Hibbett Retail Reports Data Breach to California Regulators
Hibbett Retail, Inc. reported a data breach to California authorities on September 8, 2026, stemming from an incident on April 22, 2026. This breach involved the exposure of customer information such as Full Name, Email Address, Payment Card Information, and Loyalty Account Details. Individuals affected by this incident should review their accounts and remain vigilant for suspicious activity.
- State
- California
- Breach date
- April 22, 2026
- Reported
- September 8, 2026
What may have been exposed
- Full Name
- Email Address
- Password or Credential Hash
- Mailing Address
- Purchase and Order History
- Payment Card Information
- Phone Number
- Loyalty Account Details
Hibbett Retail, Inc. filed an official data breach notification with California regulators on September 8, 2026. The company reported that a security incident occurred on April 22, 2026. The investigation into this breach is currently ongoing with a status of monitoring. These details are derived from public filings.
The information reported as exposed in this incident includes customers' Full Name, Email Address, Password or Credential Hash, Mailing Address, Purchase and Order History, Payment Card Information, Phone Number, and Loyalty Account Details. These categories cover various personal identifiers and financial transaction data.
The exposure of such data increases the risk of various follow-on attacks. For instance, compromised Email Addresses and Password or Credential Hashes can be used for unauthorized account access on multiple platforms. Payment Card Information could lead to fraudulent transactions if not secured promptly.
Individuals who may be affected by this breach should closely monitor their financial statements for any unauthorized activity. It is advisable to change passwords for online accounts, especially if the same credentials were used on the Hibbett Retail site and other platforms. Consider enabling multi-factor authentication where available.
Remaining vigilant for phishing attempts via email or phone is also important, as threat actors may use exposed contact information. Reviewing credit reports periodically for unexpected accounts can help detect potential identity fraud.