Hasbro Tells Massachusetts Regulators Employee Data Was Stolen in Breach
The toy giant filed notification letters flagging exposed Social Security numbers, bank details and driver's licence data for 436 workers in the state, months after a separate March cyberattack cost it roughly $25 million.

Key points
- Hasbro filed breach notification letters with the Massachusetts Attorney General's Office this week disclosing that a compromised employee account exposed staff data.
- The Massachusetts filing lists 436 affected state residents, with Social Security numbers, financial account details, card numbers and driver's licence information among the data stolen.
- Hasbro has not said how many employees were affected in total, when the breach was detected, or whether customers were caught up in it.
- A separate March 28 cyberattack cost Hasbro roughly $25 million in lost revenue, according to its own financial filings; the company has not linked the two incidents.
- Notification letters were sent under Massachusetts General Laws Chapter 93H, which requires written notice to residents and the Attorney General after a data breach.
Hasbro, the American company behind Monopoly, Nerf, Play-Doh and Magic: The Gathering, has told Massachusetts regulators that hackers broke into an employee account and made off with personal and financial information belonging to staff.
The disclosure came through data breach notification letters filed with the Massachusetts Attorney General's Office, first reported by BleepingComputer. Hasbro did not say in the letters how many people were affected overall, or when it spotted the intrusion.
What the company did say is narrow and carefully worded. "The information involved varied by individual but may have included your name and one or more additional personal information elements such as email, address, phone number, national ID number, or financial information," Hasbro wrote.
Regulators filled in some of the blanks. The Massachusetts Attorney General's 2026 Data Breach Notification Report records 436 Hasbro employees in the state as affected, with Social Security numbers, financial account information, credit and debit card numbers and driver's licence details among the exposed data.
How did the hackers get in?
Through a single employee account. Hasbro says it "disabled the compromised employee account, terminating unauthorized access, and deploying additional safeguards." The filing does not spell out whether the account was taken over by phishing, which is when criminals send fake emails to trick staff into handing over passwords, or by stolen credentials bought from another breach.
That matters, because account takeover is now the most common route into corporate networks. Once inside, an attacker with valid login details often looks like a legitimate user to security tools.
What does this mean for Hasbro employees?
If you work for Hasbro and live in Massachusetts, assume your Social Security number and bank details are in criminal hands and act accordingly. Freeze your credit with the three major bureaus, turn on transaction alerts with your bank, and watch for tax filings made in your name.
Hasbro's letters typically include an offer of free credit monitoring. Take it, but treat it as a floor, not a ceiling. A credit freeze is stronger and free under federal law.
Is this connected to the March cyberattack?
Hasbro says no, at least not on paper. The company disclosed a cyberattack on March 28 in a filing with the U.S. Securities and Exchange Commission, which forced systems offline and, by Hasbro's own subsequent financial reports, cost about $25 million in lost revenue.
The notification letters filed this week do not tie the two events together. Whether they are truly separate incidents, or two views of the same intrusion, is not something Hasbro has addressed publicly.
What legal clock is running?
Massachusetts General Laws Chapter 93H, section 3 requires written notice to residents and to the Attorney General "as soon as practicable and without unreasonable delay" after a breach involving personal information. The statute does not fix a hard day count, but late filings have drawn Attorney General enforcement action before.
For a publicly traded company like Hasbro, the SEC's cybersecurity disclosure rule (Item 1.05 of Form 8-K, effective December 18, 2023) requires disclosure within four business days of determining a cybersecurity incident is material. Hasbro used a Form 8-K for the March event. It has not, so far, filed one tying this employee data theft to that determination.



