Hibbett Retail Data Breach Investigation

Hibbett Retail, Inc. reported a hacking/IT incident that may have exposed personal information associated with current employees or employees of affiliated companies. A consumer notice says the event could have resulted in unauthorized access, while regulatory data reports 109,732 potentially affected individuals. Strauss Borrelli PLLC is investigating the Hibbett Retail data incident and the rights of people who received notice. If you were notified, you may fill out the secure contact form on this page to ask whether you may qualify to pursue a claim.

Key Facts at a Glance

  • Entity Involved: Hibbett Retail, Inc. (Retail)
  • Incident Type: Reported hacking/IT incident involving potential unauthorized access to a network
  • Date of Incident: April 22 to April 25, 2026, as reported in regulatory incident data
  • Discovery Date: Not disclosed in the available consumer-notice excerpt
  • Official Notice Date: September 8, 2026, according to the consumer notice
  • Exposed Information: Name confirmed in the available notice excerpt; regulatory data also lists address, Social Security number, date of birth, driver’s license number, financial account number, health records, and health insurance information as potentially involved
  • Affected Population: 109,732 potentially affected individuals reported in regulatory data; the available notice excerpt does not independently confirm the total

What Happened?

According to regulatory incident data, Hibbett Retail, Inc. reported a hacking/IT incident involving activity on its network between April 22 and April 25, 2026. The available consumer notice states that the event could have resulted in unauthorized access to personal information belonging to current and former Hibbett employees, and beneficiaries. That language describes potential access and does not establish that every listed record was viewed, acquired, or misused.

Hibbett sent its consumer notice on September 8, 2026, and the supplied regulatory record indicates that the matter was publicly listed the following day. The available excerpt does not identify a discovery date, explain the technical method used to access the network, or confirm whether a third party was involved. It references identity restoration services through Experian, but it does not clearly state the enrollment period or confirm that credit monitoring was included.

What Information Was Exposed?

The available Hibbett Retail notice excerpt confirms that an affected record contained the recipient’s name, and separate regulatory incident data lists names, addresses, Social Security numbers, dates of birth, driver’s license numbers, financial account numbers, health records, and health insurance information as potentially involved. Because the exposed elements may differ by person, recipients should review their individual notices rather than assume that every category applied to them.

This combination of information may create risks of identity theft, fraudulent account activity, medical or insurance misuse, and impersonation. Because Hibbett operates in retail, recipients should also be cautious about fake order confirmations, shipping or delivery text messages, loyalty-account reset requests, and employment-related phishing.

What Should You Do Next?

  1. Review and preserve the notice: Keep the complete Hibbett notice, envelope, emails, and any related records. Determine which data categories the company says applied to you and save documentation of suspicious activity or expenses.
  2. Consider a credit freeze or fraud alert: A security freeze can restrict access to your credit file and may make it harder for someone to open an account in your name. Contact Equifax, Experian, and TransUnion separately to place freezes.
  3. Monitor financial and insurance activity: Review bank and credit-card statements, credit reports, health insurance explanations of benefits, and medical bills. Promptly dispute unfamiliar accounts, withdrawals, claims, providers, or changes to insurance information.
  4. Be alert for retail and employment scams: Do not follow unexpected links involving orders, deliveries, loyalty rewards, payroll, benefits, tax forms, or password resets. Instead, reach Hibbett, a carrier, or a benefits provider through a verified website or telephone number.
  5. Evaluate the referenced protection services: If your notice includes an Experian eligibility code, review the enrollment instructions, deadline, scope, and terms before activating the service. Use only contact information printed in the official notice and avoid sharing the code with unsolicited callers.

Your Legal Rights

People affected by the Hibbett Retail data incident may have rights under federal or state privacy, consumer-protection, data-security, or breach-notification laws. The rights and potential remedies available can depend on where a person lives, what information was involved, whether misuse occurred, and whether the incident caused documented losses or other harm.

Depending on the applicable law and circumstances, affected individuals may be able to seek reimbursement for certain losses, costs associated with protective measures, or other relief. Some states also provide specific rights involving police reports or identity-theft documentation. Receiving a notice does not automatically establish a legal claim, and this general information is not individualized legal advice.

Why Hire Strauss Borrelli PLLC?

Strauss Borrelli PLLC represents consumers in privacy and data-security matters and can evaluate regulatory filings, notice language, the information potentially involved, and any resulting harm. An attorney can also explain how applicable laws and filing deadlines may affect an individual’s options. Consultations can help recipients understand the process without assuming that a particular result or recovery is guaranteed.

If you received a breach notification letter from Hibbett Retail, Inc.:

We would like to speak with you about your rights and potential legal remedies in response to this data breach. Please fill out the form, below, or contact us at 872.263.1100 or sam@straussborrelli.com.

Data Breach Website Blog Form

Contact Us

Learn about your legal rights

Name
Terms & Conditions and Privacy Policy

What can you do if you were impacted by a data breach?

If you were impacted by a data breach, you may consider taking the following steps to protect your personal information.

  1. Carefully review the breach notice and retain a copy;
  2. Enroll in any free credit monitoring services provided by the company;
  3. Change passwords and security questions for online accounts;
  4. Regularly review account statements for signs of fraud or unauthorized activity;
  5. Monitor credit reports for signs of identity theft; and
  6. Contact a credit bureau(s) to request a temporary fraud alert.

Contact Us Now

Data Breach Website Blog Form

What can you do if you were impacted by a data breach?

If you were impacted by a data breach, you may consider taking the following steps to protect your personal information.

  1. Carefully review the breach notice and retain a copy;
  2. Enroll in any free credit monitoring services provided by the company;
  3. Change passwords and security questions for online accounts;
  4. Regularly review account statements for signs of fraud or unauthorized activity;
  5. Monitor credit reports for signs of identity theft; and
  6. Contact a credit bureau(s) to request a temporary fraud alert.

One Magnificent Mile
980 N Michigan Avenue, Suite 1610
Chicago, Illinois 60611

Phone: 872.263.1100
Toll Free: 866.748.6220

One Magnificent Mile
980 N Michigan Avenue, Suite 1610
Chicago, Illinois 60611

Phone: 872.263.1100
Toll Free: 866.748.6220

©2026 STRAUSS BORRELLI PLLC. ALL RIGHTS RESERVED. ATTORNEY ADVERTISING.
PRIVACY POLICY  |  TERMS & CONDITIONS  |  COOKIE POLICY

©2026 STRAUSS BORRELLI PLLC. ALL RIGHTS RESERVED. ATTORNEY ADVERTISING.

PRIVACY POLICY  |  TERMS & CONDITIONS  |  COOKIE POLICY