Breach (2025): 1 Million User Records Including Home Address Exposed — Website Defaced

Company · Collectibles grading and authentication · Sports and memorabilia certification services · USA

Beckett Collectibles Sports Card Marketplace Breach (2025): 1 Million User Records Including Home Address Exposed — Website Defaced

Sports and entertainment collectibles grading and marketplace.

Confirmed · ObscureIQ Intelligence
Breach Risk Index i
39/100
Lower riskHigher risk
Moderate: notable exposure with meaningful misuse potential.
Data Sensitivity i
Standard
Exposed data is largely lower-sensitivity. Standard identity-protection precautions are advised.
1.0MRecords
2025Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
AddressPhysical address
Classification Tags
Retail & CommerceCollectiblesDirect Customers2025

Breach Summary

Beckett Collectibles suffered a data breach in November 2025 that included the public defacement of part of its website. A threat actor advertised the stolen database for sale on a hacking forum, and portions of the data circulated publicly through dark-web markets and breach-tracking sites in the weeks that followed.\n\nThe leaked data covered more than one million customer records. Fields included names, usernames, email addresses, phone numbers, and physical billing and shipping addresses. The first publicly circulating subset of around 541,000 email addresses focused on North American customers, with a larger corpus of about 1.04 million records surfacing the following month. Have I Been Pwned independently verified and indexed the dataset.\n\nBeckett Collectibles did not publicly confirm or characterize the incident in any detail in the immediate aftermath, leaving affected users to learn of the breach through cybersecurity outlets and breach-tracking services. For affected individuals, the principal risks are phishing, account takeover at services where the same email and password were reused, and physical-security concerns linked to the exposure of home shipping addresses. Customers who hold high-value collectibles face an elevated targeting risk, since the dataset effectively maps a population of likely owners of expensive cards and memorabilia. Anyone with a Beckett account should change passwords there and on any service using the same credentials, and treat any unsolicited contact about pickup, authentication, or shipping with caution.

Full threat analysis, exploitation vectors, and principal guidance below.

10 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

1.0M records analyzed

About Beckett Collectibles

Beckett Collectibles is a U.S.-based grading, authentication, and marketplace company focused on sports cards, trading cards, and entertainment collectibles. The brand traces back to 1979 as a price guide and has since grown into a multi-service business covering certification, magazines, online marketplace listings, and submission management. Its customer base ranges from casual hobbyists to professional dealers and high-value collectors. The business operates from offices in the Dallas-Fort Worth area and processes large volumes of customer submission, shipping, and payment-related records as part of its grading and trading workflow.

Why They Hold Your Data

Collectibles-grading and authentication firms collect customer identity, addresses, order history, item-submission records, payment-adjacent data, and collector account activity across appraisal and marketplace workflows.

Recent Developments

A data breach involving Beckett Collectibles came to public attention in mid-November 2025, accompanied by website content defacement. Customer records were advertised for sale on a hacking forum, and portions of the dataset were subsequently leaked publicly. As of early 2026, Beckett Collectibles had not issued a public statement directly acknowledging or characterizing the incident, and customers reported that the company had temporarily made phone support unavailable as inquiries surged. Have I Been Pwned independently verified and indexed the leaked data, ultimately covering more than 1 million records.

Data Points Exposed

5 verified field types
Email Address
Full Name
Phone Number
Physical address High
Username

Breach Impact

The most prominent institutional cost so far has been reputational rather than financial. Beckett's silence in the weeks after the breach surfaced drew sharp customer criticism on social media and prompted independent cybersecurity outlets to publish follow-up coverage when the company did not. There has been no public regulatory action, settlement, or class-action filing announced as of early 2026, but the underlying conditions for one exist: a verified breach of consumer data, a high-value customer base, and a notable gap in disclosure. Operationally, Beckett's grading and marketplace services have continued, and there is no public indication that authenticated grading workflows themselves were affected.

Exploitation & Downstream Threats

• SIM swap attacks where phone numbers are present | • Targeted phishing campaigns using exposed email addresses | • Doxxing risk from physical address exposure

Principal Risk Advisory

What this means for a principal

A consumer-service breach: contact and account data supports phishing, account takeover and profile enrichment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.

What You Should Do

  1. Treat the home address as exposed: review mail and package handling and physical-security routines, and brief household staff to verify unusual requests.
  2. Guard against SIM-swap and vishing: add a carrier port-out PIN and verify any 'support' calls independently.
  3. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping and footprint neutralization: cross-reference against broker-available data and suppress still-removable elements, prioritizing address and phone, since this record re-seeds broker networks.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation