DataBreachSearch.com
All cases
monitoring

Hibbert Retail Discloses Customer Data Breach in Vermont

Hibbert Retail, Inc. filed a data breach report in Vermont on September 8, 2026, confirming a cybersecurity incident. This breach potentially exposed customer names, email addresses, mailing addresses, password hashes, purchase history, and payment card information. Individuals affected should take steps to secure their online accounts and monitor for suspicious activity.

Compiled from official Attorney General recordsLast updated
State
Vermont
Reported
September 8, 2026

What may have been exposed

  • Full Name
  • Email Address
  • Password or Credential Hash
  • Mailing Address
  • Purchase and Order History
  • Payment Card Information

Hibbert Retail, Inc. submitted a data breach filing to Vermont regulators on September 8, 2026. This report confirms a cybersecurity incident that compromised customer data. The specific type of breach remains unspecified in the filing, and an investigation into the incident is currently monitoring the situation.

The official filing indicates that the exposed customer information includes Full Name, Email Address, Password or Credential Hash, Mailing Address, Purchase and Order History, and Payment Card Information. The company is a prominent commercial enterprise in consumer retail, handling extensive customer data through its omnichannel and e-commerce platforms.

The exposure of full names, mailing addresses, and email addresses can lead to targeted phishing campaigns, spam, and social engineering attacks. Furthermore, the potential exposure of Password or Credential Hash creates risks for unauthorized retail account takeovers, especially if passwords are reused across different services. Compromised Payment Card Information carries immediate financial dangers, including fraudulent credit card charges.

Individuals who may be affected by this incident should consider changing passwords for their Hibbert Retail accounts and any other online services where similar credentials might have been used. Enabling multi-factor authentication on all accounts offers an additional layer of security. Regularly reviewing bank and credit card statements for unfamiliar transactions is also a recommended precaution.

Source: Attorney General filing