Hasbro is reaching out to current and former staff with word that personal details may have been exposed in a security incident tied to a late-March cyberattack.
The breach notices, filed with the Massachusetts Attorney General’s Office, say affected individuals may have had names, email addresses, postal addresses, phone numbers, national ID numbers, and financial details compromised. Which fields were exposed varies by person.
The March intrusion took systems offline, ran up about $11M in direct cleanup costs, and delayed roughly $25M in product sales. Disclosure filings to Massachusetts regulators put the number of affected residents at 436; the company’s global workforce is about 4,600, mostly in the US.
The company said it has seen no signs that any of the exposed data has been used, and no reason so far to expect it will be. As a precaution, identity protection coverage is being offered through an outside provider. No ransomware crew has posted the company on a leak site, at least none that researchers track.
A spokesperson said the company identified the incident earlier this year, took immediate action, and brought in outside cybersecurity experts to determine what happened and what information may have been accessed.
The disclosure adds Hasbro to a growing list of enterprises that come forward months after an intrusion, underscoring how long it can take to scope a breach and notify victims.
