Skip to main content

Morning Overview

See’s Candies and ASOS turn up on one state’s running breach list

Washington State’s attorney general keeps a public directory of data breach notices, and two household consumer names sit on it side by side: See’s Candies, Inc., logged on 09/02/2026 with 628 Washingtonians affected, and ASOS, whose American sales arm filed the notice, logged on 08/21/2026 with 1,929. The listing is the Washington Attorney General’s Data Breach Notifications page, which publishes the filings that companies submit under state law, and the entries carry the dates, resident counts and categories of data each company reported.

The two cases look nothing alike once the underlying notices are opened.

Washington’s attorney general directory as a running register

The page describes itself as listing breach notices submitted to the attorney general in accordance with RCW 19.255 and RCW 42.56.590, the first statute covering businesses and the second covering state and local agencies. On the day of the read the Data Breach Notifications directory showed its newest entries dated 09/11/2026 and ran back across at least 38 pages of earlier filings. Each row names the organization, the date reported, the breach date, the number of Washingtonians affected and the data compromised, and it links to the PDF the company filed.

The reason a candy company in California and a British online retailer appear on a Washington list is the state’s reporting rule. RCW 19.255.010 requires a business to tell affected residents within 30 calendar days of discovering a breach, and to tell the attorney general in the same window when more than 500 Washington residents are involved. The notice to the attorney general must give the number of affected consumers, the types of information, the timeline of exposure, the containment steps taken and a sample letter. The Attorney General’s office summarizes the same thresholds on its breach notification laws page.

See’s Candies and a network intrusion that began April 11

On the directory, See’s Candies, Inc. shows a reported date of 09/02/2026, a breach date of 04/11/2026 and 628 Washingtonians affected. The categories listed are name, Social Security number, driver’s license or Washington ID card number, full date of birth, passport number and medical information. The filed See’s Candies notice says an unauthorized user reached parts of the company’s network between April 11 and 13, 2026, encrypted files on several servers, and took certain files before doing so. According to the letter, at least some of those files were made available on the dark web.

The same notice gives a timeline that explains why the filing came months after the intrusion. See’s discovered the incident on April 12, first identified impacted Washington residents on July 20, and counted 618 of them by August 13. It mailed letters on August 27 and September 2. The company offered a 12-month Experian IdentityWorks membership, identity restoration services and $1 million in identity theft insurance, with an enrollment deadline of December 31, 2026.

ASOS and a credential-stuffing run in late July

ASOS’s American sales arm appears with a reported date of 08/21/2026, a breach date of 07/28/2026 and 1,929 Washingtonians affected. The directory lists name, financial and banking information, full date of birth, and email address with password or security-question answers. The ASOS filing describes a credential-stuffing attack, meaning criminals tried login details harvested elsewhere against customer accounts. ASOS says it spotted unusual traffic on its website on July 28, confirmed and secured the situation the next day, and began notifying customers on July 30, with all notices due by August 24.

The company’s letter puts the worldwide toll at 138,828 customers, of whom 1,929 were in Washington, and reports that 55 unauthorized orders were placed worldwide and none in Washington. It says payment card details were redacted and that data was encrypted in transit and at rest. The two filings differ on categories: the directory row for ASOS lists banking and financial information, while the letter text emphasizes names, addresses, phone numbers, the last four card digits, expiration dates, social media details and birth dates. Mandatory password resets, account blocking and added anti-bot controls followed.

One is a network intrusion at a candy maker that ended with encrypted servers and stolen files, the other a credential-stuffing run against a fashion retailer’s customer accounts that was shut down within a day. The size of the two entries is worth stating plainly. Neither approaches the larger filings that appear elsewhere on the directory, and the 628 and 1,929 figures count only Washington residents, not each company’s national or global total, which the See’s notice does not give and the ASOS letter puts at 138,828 customers. A reader scanning the register for patterns would find intrusions through stolen network access and through stolen passwords sitting in adjacent rows, filed months apart from the events they describe.

Both rows are small beside the other listings that sit around them on the page, yet they are the two that carry consumer names most readers recognize, and each links to a primary document that shows exactly what the company told Washington’s attorney general.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview


Morning Overview is reader-supported. Some links in our articles are affiliate links, and we may earn a commission at no extra cost to you. As an Amazon Associate I earn from qualifying purchases. Full disclosure.