Hibbett Retail Data Breach: Customers' Personal Information Exposed
Hibbett Retail, Inc. has reported a data breach that occurred in April 2026, impacting its customers. This incident compromised various personal details, including payment card information and account credentials, potentially exposing individuals to fraud and other harms. Affected customers in California should be aware of their rights and potential avenues for recourse.
- State
- California
- Breach date
- April 22, 2026
- Reported
- September 8, 2026
What may have been exposed
- Full Name
- Email Address
- Password or Credential Hash
- Mailing Address
- Purchase and Order History
- Payment Card Information
- Phone Number
- Loyalty Account Details
Hibbett Retail, Inc., a prominent sporting goods and athletic footwear retailer, recently announced a data security incident impacting customer information. The breach, which occurred on April 22, 2026, was reported to the California Attorney General on September 8, 2026.
Our investigation indicates that the compromised data includes sensitive customer details such as Full Name, Email Address, Password or Credential Hash, Mailing Address, Purchase and Order History, Payment Card Information, Phone Number, and Loyalty Account Details. The exposure of these categories of personal information creates significant risks for affected individuals, including potential identity theft, financial fraud, and unauthorized access to other online accounts through credential stuffing.
Under California law, companies like Hibbett Retail have a legal obligation to protect the personal information they collect and store. When a data breach of this nature occurs, it often points to potential failures in a company's security practices, such as inadequate encryption, network monitoring, or access controls. Such security lapses can constitute a breach of statutory duties.
If you have received a data breach notification letter from Hibbett Retail, it is crucial to take immediate steps to protect yourself. We recommend closely monitoring your credit reports and all financial accounts for any suspicious activity. You should also change the Password or Credential Hash for your Hibbett Retail account and any other online accounts where you may have used the same or similar credentials.
For customers in California whose data was compromised, understanding your legal rights is important. You may have the ability to seek compensation for damages incurred due to the breach. Our dedicated legal team is actively investigating this incident and offers free case reviews to help you understand your options. We operate on a contingency-fee basis, meaning you pay no attorney fees unless we successfully recover compensation on your behalf.
Source: Attorney General filing