Hasbro, one of the world's largest toy and game companies, has disclosed a data breach that exposed personal and financial information belonging to an undisclosed number of employees. The Nasdaq-listed maker of Monopoly, Nerf, Transformers, Magic: The Gathering and Play-Doh confirmed the incident via breach notification letters filed with the Massachusetts Attorney General's Office this week.
What Attackers Accessed
“The information involved varied by individual but may have included your name and one or more additional personal information elements such as email, address, phone number, national ID number, or financial information,” Hasbro wrote in its notification. The Massachusetts Attorney General's 2026 Data Breach Notification Report tallies 436 in-state employees whose Social Security numbers, financial account information, credit and debit card numbers and driver's license details were exposed.
Hasbro says it disabled the compromised employee account, terminated the unauthorised access and deployed “additional safeguards” to prevent a repeat. The filing does not disclose when the intrusion was detected, the total headcount affected outside Massachusetts, or whether a ransom was demanded.
Follow-On To March Cyberattack
In April, Hasbro publicly acknowledged a March 28 cyberattack that forced it to take systems offline while it worked to restore them. In subsequent U.S. Securities and Exchange Commission filings, the company estimated a revenue hit of roughly $25 million from that incident. Hasbro has not tied the March cyberattack to this new set of employee notifications, but the timing has drawn attention from breach analysts as the company continues to remediate.
Part Of A Wider Breach Wave
The Hasbro disclosure lands during a wave of high-profile data theft. Just this week, Manchester Airports Group confirmed a cyberattack affecting 8.7 million customers, and the TITAN ransomware crew pitched AI that sorts 700GB of stolen data an hour. Extortion crews such as ShinyHunters have also been busy, most recently leaking 7.1 million Baxter International records via Salesforce compromise.
Reporting based on coverage from BleepingComputer and the Massachusetts Attorney General's Office 2026 Data Breach Notification Report.
