Hibbett Retail Data Breach Exposes Customer Information in California
Hibbett Retail, Inc. reported a data security incident to California authorities on September 8, 2026, which occurred on April 22, 2026. This breach involved the exposure of various types of customer data, placing affected individuals at risk. The company has indicated that the investigation into the incident is ongoing and being monitored.
- State
- California
- Breach date
- April 22, 2026
- Reported
- September 8, 2026
What may have been exposed
- Full Name
- Email Address
- Password or Credential Hash
- Mailing Address
- Purchase and Order History
- Payment Card Information
- Phone Number
- Loyalty Account Details
Hibbett Retail, Inc. has publicly reported a data breach impacting its customers, according to official filings made with California regulators on September 8, 2026. The incident, which exposed customer information, is reported to have taken place on April 22, 2026. The specific nature of the breach has not been detailed, and the company has stated it is currently monitoring the investigation.
The compromised information includes Full Name, Email Address, Password or Credential Hash, Mailing Address, Purchase and Order History, Payment Card Information, Phone Number, and Loyalty Account Details. These data types, when exposed, can be exploited by unauthorized parties for various malicious purposes.
Customers whose data was exposed face potential risks such as unauthorized access to their accounts, fraudulent transactions, or targeted phishing attempts. Bad actors could use personal details and account credentials to gain access to other online services or make unauthorized purchases. Additionally, exposed email addresses and phone numbers might lead to increased spam or scam attempts.
Individuals who receive a breach notification from Hibbett Retail, Inc. should take immediate steps to protect their information. It is advisable to change passwords for their Hibbett Retail account, as well as any other online accounts where they may have used the same or similar credentials. Customers should also enable multi-factor authentication wherever possible for added security.
Reviewing financial statements and credit reports regularly is a critical precaution to detect any suspicious activity or unauthorized transactions. Additionally, be vigilant against unsolicited emails, text messages, or phone calls that claim to be from Hibbett Retail or other entities, as these could be phishing attempts seeking more personal information.
This incident highlights the ongoing challenges retail companies face in safeguarding extensive customer data. Customers should refer to official communications from Hibbett Retail, Inc. for the most accurate and up-to-date information regarding this data breach and any specific recommendations.