Hasbro, the American toy and entertainment company behind brands such as Monopoly, Nerf, Transformers, and Dungeons & Dragons, has disclosed a data breach that exposed the personal and financial information of an unspecified number of employees. The company filed data breach notification letters with the Massachusetts Attorney General鈥檚 Office, but it did not reveal the total number of affected individuals or the date the incident was detected. In Massachusetts alone, the breach affected 436 employees, with their Social Security numbers, financial account details, credit and debit card numbers, and driver鈥檚 license information compromised, according to the state鈥檚 2026 Data Breach Notification Report.

Hasbro stated in its notification letters that the information involved varied by individual but could include a person鈥檚 name along with email, address, phone number, national ID number, or financial data. The company said it has implemented containment and remediation measures, including disabling the compromised employee account, terminating unauthorized access, and deploying additional safeguards to prevent a similar incident. A Hasbro spokesperson was not immediately available to comment on whether customers were also affected or if the attackers made a ransom demand.

This disclosure follows a separate cyberattack that Hasbro reported in early April, which hit its systems on March 28 and forced the company to take some of those systems offline while working to restore them. In a filing with the U.S. Securities and Exchange Commission at that time, Hasbro warned investors of potential delays and said interim business continuity measures might continue for several weeks before the situation was fully resolved. Since then, the company鈥檚 financial reports indicate the cyberattack led to approximately $25 million in lost revenue.

Hasbro has not linked the March incident to the employee data breach disclosed in the Massachusetts notification letters. The company, founded in 1923 and publicly traded on the NASDAQ, also owns other well-known properties such as Clue, Play-Doh, Peppa Pig, Scrabble, and Magic: The Gathering. The breach letters did not specify the nature of the exposure beyond the employee data detailed in the Massachusetts report, nor did they clarify how the attackers gained access. The company鈥檚 response has focused on securing the affected accounts and restoring normal operations, but the full scope of the breach remains unclear.

More cybersecurity news from TechManNews.