Hibbett Retail, Inc.
ent_daf3307c25bbe4e919fd8e8c
Disclosures
6
State AG · 6 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
15,223
as filed · State AG TX
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Hibbett Retail, Inc.
- Normalized
- hibbett retail— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (6)newest first
- Texas State AGas victim2026-09-09
Hibbett Retail, Inc. based in Birmingham, Alabama, a business – retail or merchant entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-07-26 and reported on 2026-09-09. 15,223 Texas residents were affected. 109,732 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Driver’s License number;Government-issued ID number (e.g. passport, state ID card);Financial Information (e.g. account number, credit or debit card number);Medical Information;Health Insurance Information;Date of Birth. Consumers were notified via U.S. Mail.
- Washington State AGas victim2026-09-08
Hibbett Retail, Inc., a business sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2026-04-27 and filed notice on 2026-09-08. 510 Washington residents were affected. 134 days elapsed between awareness and notification. 5 days to identify the breach. 0 days to contain the breach.
- New Hampshire State AGas victim2026-09-08
Hibbett Retail, Inc. reported that an unknown third party gained unauthorized access to its computer systems between April 22 and April 25, 2026. The company discovered suspicious activity on April 27, 2026. The incident affected 52 New Hampshire residents, involving exposure of names, Social Security numbers, and dates of birth from personnel records. Hibbett engaged forensic experts, notified law enforcement, and implemented security enhancements to its Microsoft 365 environment.
- California State AGas victim2026-09-08
Hibbett Retail, Inc. reported unauthorized access to employee personal information (name and engagement number) occurring between April 22 and April 25, 2026. The incident affected employees of Hibbett and its affiliates. The company engaged Kroll for investigation and is offering identity restoration services via Experian. No specific attack vector or malware was identified in the notice.
- South Carolina State AGas victim2026-09-08
Hibbett Retail, Inc. experienced unauthorized access to its computer network between April 22 and April 25, 2026. An unknown third party accessed personnel records for current and former employees, potentially exposing names, Social Security numbers, bank account numbers, and employment information. The company engaged forensic experts, notified law enforcement, and secured systems. Affected individuals are offered one year of complimentary credit monitoring.
- Massachusetts State AGas victim2026-09-01
Hibbett Retail, Inc. notified former employees that unauthorized access may have occurred involving their name and employment-related information. The company is offering identity restoration services through Experian. The specific nature of the breach, dates of occurrence, and number of affected individuals were not detailed in the provided excerpt.