Beckett Faces Proposed Class Action Over 2025 Data Breach

Liz Morton
Liz Morton


Comments

Beckett Collectibles and Beckett Authentication Services are facing a proposed class action lawsuit over a November 2025 data breach that exposed personal information from approximately one million accounts.

New Mexico resident Douglas Larson filed the complaint August 5 in federal court, accusing Beckett of failing to protect customer information and provide affected users with a complete account of what was compromised.

The lawsuit seeks damages and changes to Beckett’s security and data retention practices. Larson is asking to represent a nationwide class, along with proposed subclasses for New Mexico residents and customers who paid Beckett for grading, authentication or related services.

The case follows months of uncertainty surrounding the incident. Value Added Resource first reported in November that data allegedly taken from Beckett had been advertised for sale on a hacking forum while portions of the company’s website appeared to have been defaced.

Beckett Collectibles Silent After Alleged Data Breach, Customers Demand Answers
Beckett Collectibles gives customers silent treatment as multiple cybersecurity outlets report alleged data breach exposing sensitive personal data.

Screenshots reportedly showed customer records containing names, email addresses, phone numbers and billing and shipping addresses. Beckett had not publicly addressed the reports or provided customers with information about the potential scope of the incident.

Have I Been Pwned later added the breach to its database, reporting that an initial release contained more than 500,000 email addresses associated with North American customers. A larger collection containing more than one million addresses was published the following month. The compromised information reportedly included names, usernames, phone numbers and physical addresses in addition to email addresses.

Larson says his personal Gmail address was included in the leaked data. According to the complaint, he paid Beckett Authentication Services $150 to authenticate a Pink Floyd autographed guitar at the Colorado Springs Comic Con in August 2021.

The submission form required him to provide his name, phone number, physical address and email address under a section labeled “Important for customer notification.” Larson later contacted Beckett through its online and email support systems while trying to obtain the final authentication results and a refund. Those records allegedly contained his contact information, submission number, transaction date, event location and service details.

Larson and his attorneys say they used Have I Been Pwned’s breach verification process to confirm that the same Gmail address he provided to Beckett appeared in the leaked data.

The complaint says the match connects his Beckett transaction and support records to the publicly released data. Larson says he later experienced a sustained increase in spam and phishing attempts and spent time reviewing suspicious messages, securing accounts and monitoring for further misuse.

The complaint also discusses an April 2026 attack against the payment system used by Larson’s website, freedrama.com. According to Larson, the site’s Stripe checkout was flooded with fraudulent transactions. At least one customer’s card was charged and refunded, while other attempted transactions were declined and legitimate payments could not be processed during the incident. He later removed Stripe and moved the site to PayPal, which he says has reduced business.

Larson links the attack to the exposed information, though he does not allege that the breach gave anyone direct access to his Stripe account. The complaint says discovery will be needed to determine whether the incidents were connected.

The complaint accuses Beckett of failing to use reasonable security measures, detect the intrusion quickly and limit how much customer information it retained. Larson questions why Beckett kept years-old contact and transaction records and says the company remained responsible for protecting the information for as long as it retained it.

Beckett is now owned by Collectors, the parent company of PSA and SGC. Collectors announced the deal in December 2025, after the alleged breach occurred. Neither Collectors nor PSA is named as a defendant or accused of involvement in the incident. As Beckett’s current owner, Collectors may oversee its response and any changes to its security or data retention practices.

The complaint also anticipates a possible dispute over arbitration. Its current Member Terms contain an arbitration clause and class action waiver, but those terms took effect in August 2025, years after Larson’s transaction and customer support interactions.

Larson says the 2021 form he retained does not show an arbitration provision. The front refers to additional terms on the reverse side, but his copy does not include them. If Beckett relies on those terms, Larson argues the company would need to produce the version used at the event and show that he agreed to it.

The lawsuit seeks damages for loss of privacy, time spent responding to the breach, unwanted communications, fraud, business interruption and other alleged harm. It also asks the court to require Beckett to explain what was compromised, improve its security practices and delete customer information it no longer needs.

Beckett has not yet responded in court, and the allegations have not been proven. The case could provide the first detailed account of what happened, which systems were affected and why customer records dating back several years remained in Beckett’s possession.

Larson v. Beckett Collectibles, LLC et al.
Case No. 1:26-cv-02563
U.S. District Court for the District of New Mexico

BeckettLegalNewsThe Hobby

Liz Morton Twitter Facebook LinkedIn

Liz Morton is a 17 year ecommerce pro turned indie investigative journalist providing ad-free deep dives on eBay, Amazon, Etsy & more, championing sellers & advocating for corporate accountability.


Recent Comments