Blog > Data Breach & Privacy

Hibbett Retail, Inc. Data Breach: What Employees Need to Know

Hibbett Retail, Inc., a national athletic footwear and apparel retailer, reported a data security incident that may have exposed personnel records of current and former employees and their dependents. Here is what the company has disclosed so far and what affected individuals can consider doing to protect their personal information.

Hibbett Retail, Inc. Data Breach: What Employees Need to Know

What Happened in the Hibbett Retail Data Breach

Unauthorized network access between April 22 and 25, 2026

According to a sample notification letter that Hibbett Retail, Inc. submitted to the California Attorney General on September 8, 2026, the company recently discovered suspicious activity in its computer network. Hibbett states that upon discovery it initiated an investigation, notified law enforcement, secured its systems, and engaged external forensic cybersecurity experts. The forensic investigation determined that an unknown third party gained unauthorized access to the company’s computer systems between April 22, 2026, and April 25, 2026.

During that window, according to the letter, the third party may have accessed and acquired certain files within the network, including personnel records the company maintains for human resources purposes relating to current and former employees and their dependents or beneficiaries. Hibbett states that it has been conducting an in-depth review of those records over the past few months and that it is not aware of any instances of fraud or identity theft relating to the incident. The letter does not say when the activity was discovered or how the third party gained access.

What Information May Have Been Involved

Identifiers, financial details, and health information

The sample letter filed in California redacts the specific data elements involved. However, in its report to the Texas Attorney General, Hibbett Retail listed the following categories of information as affected: names, addresses, dates of birth, Social Security numbers, driver’s license numbers, other government-issued identification numbers such as passport or state ID numbers, financial information such as account or credit and debit card numbers, medical information, and health insurance information.

The specific types of data involved may vary for each individual depending on the records the company maintained, and individual letters describe the elements that apply to each recipient. The exposure of sensitive identifiers together with health information can raise the risk of identity theft, medical identity theft, fraud, or targeted phishing even when a company reports it is not aware of any misuse.

Who May Be Affected by the Hibbett Retail Breach

Current and former employees, dependents, and beneficiaries

According to the California sample letter, the affected records are personnel files relating to current and former employees of Hibbett Retail, Inc. and its affiliate companies, as well as their dependents and beneficiaries. Hibbett, headquartered in Birmingham, Alabama, described itself in its last public annual report as operating more than 1,000 stores across dozens of states under the Hibbett, City Gear, and Sports Additions banners, so affected individuals may be located nationwide.

The company has not published a total number of affected individuals. Its report to the Texas Attorney General, published on September 9, 2026, states that 15,223 Texas residents were affected. Its sample notice was posted by the California Attorney General on September 8, 2026, and under California Civil Code section 1798.82 a business submits a sample notice to the Attorney General only when a breach affects more than 500 California residents, so more than 500 Californians are understood to be involved. As of this writing, no filing for this incident appears on the Vermont Attorney General’s breach list.

How Hibbett Retail Responded and What Is Offered

One year of Experian IdentityWorks Credit 3B at no cost

Hibbett states in its letter that it has already taken steps to reduce the risk of this type of incident occurring in the future and will continue to prioritize data security. Based on the dates of the state filings, written notifications to affected individuals were being issued in early September 2026, and the Texas report states that notice was provided by U.S. mail.

The company is offering affected individuals a complimentary one-year membership in Experian IdentityWorks Credit 3B, which the letter describes as including a credit report at signup, credit monitoring across the three nationwide bureaus, identity restoration support, and identity theft insurance. Each letter includes an activation code and an enrollment deadline, and the letter states the code will not work after that date. The letter also indicates that a line is available for questions about the incident.

Talk to Wilshire Law Firm

Were you affected by the Hibbett Retail data breach?

Did your personnel file end up in the Hibbett Retail data breach? Current and former employees of Hibbett and its affiliates, along with their dependents and beneficiaries, may want to know where they stand. Wilshire Law Firm’s nationally recognized, award-winning team includes California data privacy lawyers who handle employee data incidents, and breaches involving Social Security numbers and health information are frequently pursued as class actions. A consultation and case review are free, a legal professional is available around the clock, and there are no fees unless you get paid.

Reach out to Wilshire Law Firm to have your Hibbett notification letter reviewed at no cost.

FAQs

According to Hibbett’s notification letter, an unknown third party had unauthorized access to the company’s computer systems between April 22, 2026, and April 25, 2026. The company’s sample notice was posted by the California Attorney General on September 8, 2026, and its Texas report was published on September 9, 2026.

Hibbett states that it discovered suspicious activity in its computer network and that a forensic investigation determined an unknown third party gained unauthorized access to its systems. The company says it initiated an investigation, notified law enforcement, secured its systems, and engaged external forensic cybersecurity experts. It has not publicly described how the third party gained access.

The categories Hibbett listed in its Texas Attorney General report are names, addresses, dates of birth, Social Security numbers, driver’s license numbers, other government-issued identification numbers, financial information such as account or card numbers, medical information, and health insurance information. The elements involved may vary by individual, and each letter describes what applied to its recipient.

Hibbett has not published a total. Its report to the Texas Attorney General states that 15,223 Texas residents were affected, and because the company filed a sample notice with the California Attorney General, more than 500 California residents are understood to be involved.

Yes. According to its notification letter, Hibbett is offering affected individuals a complimentary one-year membership in Experian IdentityWorks Credit 3B, which includes credit monitoring and identity restoration support. Each letter contains an activation code and an enrollment deadline.

Consider enrolling in the complimentary Experian membership before the deadline in your letter, placing a credit freeze or fraud alert with the three nationwide bureaus, and reviewing your financial and health insurance statements for unfamiliar activity. Keep the letter, and consider speaking with a legal professional about any rights that may apply to you.

Possibly. Hibbett’s letter says an unknown third party may have acquired HR files holding Social Security numbers, driver’s license numbers, and medical and health insurance information for current and former employees and their dependents, and the company reported the incident to state regulators roughly four and a half months after the April intrusion. Incidents with that profile are often examined for class action treatment, though whether any claim fits your situation depends on facts such as what your letter lists and whether you have seen misuse. A free case review is the quickest way to find out.

Related Content

Guides, nearby offices, and related practice areas.

Start Your Free Case Review

4.9 out of 2,525 reviews
  • Available 24/7
  • Hablamos Español
  • Nationally-Recognized Powerhouse Team
As seen in:

We'll contact you within minutes

No fees unless you get paid.

By submitting this form, you knowingly, voluntarily, and expressly consent to receive from Wilshire Law Firm telephone calls, emails, and SMS text messages, including those made using an automatic telephone dialing system (auto-dialer), artificial intelligence (AI), and/or pre-recorded or artificial voice messages. These communications are for the purpose of providing prompt consultation regarding your potential case. You understand that by providing your telephone number, you are granting permission to be contacted for this purpose, even if your number is on a federal or state Do-Not-Call registry. Consent is not required as a condition of retaining Wilshire Law Firm. Message and data rates may apply. You may revoke your consent to receive calls, texts, or emails at any time by replying “STOP” to any text message, calling 888-557-3271, filling out the form at wilshirelawfirm.com/do-not-contact or by any other reasonable method. For more information, refer to our Privacy Policy.

Locations

Find your nearest office — serving all of California and employment clients in Oregon and Washington.

Appointments required for office visits

Beverly HillsIrvineLos AngelesOaklandRiversideSacramentoSan DiegoTorrance