Toy and game maker Hasbro has begun notifying current and former employees that a cyberattack exposed their personal and financial information, according to breach notification letters filed with state regulators, including the Massachusetts Attorney General’s Office on August 28, 2026, and reported by BleepingComputer.
The exposed data varied by individual but could include Social Security numbers, financial account information, credit and debit card numbers, driver’s license details, names, email addresses, and phone numbers. The Massachusetts filing alone identifies 436 affected employees in that state; the total number of individuals notified nationwide was not disclosed in the filing reviewed by BleepingComputer.
Response and Unresolved Questions on Scope
Hasbro said it “implemented containment and remediation measures, including disabling the compromised employee account, terminating unauthorized access, and deploying additional safeguards,” and is offering affected individuals complimentary identity-protection services. The company said it has “no indication” the exposed information has been misused.
Hasbro separately disclosed a cyberattack detected on March 28, 2026, that forced systems offline and contributed to an estimated $25 million in lost revenue during the resulting disruption; the company’s current employee-data notification does not formally confirm whether the two incidents are connected, and BleepingComputer’s reporting treats the link as unconfirmed. The disclosure adds Hasbro to a lengthening list of large employers notifying staff of breach exposure this year, following similar notifications from healthcare and logistics firms including McKesson’s disclosure of a ShinyHunters-linked breach earlier this week.

Leave a Reply