The Hasbro employee data breach has claimed at least 436 victims in Massachusetts alone, with attackers accessing Social Security numbers, financial account details, credit and debit card numbers, and driver’s licence information, according to the Massachusetts Attorney General’s Office 2026 Data Breach Notification Report. The toy and games giant, which owns brands including Monopoly, Nerf, Transformers and Dungeons & Dragons, has not disclosed the total number of affected employees across all states.

What was exposed in the Hasbro employee data breach

In breach notification letters filed with the Massachusetts Attorney General’s Office, Hasbro described the compromised information in carefully hedged terms. ‘The information involved varied by individual but may have included your name and one or more additional personal information elements such as email, address, phone number, national ID number, or financial information,’ the company said. The letters do not state when the incident was detected, nor how many employees were affected in total.

What the AG’s own report fills in is considerably more specific. For the 436 Massachusetts employees on record, the exposed data extended to Social Security numbers, financial account information, credit and debit card numbers, and driver’s licence information, categories that sit at the sharper end of identity-theft risk. According to SafeState, the notification letters were formally filed on 28 August 2026.

Hasbro said it responded by ‘disabling the compromised employee account, terminating unauthorized access, and deploying additional safeguards designed to help prevent a similar incident from occurring in the future.’ Whether any customers were also caught up in the breach, or whether the attackers issued a ransom demand, remained unanswered when BleepingComputer sought comment from a Hasbro spokesperson.

A turbulent year for the Pawtucket toymaker

The data breach disclosure lands against an already bruising backdrop for the company. Founded in 1923 and headquartered in Pawtucket, Rhode Island, Hasbro trades on the NASDAQ and, according to Shattered.io, employs roughly 4,600 people worldwide, most of them in the United States. That workforce context matters: 436 affected Massachusetts employees represents a not-insignificant slice of the company’s domestic headcount.

In early April, Hasbro disclosed a separate cyberattack that struck its systems on 28 March, forcing the company to take some systems offline while restoration work was under way. In a filing with the US Securities and Exchange Commission at the time, Hasbro warned investors of ‘some delays’ and acknowledged that interim business-continuity measures ‘may continue for several weeks before the situation is fully resolved.’

Financial reports filed since then show the cost has been concrete: Hasbro has lost approximately $25 million in revenue as a direct consequence of that cyberattack. Hasbro has not linked the March incident to the data breach disclosed this week in the Massachusetts filings, and the notification letters make no reference to the earlier attack on its systems.

Whether the two events are connected remains an open question the company has not addressed. The March attack was serious enough to trigger an SEC disclosure and weeks of operational disruption; the data breach, affecting employee records down to Social Security and financial account level, is a different category of harm entirely, one that lands on individual workers rather than corporate balance sheets.

Hasbro’s broad brand portfolio (Peppa Pig, Scrabble, Magic: The Gathering, Play-Doh and many others sit alongside the flagship names) means the company’s public profile is consumer-facing, but the breach itself is squarely an internal, employment-data incident. No customer data exposure has been confirmed. The 436 figure covers Massachusetts filings only; the national total, which Hasbro has declined to disclose, could be considerably higher given that SafeState notes most of Hasbro’s roughly 4,600 employees are based in the United States.

Affected employees in Massachusetts have now received formal notification. Hasbro’s next obligation is transparency about the full scope, including whether the total affected count and the range of exposed data types extend beyond what the Massachusetts AG’s report has already put on the public record.

Share.

Software engineer and video game uber-nerd.

Comments are closed.

Exit mobile version