Skip to main content
Cardboard Journal

← The Wire

A collector's Beckett data-breach suit vanished the week the site went dark

The lawsuit vanished exactly when Beckett's site did — with no explanation for either.

Cardboard JournalOur analysis

Two facts landed in the same week, and neither party has explained the overlap. On 5 August, Douglas Larson sued Beckett in New Mexico federal court over a November 2025 breach that exposed roughly a million accounts — names, emails, phone numbers and physical addresses. Beckett never publicly addressed the breach when cybersecurity researchers first reported it, and it still has not filed a response to Larson's complaint. On 11 September, Larson voluntarily dismissed the case. That same week Beckett took its entire site and app offline for what it called "infrastructure enhancements" — the outage this wire already covered, which killed cert lookup, the pop report, price guide, marketplace, registry and account access with no restoration date given.

A voluntary dismissal proves nothing by itself. Plaintiffs drop cases for many reasons — a private settlement with a confidentiality clause that never reaches the public docket, an unfavorable early signal on Beckett's arbitration clause, or a decision to refile elsewhere. Value Added Resource, which broke the original breach story in November 2025, flagged the timing itself and stopped short of connecting the two events. This site does the same: there is no public record tying the dismissal to the outage, and no evidence the infrastructure work has anything to do with the security failures the complaint alleged.

What is documented is the breach itself. Have I Been Pwned catalogued an initial release of more than 500,000 North American email addresses in November 2025, followed a month later by a set of more than a million. The complaint says Beckett kept years-old customer and transaction records with no apparent need to. None of that changes because one plaintiff walked away from one lawsuit — anyone with an older Beckett account should still treat unsolicited messages about a grading order or authentication as suspicious until verified by logging in directly.

Back to The Wire

See An Error? Have Feedback?

This site is only as good as the data behind it. If something looks wrong, out of date, or missing — or you just have a thought about it — tell us and we'll take a look.

Contact Us