Data Breach & Privacy
Blog > Data Breach & Privacy
Hibbett Retail, Inc. Data Breach: What Employees Need to Know
Hibbett Retail, Inc., a national athletic footwear and apparel retailer, reported a data security incident that may have exposed personnel records of current and former employees and their dependents. Here is what the company has disclosed so far and what affected individuals can consider doing to protect their personal information.

What Information May Have Been Involved
Identifiers, financial details, and health information
The sample letter filed in California redacts the specific data elements involved. However, in its report to the Texas Attorney General, Hibbett Retail listed the following categories of information as affected: names, addresses, dates of birth, Social Security numbers, driver’s license numbers, other government-issued identification numbers such as passport or state ID numbers, financial information such as account or credit and debit card numbers, medical information, and health insurance information.
The specific types of data involved may vary for each individual depending on the records the company maintained, and individual letters describe the elements that apply to each recipient. The exposure of sensitive identifiers together with health information can raise the risk of identity theft, medical identity theft, fraud, or targeted phishing even when a company reports it is not aware of any misuse.
Who May Be Affected by the Hibbett Retail Breach
Current and former employees, dependents, and beneficiaries
According to the California sample letter, the affected records are personnel files relating to current and former employees of Hibbett Retail, Inc. and its affiliate companies, as well as their dependents and beneficiaries. Hibbett, headquartered in Birmingham, Alabama, described itself in its last public annual report as operating more than 1,000 stores across dozens of states under the Hibbett, City Gear, and Sports Additions banners, so affected individuals may be located nationwide.
The company has not published a total number of affected individuals. Its report to the Texas Attorney General, published on September 9, 2026, states that 15,223 Texas residents were affected. Its sample notice was posted by the California Attorney General on September 8, 2026, and under California Civil Code section 1798.82 a business submits a sample notice to the Attorney General only when a breach affects more than 500 California residents, so more than 500 Californians are understood to be involved. As of this writing, no filing for this incident appears on the Vermont Attorney General’s breach list.
How Hibbett Retail Responded and What Is Offered
One year of Experian IdentityWorks Credit 3B at no cost
Hibbett states in its letter that it has already taken steps to reduce the risk of this type of incident occurring in the future and will continue to prioritize data security. Based on the dates of the state filings, written notifications to affected individuals were being issued in early September 2026, and the Texas report states that notice was provided by U.S. mail.
The company is offering affected individuals a complimentary one-year membership in Experian IdentityWorks Credit 3B, which the letter describes as including a credit report at signup, credit monitoring across the three nationwide bureaus, identity restoration support, and identity theft insurance. Each letter includes an activation code and an enrollment deadline, and the letter states the code will not work after that date. The letter also indicates that a line is available for questions about the incident.
Steps You Can Take to Protect Yourself
Recommended security measures for affected personnel and retail staff
Because the records involved were human-resources files, the risks for Hibbett employees and their dependents run beyond ordinary credit fraud. If you received a letter, or worked for Hibbett or an affiliate during the period covered, these steps fit this incident:
- Enroll in the Experian membership before your code expires. Your letter carries an activation code and an enrollment deadline for the one-year IdentityWorks Credit 3B membership; the letter says the code stops working after that date.
- Freeze your credit if a Social Security number was listed for you. A freeze at Equifax, Experian, and TransUnion costs nothing and blocks new accounts opened in your name, which matters when a Social Security number, date of birth, and driver’s license number were exposed together.
- Check your health plan statements, not just your bank. Hibbett’s Texas report lists medical and health insurance information, so review Explanation of Benefits notices for visits, prescriptions, or claims you do not recognize.
- Watch payroll and tax accounts. HR files often hold the details used to redirect direct deposits or file a fraudulent tax return; consider an IRS Identity Protection PIN and confirm your direct-deposit details with your employer.
- Treat unexpected contact about the breach with suspicion. Anyone who claims to be from Hibbett, Experian, or Kroll and asks for your code, password, or Social Security number should be verified independently before you respond.
These suggestions are general and do not amount to legal advice. Your circumstances may call for different steps, and a legal professional can explain which rights may apply to you.
Talk to Wilshire Law Firm
Were you affected by the Hibbett Retail data breach?
Did your personnel file end up in the Hibbett Retail data breach? Current and former employees of Hibbett and its affiliates, along with their dependents and beneficiaries, may want to know where they stand. Wilshire Law Firm’s nationally recognized, award-winning team includes California data privacy lawyers who handle employee data incidents, and breaches involving Social Security numbers and health information are frequently pursued as class actions. A consultation and case review are free, a legal professional is available around the clock, and there are no fees unless you get paid.
Reach out to Wilshire Law Firm to have your Hibbett notification letter reviewed at no cost.
FAQs
According to Hibbett’s notification letter, an unknown third party had unauthorized access to the company’s computer systems between April 22, 2026, and April 25, 2026. The company’s sample notice was posted by the California Attorney General on September 8, 2026, and its Texas report was published on September 9, 2026.
Hibbett states that it discovered suspicious activity in its computer network and that a forensic investigation determined an unknown third party gained unauthorized access to its systems. The company says it initiated an investigation, notified law enforcement, secured its systems, and engaged external forensic cybersecurity experts. It has not publicly described how the third party gained access.
The categories Hibbett listed in its Texas Attorney General report are names, addresses, dates of birth, Social Security numbers, driver’s license numbers, other government-issued identification numbers, financial information such as account or card numbers, medical information, and health insurance information. The elements involved may vary by individual, and each letter describes what applied to its recipient.
Hibbett has not published a total. Its report to the Texas Attorney General states that 15,223 Texas residents were affected, and because the company filed a sample notice with the California Attorney General, more than 500 California residents are understood to be involved.
Yes. According to its notification letter, Hibbett is offering affected individuals a complimentary one-year membership in Experian IdentityWorks Credit 3B, which includes credit monitoring and identity restoration support. Each letter contains an activation code and an enrollment deadline.
Consider enrolling in the complimentary Experian membership before the deadline in your letter, placing a credit freeze or fraud alert with the three nationwide bureaus, and reviewing your financial and health insurance statements for unfamiliar activity. Keep the letter, and consider speaking with a legal professional about any rights that may apply to you.
Possibly. Hibbett’s letter says an unknown third party may have acquired HR files holding Social Security numbers, driver’s license numbers, and medical and health insurance information for current and former employees and their dependents, and the company reported the incident to state regulators roughly four and a half months after the April intrusion. Incidents with that profile are often examined for class action treatment, though whether any claim fits your situation depends on facts such as what your letter lists and whether you have seen misuse. A free case review is the quickest way to find out.

