Hasbro breach may have exposed employee personal data
Hasbro notified current and former employees that a security incident earlier this year may have exposed names, contact details, national ID numbers and financial information.
Hasbro notified current and former employees that a security incident earlier this year may have exposed personal data including names, contact details, national identification numbers and financial information.
Notification letters filed with the Massachusetts Attorney General’s Office list 436 Massachusetts residents as affected and say the affected data varies by person. The company has not disclosed a total number of impacted employees. Revelio Labs reports Hasbro has roughly 4,600 employees worldwide, most in the United States.
Hasbro launched an investigation and engaged outside cybersecurity experts after identifying the incident. The notification letters provide limited detail about how the data was accessed or which systems were involved.
The notifications do not explicitly link the disclosure to a late-March cyberattack that previously disrupted Hasbro systems and led to outages. Hasbro did not confirm whether the two incidents are connected.
Letters to employees state the company is ‘not aware of any misuse of personal data’ and that it ‘took immediate action to address the incident.’ The company is offering affected individuals identity protection services through a third-party provider.
At the time of the filing, the notifications did not appear on other state attorney general websites. No known cybercrime group has posted Hasbro on a data-leak site, and the company has not reported confirmed fraud tied to the incident. Investigations into the scope of exposed data and any potential misuse are ongoing.








