Toy and game giant Hasbro is notifying current and former employees that their personal information may have been compromised during a cybersecurity incident earlier this year. The disclosure adds a data-privacy dimension to an attack that had already caused significant operational and financial disruption across the company.
According to breach notifications filed with the Massachusetts Attorney General’s Office, the compromised information varies by individual but may include names, email addresses, postal addresses, phone numbers, national identification numbers and financial information. Hasbro has not publicly disclosed the total number of people affected.
The breach appears connected to an earlier cyberattackHasbro experienced a cyberattack in late March that forced the company to take some systems offline while it investigated and contained the incident. Those shutdowns disrupted normal operations and ultimately had a measurable financial impact.
The company reported approximately $11 million in direct expenses related to responding to the attack, while system outages delayed roughly $25 million in product sales. Those figures illustrate how the cost of a modern cyberattack can extend well beyond incident response, affecting revenue and business operations even before the consequences of stolen data are fully understood.
SecurityWeek asked Hasbro whether the newly disclosed employee breach was directly connected to the March attack. The company did not explicitly confirm the connection, but said it had identified a network security incident earlier this year and immediately began investigating with external cybersecurity specialists.
That investigation eventually determined that personal information belonging to some current and former employees may have been accessed.
Employee data creates long-term risksWhile customer breaches often attract greater attention because they can involve millions of records, compromised employee information can be particularly valuable to attackers.
National identification numbers and financial information can potentially support identity theft and fraud. Contact information can also be combined with knowledge about an employee’s role to construct convincing phishing or social-engineering campaigns.
The danger does not necessarily disappear when the original incident is contained. Information obtained during a breach can remain useful for years, especially when it includes identifiers that cannot easily be changed.
Hasbro said it is not aware of any misuse of the compromised personal information and has no indication that the data will be abused. As a precaution, the company is providing affected individuals with identity protection services through a third-party provider.
The full scale remains unclearThe Massachusetts filing indicates that 436 residents of the state were affected, but that figure does not represent the total number of victims. Hasbro employs roughly 4,600 people worldwide, with a significant portion of its workforce based in the United States.
SecurityWeek estimates that the overall number of affected individuals could range from hundreds to several thousand, although Hasbro has not provided a definitive number. At the time of reporting, similar breach notifications had not appeared on other state attorney general websites.
There is also currently little public information about how attackers initially entered Hasbro’s environment, how long they maintained access or precisely which systems were compromised.
No ransomware group has claimed the attackAnother unresolved question is who was responsible.
No known ransomware or cyber-extortion group has listed Hasbro on its public leak site, according to SecurityWeek. That does not rule out ransomware, data theft or financially motivated attackers, but there is currently insufficient public evidence to attribute the incident to a specific threat actor.
The absence of a public extortion claim is also notable because many major corporate breaches now become visible when attackers threaten to publish stolen information. In Hasbro’s case, the company appears to have disclosed the exposure through the regulatory notification process rather than in response to a public leak.
A breach can have several costs at onceHasbro’s experience demonstrates why measuring cyber incidents purely through the number of compromised records can be misleading. The company had to respond to an intrusion, temporarily shut down systems, absorb millions of dollars in recovery expenses and deal with delayed sales. It is now also responsible for breach notifications and identity protection for affected employees.
The incident therefore combines three different categories of cyber risk:operational disruption, direct financial loss and long-term exposure of personal information.
For organizations, that combination reinforces the importance of protecting internal employee systems with the same attention traditionally given to customer-facing infrastructure. HR and corporate platforms can contain highly concentrated collections of personal and financial information, making them valuable targets even when attackers never touch customer databases.
For Hasbro, the immediate operational crisis may have passed, but the disclosure shows how the consequences of a cyberattack can continue emerging months after systems have been restored.
Original report at SecurityWeek