Hasbro disclosed that a sophisticated cyber intrusion hit the company on March 28 and forced some systems offline, disrupting order processing, shipping, and invoicing across parts of its business. The toy and entertainment company, known for brands including Peppa Pig, Transformers, and Magic: The Gathering, said the incident may have exposed certain internal systems and triggered delays for customers, while the full scope of the breach and any potential data compromise remain under investigation.
The company said it contained the attack and brought in third-party cybersecurity and forensic specialists to support containment, assessment, and recovery, but warned that restoration would take weeks and that the disruption is expected to affect second-quarter revenue and operating profit. Hasbro said business continuity measures have allowed some orders and shipments to continue, including planned releases, and it expects most delayed activity to be recovered later in the year, while also incurring investigation and advisory costs and delaying its first-quarter earnings release.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
In a later SEC filing, Hasbro said the attack had been contained but restoration was still ongoing and that delays from the incident were expected to affect second-quarter revenue and operating profit. The company also said most delayed business should be recovered in the second half of the year, while it incurred investigation and advisory costs and delayed its first-quarter earnings release.
Hasbro publicly disclosed the cyberattack in SEC-related reporting, saying the incident could disrupt manufacturing, order processing, shipping, and invoicing while the full scope remained under investigation. Early reporting noted recovery could take weeks and raised uncertainty over whether ransomware or customer-data compromise was involved.
Hasbro disclosed that it suffered a sophisticated cyber intrusion on 2026-03-28. The company began containment and assessment efforts with third-party cybersecurity and forensic specialists, and some internal systems were taken offline.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
5 references tracked. Mallory keeps watching after this page renders.
cybersecuritydive.com
Open sourcecybersecurity-insiders.com
Open sourcecybernews.com
Open sourcecybersecuritydive.com
Open sourcebbc.co.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.