"The information involved varied by individual but may have included your name and one or more additional personal information elements such as email, address, phone number, national ID number, or financial information," Hasbro said in its disclosure.
Hasbro's description of the breach and what it may have exposed
Hasbro, the publicly traded toy and game company founded in 1923 and owner of brands such as Monopoly, Clue, Nerf, Transformers, Play‑Doh, Peppa Pig, Scrabble, Magic: The Gathering and Dungeons & Dragons, disclosed that attackers accessed the personal and financial information of an undisclosed number of employees.
In letters filed with the Massachusetts Attorney General's Office, the company said the specific elements of information accessed varied by individual and "may have included" names plus one or more of the following elements: email, address, phone number, national ID number, or financial information.
Massachusetts Attorney General report: 436 employees' most sensitive records exposed
Although Hasbro's notification letters did not state a total number of affected individuals or provide a detection date, the Massachusetts Attorney General's Office included a concrete figure in its 2026 Data Breach Notification Report. According to that report, the breach affected the Social Security numbers, financial account information, credit/debit card numbers, and driver's license information of 436 Hasbro employees in Massachusetts.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleRemediation steps Hasbro says it implemented
Hasbro told affected individuals it had implemented containment and remediation measures. Those measures, as described by the company, included disabling the compromised employee account, terminating unauthorized access, and deploying additional safeguards "designed to help prevent a similar incident from occurring in the future."
When BleepingComputer contacted Hasbro to ask whether any customers were also affected and whether the attackers issued a ransom demand, a Hasbro spokesperson was not immediately available for comment, the outlet reported.
The March 28 systems outage and reported financial impact
Earlier in the spring Hasbro disclosed a separate cyberattack that struck its systems on March 28 and forced the company to take some systems offline while restoring them. At the time the company filed a notice with the U.S. Securities and Exchange Commission (SEC) warning investors of "some delays" and saying interim measures for business continuity "may continue for several weeks before the situation is fully resolved."
In subsequent financial reports, Hasbro said it lost approximately $25 million in revenue because of that cyberattack. The company has not linked the March incident directly to the employee data breach disclosed in the Massachusetts filings.
What this means for Hasbro employees, customers, and regulators
- Hasbro employees: According to the Massachusetts report, 436 employees in Massachusetts had highly sensitive identifiers exposed, including Social Security numbers, financial account data, credit/debit card numbers, and driver's license information. Those individuals and any others notified will face the task of monitoring financial accounts and identity records, and following any remedies offered by the company.
- Customers: Hasbro's public notifications and the BleepingComputer exchange indicate the company had not confirmed whether customers were affected; a Hasbro spokesperson was not immediately available to answer that question. Customers who receive direct communications from Hasbro will need to evaluate those notices against their own accounts and transactions.
- Regulators and investors: Hasbro filed notification letters with the Massachusetts Attorney General and issued an SEC filing about the March systems outage. Regulators and investors now have discrete records from both channels: the AG's 2026 Data Breach Notification Report documents employee identity exposure in Massachusetts, while SEC filings described operational disruption and an estimated $25 million revenue impact.
Two concrete points remain in the public record: Hasbro has described the types of employee information the attackers accessed and said it took steps to disable the compromised account and terminate unauthorized access; and the Massachusetts Attorney General's Office quantified the exposure for employees in that state as 436 people whose Social Security numbers and other sensitive identifiers were exposed. The company has not publicly tied the March 28 systems outage to these employee data disclosures, and a spokesperson did not immediately answer questions about customer impact or a ransom demand.




