Hasbro, the company behind brands such as Nerf, Magic: The Gathering, Dungeons & Dragons and Monopoly, has begun notifying current and former employees that their personal information was exposed in a data breach. The disclosure came through a filing with the Massachusetts Attorney General’s office, first reported by BleepingComputer on August 28, 2026, with additional detail published by SecurityWeek the following day.
According to Hasbro’s notification letter, attackers gained access through a compromised employee account. The company told affected staff that exposed information “may have included your name and one or more additional personal information elements such as email, address, phone number, national ID number, or financial information.” The filing submitted to Massachusetts regulators was more specific about what was taken from employees in that state, listing Social Security numbers, financial account details, credit and debit card numbers, and driver’s license information.
At least 436 employees in Massachusetts were confirmed as affected in that state’s filing. Hasbro has not disclosed how many employees were affected company-wide. The toy and game maker employs roughly 4,600 people globally, though it is unclear what share of that workforce had data exposed in this incident.
Hasbro said it responded by disabling the compromised account, cutting off the unauthorized access, and adding further security safeguards. The company is also offering identity protection services to those affected and said it is “not aware of any misuse of personal data” resulting from the incident. No cybercriminal group had publicly claimed responsibility for the breach or listed Hasbro on a dark web leak site as of publication.
This disclosure is separate from an earlier cyberattack that hit Hasbro on March 28, 2026, when the company took select systems offline as a precaution while investigating what it described at the time only as a security incident affecting certain internal systems. That earlier disruption lasted several weeks and, according to BleepingComputer’s reporting, cost the company approximately 25 million dollars in lost revenue. Hasbro has stated that the newly disclosed employee data breach is not linked to the March attack, though it has not explained what caused the compromised account or when it first discovered the intrusion.
Breaches involving a single compromised account remain one of the more common ways companies lose employee data, since a stolen login can hand an attacker legitimate-looking access to internal systems without the need to exploit a software flaw. Hasbro has not detailed what authentication protections, such as multi-factor authentication, were in place on the account involved.
Hasbro has not issued further public comment beyond its notification letter and regulatory filing as of this writing.
Source: BleepingComputer, “Toy-making giant Hasbro disclose data breach affecting employees” and SecurityWeek, “Hasbro Data Breach Exposed Employee Personal Information”.
