Hibbett Retail, Inc. filed a data breach notification in September 2026 after discovering unauthorized access to personal and financial information. The exact number of affected individuals has not been publicly disclosed. If you received a notification letter, monitor your credit reports and financial statements closely, and consider placing a fraud alert or credit freeze immediately.
| Company | Hibbett Retail, Inc. |
|---|---|
| Industry | Retail |
| Data Types Exposed | Full Names, Financial Account Information, Payment Card Details, Contact Information, Other Personally Identifiable Information |
| People Affected | Not Publicly Disclosed |
| Attack Method | Unspecified/Unauthorized Access |
| Regulators Notified | California Attorney General, Washington State Attorney General |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewWhat Happened in the Hibbett Retail Data Breach?
Hibbett Retail, Inc. recently disclosed a data breach that exposed sensitive personal information belonging to customers or employees. The company filed formal notification with state regulators in September 2026, confirming that unauthorized parties gained access to protected data. As a result, affected individuals are now being notified of the incident and the risks it may carry.
According to the filing, the breach discovery date has not been publicly disclosed. This means the exact timeline between when the intrusion began and when Hibbett Retail identified it remains unclear. However, the company did confirm that it filed notifications with regulators once it determined that personal information had been compromised.
Following discovery, Hibbett Retail appears to have launched an internal review to determine the scope of the incident. In many cases like this, companies bring in forensic specialists to assess how attackers gained access and what specific data was touched. Because the notification was filed only recently, additional details about the attack method may still emerge as the investigation continues.
Who was affected?
The population affected by this breach has not been specified in detail within the available filing. Therefore, it isn’t yet clear whether the incident primarily impacted customers, employees, or both groups. Given that Hibbett Retail operates as a retail business, the exposed data could include information tied to in-store or online shoppers, as well as staff records.
The exact number of individuals affected has not been publicly disclosed. Regulatory filings sometimes omit a specific count until a final tally is confirmed. In addition, the geographic scope of the breach is not fully detailed, though the notification to Washington State and California regulators suggests residents in at least these states were included among those notified.
What Information Was Potentially Exposed?
Although Hibbett Retail has not published an exhaustive breakdown of every data element involved, breach notifications of this nature typically point to categories of sensitive personal and financial information. Based on the nature of this filing, the following types of data may have been exposed.
- Full names
- Financial account information
- Payment card details
- Contact information such as addresses or phone numbers
- Other personally identifiable information tied to customer or employee records
If financial account details or payment information were part of this breach, affected individuals could face an elevated risk of fraudulent charges. Criminals often use stolen financial data quickly, either by making unauthorized purchases or by selling the information on illicit marketplaces. As a result, monitoring financial statements closely in the weeks following notification is especially important.
Beyond financial fraud, exposed personal information can also fuel identity theft schemes. For instance, scammers may use names and contact details to craft convincing phishing messages. Because these tactics often mimic legitimate communications, victims may not immediately recognize the danger, which makes early awareness critical.
What is the company doing?
In response to the breach, Hibbett Retail took steps to notify affected individuals and relevant government authorities. The company filed breach notifications with the California Attorney General on September 8, 2026, and with the Washington State Attorney General the following day. These filings represent a formal acknowledgment of the breach and outline the company’s obligations to inform impacted individuals.
Beyond notification, companies facing incidents like this typically undertake additional remediation efforts. These often include strengthening network security, reviewing access controls, and working with cybersecurity professionals to prevent further unauthorized access. While specific protective services such as credit monitoring have not been detailed in the available filing, affected individuals should review any notification letter they receive directly from Hibbett Retail for these offerings.
What Should Affected Individuals Do?
Monitor Your Credit Reports
Affected individuals should check their credit reports regularly in the months following this breach. Because financial information may have been exposed, new fraudulent accounts could appear without immediate notice. Reviewing your credit report from all three major bureaus gives you a clearer picture of any suspicious activity.
You are entitled to a free credit report each year from each bureau, and additional free checks are often available given the frequency of breaches nationwide. In addition, consider spacing out your requests across the year so you have ongoing visibility rather than a single annual snapshot.
Consider a Fraud Alert or Credit Freeze
If your financial account information was part of this breach, placing a fraud alert on your credit file is a strong protective step. This alert requires creditors to take extra steps to verify your identity before opening new accounts in your name. As a result, it can slow down or stop identity thieves attempting to use your information.
A credit freeze offers even stronger protection by restricting access to your credit file entirely. While this means you’ll need to lift the freeze temporarily when applying for new credit yourself, it significantly reduces the risk that someone else could open accounts using your identity. Both options are typically free to set up with each credit bureau.
Watch for Phishing Attempts
Because your contact information may have been exposed, you should stay alert to phishing emails, texts, and phone calls. Scammers often use breach data to make their messages appear more convincing, sometimes referencing your name or partial account details. This means even messages that look legitimate should be treated with caution.
Never click links or provide personal information in response to unsolicited messages. Instead, contact companies directly using verified phone numbers or websites if you’re unsure whether a message is genuine. This simple habit can prevent scammers from tricking you into revealing additional sensitive information.
Review Account Statements Closely
In addition to monitoring credit reports, review your bank and credit card statements for unfamiliar transactions. Even small, unusual charges can indicate that your financial information is being tested by fraudsters before larger charges follow. Therefore, reporting any suspicious activity to your financial institution promptly is essential.
Many banks offer transaction alerts that notify you immediately of new charges. Setting these up can help you catch fraudulent activity in real time rather than discovering it weeks later. If you notice anything suspicious, contact your bank right away to dispute the charges and request a new card if necessary.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
More Information
Official data breach notification from California Attorney General
Official data breach notification report (PDF) from Washington State Attorney General
