Hasbro, one of the world’s best-known toy and gaming companies, has revealed that a cybersecurity incident exposed personal and financial information belonging to some of its employees. According to breach notification documents submitted to the Massachusetts Attorney General’s Office, unauthorized individuals gained access to an employee account and potentially obtained sensitive information. Hasbro said the data involved differed from person to person and could have included names, email addresses, residential addresses, telephone numbers, national identification details, and financial information. Although Hasbro has not publicly stated how many people were affected overall, records from Massachusetts indicate that 436 employees in the state had sensitive information compromised. The exposed information reportedly included Social Security numbers, bank or other financial account details, credit and debit card numbers, and driver’s license information. The company said it responded by disabling the affected account, ending the unauthorized access, and implementing additional security measures to reduce the likelihood of a similar incident. The disclosure comes several months after another cyberattack disrupted Hasbro’s operations. In March, the company experienced an attack that caused it to take certain systems offline while it worked on recovery efforts. Hasbro subsequently warned investors that the disruption could lead to delays and that temporary business-continuity measures might remain necessary for several weeks. Financial reports filed after the incident indicate that the March cyberattack contributed to an estimated $25 million loss in revenue. However, Hasbro has not confirmed that the earlier operational disruption and the newly disclosed employee data breach were connected. The latest incident highlights the growing cybersecurity risks faced by large multinational companies and the potential consequences when employee accounts are compromised. It also demonstrates why organizations must strengthen access controls, monitor accounts, and protect sensitive employee information from unauthorized access.
Attackers have chained two vulnerabilities in JFrog Artifactory to gain administrator control of self-hosted servers and install backdoors, according to cloud security company Wiz....
Trezor has disclosed that a phishing campaign following a September 9, 2026 security incident at its third-party email marketing provider, Brevo, exposed approximately 347,000 opt-...
Microsoft’s September 2026 security updates have been associated with a serious Remote Desktop Services (RDS) stability issue affecting Windows Server 2019, 2022, and 2025. Admin...