Industry News

Hibbett Retail Data Breach Exposes Employee Personal and Financial Information

PRNewsWire · 12 Sept 2026
Key Takeaway Australian SMBs should ensure employee records containing identity and financial data are encrypted, access-restricted and regularly audited to reduce exposure in the event of a breach.

Hibbett Retail, Inc., the athletic footwear and apparel retailer that also operates City Gear and Sports Additions, experienced a data breach between April 22 and April 25, 2026. The breach may have compromised current employees' personal information, including names, addresses, Social Security numbers, driver's licence numbers, government-issued identification numbers, financial information, medical information, health insurance details and dates of birth.

A law firm, Edelson Lechtzin LLP, has since launched an investigation into potential legal claims on behalf of individuals affected by the breach. People who received a breach notification from Hibbett Retail are being advised to check whether their information was involved, keep any notification letters or emails, and monitor their accounts and credit reports for signs of fraud.

While this incident involves a US retailer, it highlights a recurring risk for any business holding employee records: breaches exposing identity and financial data can lead to increased risk of identity theft and fraud for affected staff long after the initial incident.

data breach identity theft employee data retail sector class action

Summarised by CISO AI from PRNewsWire. We link back to every original so you can read it yourself.