Hasbro, one of the world’s best-known toy and gaming companies, has revealed that a cybersecurity incident exposed personal and financial information belonging to some of its employees. According to breach notification documents submitted to the Massachusetts Attorney General’s Office, unauthorized individuals gained access to an employee account and potentially obtained sensitive information. Hasbro said the data involved differed from person to person and could have included names, email addresses, residential addresses, telephone numbers, national identification details, and financial information. Although Hasbro has not publicly stated how many people were affected overall, records from Massachusetts indicate that 436 employees in the state had sensitive information compromised. The exposed information reportedly included Social Security numbers, bank or other financial account details, credit and debit card numbers, and driver’s license information. The company said it responded by disabling the affected account, ending the unauthorized access, and implementing additional security measures to reduce the likelihood of a similar incident. The disclosure comes several months after another cyberattack disrupted Hasbro’s operations. In March, the company experienced an attack that caused it to take certain systems offline while it worked on recovery efforts. Hasbro subsequently warned investors that the disruption could lead to delays and that temporary business-continuity measures might remain necessary for several weeks. Financial reports filed after the incident indicate that the March cyberattack contributed to an estimated $25 million loss in revenue. However, Hasbro has not confirmed that the earlier operational disruption and the newly disclosed employee data breach were connected. The latest incident highlights the growing cybersecurity risks faced by large multinational companies and the potential consequences when employee accounts are compromised. It also demonstrates why organizations must strengthen access controls, monitor accounts, and protect sensitive employee information from unauthorized access.
Cybersecurity researchers have identified TASK#STOMP, a campaign delivering a PowerShell-based backdoor that targets sensitive information on compromised Windows systems. The malwa...
Security researchers have identified a cache key injection technique that can affect vulnerable Nginx web server configurations and shared caching systems. The attack takes advanta...
Threat actors are abusing Microsoft Teams external chat functionality to impersonate corporate IT help desks and target employees with convincing support requests. Attackers operat...