Hasbro Data Breach Exposes Employee Personal Information in March Attack
Toy and game giant Hasbro has begun notifying employees that their personal information was compromised in a data breach potentially linked to a March cyberattack. Notification letters submitted to the Massachusetts Attorney General's Office reveal that exposed data varies by individual but may include names, email addresses, postal addresses, phone numbers, national ID numbers, and financial information. While the total number of affected individuals remains unclear, the Massachusetts filing reports 436 state residents impacted, and Revelio Labs data indicates Hasbro employs roughly 4,600 people worldwide, the majority based in the United States. Employees concerned about credential exposure can verify their email addresses using our email breach checker.
The breach appears connected to a cyberattack that targeted Hasbro in late March, which forced the company to take several systems offline and caused operational disruptions. When SecurityWeek asked Hasbro to confirm the link, the company did not provide a direct answer. A Hasbro spokesperson stated the organization identified a security incident involving its network earlier this year and took immediate action, including engaging external cybersecurity experts to investigate the scope of the intrusion. The investigation concluded that current and former employees' personal information may have been accessed during the incident.
Hasbro has stated it is not aware of any misuse of the exposed data and has no indication the information will be misused, though the company is offering identity protection services through a third-party provider as a precaution. At the time of writing, no known cybercrime group had listed Hasbro on its leak site, leaving the attribution and full scope of the attack undetermined. SecurityWeek senior managing editor Eduard Kovacs reported the story. Affected individuals are advised to update credentials on any accounts associated with their work email and run a password checker to identify weak or reused passwords, along with a privacy checkup to assess their overall digital exposure.