Did Hibbett Retail, Inc. have a data breach?
Answer
Yes. Hibbett Retail, Inc. reported a data breach to the California Attorney General on September 8, 2026.
View the official filingWhat the filing says
- Reported to
- California Attorney General
- Filing date
- September 8, 2026
- Breach date
- April 22, 2026
- People affected
- Not stated in the filing
Information involved
- Full Name
- Email Address
- Password or Credential Hash
- Mailing Address
- Purchase and Order History
- Payment Card Information
- Phone Number
- Loyalty Account Details
In plain terms
Hibbett Retail, Inc. reported a data breach to California authorities on September 8, 2026, stemming from an incident on April 22, 2026. This breach involved the exposure of customer information such as Full Name, Email Address, Payment Card Information, and Loyalty Account Details. Individuals affected by this incident should review their accounts and remain vigilant for suspicious activity.
Hibbett Retail, Inc. filed an official data breach notification with California regulators on September 8, 2026. The company reported that a security incident occurred on April 22, 2026. The investigation into this breach is currently ongoing with a status of monitoring. These details are derived from public filings.
The information reported as exposed in this incident includes customers' Full Name, Email Address, Password or Credential Hash, Mailing Address, Purchase and Order History, Payment Card Information, Phone Number, and Loyalty Account Details. These categories cover various personal identifiers and financial transaction data.
The exposure of such data increases the risk of various follow-on attacks. For instance, compromised Email Addresses and Password or Credential Hashes can be used for unauthorized account access on multiple platforms. Payment Card Information could lead to fraudulent transactions if not secured promptly.
Individuals who may be affected by this breach should closely monitor their financial statements for any unauthorized activity. It is advisable to change passwords for online accounts, especially if the same credentials were used on the Hibbett Retail site and other platforms. Consider enabling multi-factor authentication where available.
Remaining vigilant for phishing attempts via email or phone is also important, as threat actors may use exposed contact information. Reviewing credit reports periodically for unexpected accounts can help detect potential identity fraud.
Other filings by Hibbett Retail, Inc.
Companies often file the same breach in several states. Each filing is listed separately.
Commonly recommended next steps
Watch your financial accounts
Review bank and card statements for unfamiliar activity and turn on transaction alerts. Report anything you don't recognize to your bank right away.
Secure your online accounts
Change the password on any account that reused an exposed password and turn on two-factor authentication wherever it's offered.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Look up another company
Other breaches reported in California
- ZZ Diag ProbeYes — reportedCalifornia
- Sheppard, Mullin, Richter & Hampton LLPYes — reportedCalifornia · October 2, 2026
- Fragomen, Del Rey, Bernsen & Loewy, LLPYes — reportedCalifornia · October 2, 2026
- Aldrich Services LLPYes — reportedCalifornia · October 1, 2026
- Lincoln Property Company Commercial LLCYes — reportedCalifornia · October 1, 2026
- Marana Health CenterYes — reportedCalifornia · October 1, 2026
- DriveWealthYes — reportedCalifornia · September 30, 2026
- American Family Connect Insurance CompanyYes — reportedCalifornia · September 30, 2026
- Nishiyamato AcademyYes — reportedCalifornia · September 30, 2026
- ProCampsYes — reportedCalifornia · September 30, 2026
DataBreachSearch.com reports what was filed with state regulators. It is not legal advice, is not a law firm, and is not affiliated with any government agency or with Hibbett Retail, Inc..