DataBreachInformation.com
MonitoringWashington AG filing · September 8, 2026

Hibbett Retail Discloses Data Security Incident in Washington

Hibbett Retail, Inc. submitted a data breach notification to Washington state authorities on September 8, 2026. This incident involved the exposure of customer data including Full Name, Email Address, Password or Credential Hash, Mailing Address, Purchase and Order History, Payment Card Information, Phone Number, and Loyalty Account Details. The company has indicated that the investigation into the breach is currently ongoing.

State
Washington
Reported
September 8, 2026

What may have been exposed

  • Full Name
  • Email Address
  • Password or Credential Hash
  • Mailing Address
  • Purchase and Order History
  • Payment Card Information
  • Phone Number
  • Loyalty Account Details

Hibbett Retail, Inc., a prominent sporting goods and athletic footwear retailer, filed a data security incident report with the State of Washington on September 8, 2026. The specific nature of the breach remains unspecified in the public filing, and the company has stated that the investigation into the event is still in progress. These details are derived from official public records submitted to state regulators.

The compromised information reported in connection with this incident includes customers' Full Name, Email Address, Password or Credential Hash, Mailing Address, Purchase and Order History, Phone Number, and Loyalty Account Details. Additionally, Payment Card Information was among the categories of data exposed during the event.

Exposure of such personal data carries various risks for affected individuals. Unauthorized parties could potentially use Payment Card Information for fraudulent transactions. Leaked Email Addresses and Password or Credential Hashes might be used in 'credential stuffing' attacks, where criminals attempt to access other online accounts using the same credentials. This type of information could also lead to targeted phishing attempts.

Individuals who receive notifications regarding this incident are advised to take general protective steps. It is recommended to monitor bank and credit card statements for any unusual activity. Changing passwords for online accounts, especially those that may have used the same credentials as any Hibbett Retail account, is a common precaution. Enabling multi-factor authentication (MFA) on all available online services can also add an extra layer of security.

Source: Washington Attorney General filing

More Washington data breach cases