Hasbro disclosed that attackers accessed personal and financial information belonging to current and former employees after compromising an employee account. Data exposed varied by individual and included names and contact details, Social Security or other national identification numbers, financial-account and payment-card details, and driver’s-license information. Massachusetts notification records show 436 affected employees in the state.
Hasbro said it disabled the compromised account, terminated unauthorized access, and added safeguards. The company reported no known misuse of the information and is offering identity-protection services to affected individuals. It did not confirm whether the breach was linked to the late-March cyberattack that disrupted operations and reportedly cost roughly $25 million in lost revenue; no threat actor had publicly claimed responsibility.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
A cyberattack forced Hasbro to take some systems offline and disrupted operations. Hasbro later attributed approximately $25 million in lost revenue to the incident, while not confirming it was related to the employee-data breach.
Hasbro identified a security incident involving its network earlier in 2026. Its investigation found that personal information of current and former employees may have been accessed.
Hasbro notified relevant law-enforcement authorities after detecting unauthorized access to its internal network and beginning its investigation into the employee-data breach.
Hasbro said it disabled the compromised employee account, terminated unauthorized access, and deployed additional safeguards. It engaged external cybersecurity experts and offered affected individuals third-party identity-protection services; it reported no known misuse of the data.
Hasbro submitted breach-notification letters to the Massachusetts Attorney General and notified affected current and former employees that personal and financial information may have been accessed. The Massachusetts filing listed 436 affected residents, with exposed data potentially including Social Security numbers, financial-account or payment-card information, and driver's-license information.
The March cyberattack reportedly caused approximately $11 million in direct response and cleanup costs, alongside roughly $25 million in lost revenue from operational disruption.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
5 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourcesecuritymagazine.com
Open sourcecysecurity.news
Open sourcesecurityweek.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.