Description

Hasbro, one of the world’s best-known toy and gaming companies, has revealed that a cybersecurity incident exposed personal and financial information belonging to some of its employees. According to breach notification documents submitted to the Massachusetts Attorney General’s Office, unauthorized individuals gained access to an employee account and potentially obtained sensitive information. Hasbro said the data involved differed from person to person and could have included names, email addresses, residential addresses, telephone numbers, national identification details, and financial information. Although Hasbro has not publicly stated how many people were affected overall, records from Massachusetts indicate that 436 employees in the state had sensitive information compromised. The exposed information reportedly included Social Security numbers, bank or other financial account details, credit and debit card numbers, and driver’s license information. The company said it responded by disabling the affected account, ending the unauthorized access, and implementing additional security measures to reduce the likelihood of a similar incident. The disclosure comes several months after another cyberattack disrupted Hasbro’s operations. In March, the company experienced an attack that caused it to take certain systems offline while it worked on recovery efforts. Hasbro subsequently warned investors that the disruption could lead to delays and that temporary business-continuity measures might remain necessary for several weeks. Financial reports filed after the incident indicate that the March cyberattack contributed to an estimated $25 million loss in revenue. However, Hasbro has not confirmed that the earlier operational disruption and the newly disclosed employee data breach were connected. The latest incident highlights the growing cybersecurity risks faced by large multinational companies and the potential consequences when employee accounts are compromised. It also demonstrates why organizations must strengthen access controls, monitor accounts, and protect sensitive employee information from unauthorized access.