← BACK TO FEED
data breachHasbroemployee datacyberattackincident response

Hasbro Breach Exposes Employee Data — Monopoly Money Won't Cover This One

Hasbro has notified employees that their personal information, including names, addresses, phone numbers, national ID numbers, and financial details, may have been compromised in a data breach. The breach likely affects hundreds to a few thousand employees and may be linked to a cyberattack in late March that cost the company $11 million in cleanup expenses and delayed $25 million in product sales. Hasbro states it is unaware of any misuse of the exposed data and is offering identity protection services to those affected.

Hasbro has begun notifying employees that their personal data was compromised in a breach, with the details trickling out via notification letters filed with the Massachusetts Attorney General's Office rather than any proactive public disclosure.

The exposed data varies by individual but potentially includes names, email and postal addresses, phone numbers, national ID numbers, and financial information. That's a fairly comprehensive haul if you're building a dossier on someone.

The exact number of affected employees isn't confirmed, but the Massachusetts filing covers 436 state residents. Hasbro employs around 4,600 people globally, mostly in the US, so the total affected figure is probably somewhere in the hundreds to low thousands. No other state AG offices appear to have published similar filings.

The timing points squarely at the cyberattack Hasbro disclosed in late March, when the company pulled systems offline to contain the damage. That incident alone cost the toymaker $11 million in direct remediation costs and pushed back $25 million worth of product sales due to the resulting downtime.

Asked directly whether this breach notification relates to the March attack, Hasbro declined to give a straight answer. A company spokesperson confirmed a 'security incident involving its network earlier this year' and said the subsequent investigation found that some current and former employee data may have been accessed. The standard assurances followed: no known misuse detected, no indication of further risk, and identity protection services on offer through a third party.

No ransomware or extortion group has claimed Hasbro on a leak site, which either means this wasn't ransomware, or whoever did it is staying quiet for now.

For a company that makes games built around risk and strategy, Hasbro's incident response communications have been notably light on detail. Employees finding out their national ID numbers and financial data may be floating around out there probably deserved a clearer picture a bit sooner.

READ NEXT
Boston Scientific Hit by Cyberattack, Global Operations in ChaosHackers Raid Liechtenstein's Beneficial Ownership Register, Exposing 31,000 PeopleNichirei Cyberattack Leaves Japan's Frozen Food Chain on Ice