Hibbett Retail Data Breach Class Action Lawsuit Investigation
Data breach law firm Abington Cole + Ellery is investigating potential legal claims related to the Hibbett Retail data breach, which reportedly affected about 109,732 individuals and may have exposed names, addresses, dates of birth, Social Security numbers, driver’s license or state identification numbers, passport numbers, military identification numbers, student identification numbers, financial and banking information, medical information, and health insurance information.
JOIN THIS INVESTIGATION: If you are interested in potentially volunteering to serve as a class representative in a class action lawsuit against Hibbett Retail, please submit your information to be considered:
You may also open the form here: Hibbett Retail Data Breach Lawsuit Form. An attorney-client relationship is not formed by submitting information through this website.
Hibbett Retail Data Breach: Key Facts
| Company: | Hibbett Retail |
|---|---|
| Location: | Birmingham, Alabama |
| Incident Type: | UNDISCLOSED |
| Number Affected: | APPROXIMATELY 109,732 |
| Data Involved: | names, addresses, dates of birth, Social Security numbers, driver’s license or state identification numbers, passport numbers, military identification numbers, student identification numbers, financial and banking information, medical information, and health insurance information |
| Date Began: | April 22, 2026 |
| Date Discovered: | July 26, 2026 (Discovery date reported in Hibbett’s Texas Attorney General filing. The notification letter does not separately specify a discovery date.) |
| Date Ended: | April 25, 2026 |
| Notice Date: | September 8, 2026 |
| Credit Monitoring: | 12 Months of Experian IdentityWorks Credit 3B credit monitoring and identity theft protection |
| Status: | Class Action Lawsuit Investigation |
What happened in the Hibbett Retail data breach?
Hibbett Retail, Inc. disclosed a data breach involving personnel records after an unauthorized third party accessed its computer systems between April 22 and April 25, 2026. The company’s filing with the Texas Attorney General reports 109,732 affected individuals overall, including 15,223 Texans. Washington’s Attorney General separately reports 510 affected Washington residents. Hibbett’s notification letter explains that the records concerned current and former employees, their dependents, and beneficiaries, including employees of affiliated companies. Texas Attorney General Data Security Breach Reports; Washington Attorney General Data Breach Notifications Directory
According to Hibbett, an investigation determined that the intruder may have accessed and acquired files stored on its network, including records maintained for human resources purposes. The company says it secured its systems, notified law enforcement, and engaged outside forensic cybersecurity specialists after discovering suspicious activity. The method used to gain access has not been identified in the notification letter. The notice does not attribute the incident to phishing, stolen credentials, a particular software vulnerability, or ransomware.
The Texas filing identifies July 26, 2026, as the discovery date, while Hibbett’s individual notification letter is dated September 8, 2026. The letter describes a detailed review of the affected records over several months but does not provide specific dates for completing the forensic investigation or records review. It also does not explain how that description relates to the discovery date reported in Texas. California and Washington listed the breach on September 8, and Texas published its report on September 9, 2026. These reporting and notification dates are separate from the unauthorized access that occurred in April. Texas Attorney General Data Security Breach Reports; California Attorney General Submitted Breach Notification Sample; Washington Attorney General Data Breach Notifications Directory
Together, the Texas and Washington filings identify the potentially exposed information as names, addresses, dates of birth, Social Security numbers, driver’s license or state identification numbers, passport numbers, military identification numbers, student identification numbers, financial and banking information, medical information, and health insurance information. Washington specifically identifies health insurance policy or identification numbers. The reported categories do not establish that every affected person had every type of information exposed; recipients should consult their own letters for the information involved in their particular cases. Texas Attorney General Data Security Breach Reports; Washington Attorney General Data Breach Notifications Directory
Hibbett stated in its September 8 notice that it was unaware of fraud or identity theft connected to the incident. The company also reported taking steps to reduce the risk of a similar event, without describing those measures in detail. Its sample notice offers recipients one year of complimentary Experian IdentityWorks Credit 3B, including credit monitoring through Experian, Equifax, and TransUnion, identity restoration assistance, and up to $1 million in identity theft insurance, subject to policy terms and exclusions. No credit card is required to enroll, and enrollment does not affect the recipient’s credit score.
Individuals receiving a Hibbett Retail data breach letter should review the information identified in their notice and follow its instructions for activating the offered protection before the stated deadline. The enrollment deadline and activation code are redacted in the public sample. Hibbett also encourages recipients to review account statements and credit reports and promptly report suspicious activity. The available notice describes an incident involving employment-related records; it does not identify customer shopping accounts or retail purchase records as affected.
How did the Hibbett Retail breach occur?
The Hibbett Retail data breach occurred when an unknown third party gained unauthorized access to the company’s computer systems between April 22 and April 25, 2026. According to Hibbett’s notification letter, the intruder may have accessed and acquired files containing personnel records relating to current and former employees, their dependents, and beneficiaries.
The exact method of entry has not been disclosed in the notice. Hibbett does not identify phishing, stolen credentials, a software vulnerability, or ransomware as the cause. The notice confirms unauthorized system access but does not explain how the intruder obtained that access.
When did the Hibbett Retail breach occur?
The Hibbett Retail data breach reportedly took place on or around between April 22 and April 25, 2026.
How many people were affected by the Hibbett Retail breach?
The Texas Attorney General’s Hibbett filing reports 109,732 individuals affected overall, including 15,223 Texans. Texas Attorney General Data Security Breach Reports
What information was exposed in the Hibbett Retail breach?
- According to Hibbett Retail’s filing with the Texas Attorney General, the information affected included:
- Names
- Addresses
- Social Security numbers
- Driver’s license numbers
- Other government-issued identification numbers, such as passport or state ID numbers
- Financial information, such as account numbers or credit or debit card numbers
- Medical information
- Health insurance information
- Dates of birth
- Military identification numbers
- Student identification numbers
Has Hibbett Retail offered free credit monitoring and/or identity theft protection services?
- Yes. Hibbett Retail is offering one year of free Experian IdentityWorks Credit 3B credit monitoring and identity theft protection, according to its September 8, 2026 notification letter. The services include:
- Three-bureau credit monitoring through Experian, Equifax, and TransUnion.
- Identity restoration assistance, including continued restoration support after the membership expires through Experian’s ExtendCARE service.
- Up to $1 million in identity theft insurance, subject to policy terms, conditions, and exclusions.
Hibbett Retail data breach timeline:
| Date | Event |
|---|---|
| April 22–25, 2026 | An unauthorized third party accessed Hibbett Retail’s computer systems and may have accessed and acquired files, including personnel records concerning current and former employees, their dependents, and beneficiaries. |
| July 26, 2026 | Discovery date reported in Hibbett’s Texas Attorney General filing. The notification letter does not separately specify a discovery date. |
| Following discovery; specific dates not disclosed | Hibbett says it secured its systems, notified law enforcement, and engaged outside forensic cybersecurity specialists. The company also reviewed the affected records to determine what personal information was involved. |
| September 8, 2026 | Hibbett dated its individual notification letters, offering eligible recipients one year of complimentary Experian IdentityWorks Credit 3B credit monitoring and identity protection services. |
| September 8, 2026 | California and Washington listed the breach. Washington reported 510 affected residents. |
| September 9, 2026 | Texas published Hibbett’s report. Its underlying public data identified 109,732 affected individuals overall, including 15,223 Texans. |
Who is Hibbett Retail?
Hibbett Retail, Inc. is a retailer based in Birmingham, Alabama, specializing in athletic footwear, clothing, and accessories. The company serves customers through physical stores, its website, and the Hibbett mobile app. Its merchandise includes sneakers, running shoes, sports apparel, and casual clothing for adults and children, with products from brands such as Nike, Jordan, adidas, and New Balance. Hibbett Retail Website
What should you do if you received a Hibbett Retail data breach letter?
If you received a Hibbett Retail data breach letter, review it carefully and take steps based on the specific information involved:
-
- Keep the letter and identify what was exposed. Your notice should describe the information affected in your case. Save the letter, envelope, and records of any related expenses or suspicious activity.
- Enroll in the free protection offered. Hibbett’s sample notice offers one year of Experian IdentityWorks Credit 3B, including three-bureau credit monitoring and identity restoration assistance. Use the activation code and deadline in your letter. No credit card is required.
- Consider freezing your credit, particularly if your Social Security number was exposed. Contact Equifax, Experian, and TransUnion separately. Freezes are free and do not affect your credit score. You can also place a free, one-year fraud alert through one bureau, which must notify the other two. FTC: Credit Freezes and Fraud Alerts
- Review credit reports and financial accounts. Look for unfamiliar accounts, inquiries, withdrawals, or charges. If account or payment-card information was involved, contact your bank or card issuer promptly about appropriate safeguards.
- Check medical and insurance records if those details were exposed. Review bills and explanations of benefits for care you did not receive. Report unfamiliar services or claims to the provider and insurer. If an identification-document number was exposed, contact its issuing agency for guidance.
- Watch for impersonation attempts. Be cautious about unexpected calls, texts, or emails referencing Hibbett or the breach. Verify requests independently before sharing personal information, passwords, or verification codes.
- Act promptly if you discover misuse. Contact the affected institution and Experian’s identity restoration service, and report identity theft through IdentityTheft.gov. Keep copies of reports, correspondence, and any resulting costs.
Hibbett Retail Data Breach Notice
The notice describes the Hibbett Retail data breach, including the type of information that may have been involved and the steps offered to affected individuals.
Open the Hibbett Retail Data Breach Notice in a New Tab
Sources and additional information about the data breach:
-
- Hibbett Retail Website
- Texas Attorney General Data Security Breach Reports
- Washington Attorney General Data Breach Notifications Directory
- California Attorney General Submitted Breach Notification Sample
- my Social Security
- Medicare.gov: Reporting Medicare fraud & abuse
- FTC: Checking Your Credit Report
- FTC: Credit Freezes and Fraud Alerts
- AnnualCreditReport.com
- FTC Consumer Advice: Identity Theft
- IdentityTheft.gov
- IRS Identity Theft Guide for Individuals
- IRS Identity Theft Guide Central
- IRS: Get an identity protection PIN (IP PIN)
- U.S. Department of Health and Human Services Office of Inspector General: Medical Identity Theft
- IdentityTheft.gov: What To Do if Your Information Was Lost or Stolen, or Part of a Data Breach
Class Action FAQ
About This Data Breach Resource
This page was created to give affected individuals and researchers a clear, comprehensive explanation of the Hibbett Retail data breach. It summarizes what is currently known about the incident, including the timeline, how the breach was discovered, the types of information involved, the number of people affected when available, important notice dates, and steps individuals may want to take after receiving a data breach notification.
This resource is independently written and organized to help readers understand the breach without having to review multiple notices, state attorney general filings, company statements, and related materials. When available, this page relies on primary sources and identifies key facts, unanswered questions, and updates as new information becomes public.
This page is especially relevant for readers searching for information about the Hibbett Retail data breach, Hibbett Retail data breach notice, Hibbett Retail class action investigation, what information was exposed, how many people were affected, and what affected individuals should do next.
Abington Cole + Ellery reviews data breach incidents involving sensitive personal information, financial information, and protected health information. This page is intended to help affected individuals understand the publicly reported facts, the types of information that may have been involved, and practical steps that may reduce the risk of identity theft or medical identity theft.
The information on this webpage is provided for general informational purposes only and does not constitute legal advice. Nothing on this page should be relied upon as legal advice for any particular situation. Submitting information through this page does not create an attorney-client relationship.
For more information about steps you can take to possibly reduce the risk harm arising from a data breach, please review the following article: What are some steps you can take if you've been the victim of a data breach?
This website is not associated with nor authorized by Hibbett Retail or any affiliated companies. If you have received any other data breach notifications, you may want to review Abington Cole + Ellery's current list of data breach investigations.