Hibbett Retail Data Breach Class Action Lawsuit Investigation

Data breach law firm Abington Cole + Ellery is investigating potential legal claims related to the Hibbett Retail data breach, which reportedly affected about 109,732 individuals and may have exposed names, addresses, dates of birth, Social Security numbers, driver’s license or state identification numbers, passport numbers, military identification numbers, student identification numbers, financial and banking information, medical information, and health insurance information.


JOIN THIS INVESTIGATION: If you are interested in potentially volunteering to serve as a class representative in a class action lawsuit against Hibbett Retail, please submit your information to be considered:

You may also open the form here: Hibbett Retail Data Breach Lawsuit Form. An attorney-client relationship is not formed by submitting information through this website.

Hibbett Retail Data Breach: Key Facts

Company: Hibbett Retail
Location: Birmingham, Alabama
Incident Type: UNDISCLOSED
Number Affected: APPROXIMATELY 109,732
Data Involved: names, addresses, dates of birth, Social Security numbers, driver’s license or state identification numbers, passport numbers, military identification numbers, student identification numbers, financial and banking information, medical information, and health insurance information
Date Began: April 22, 2026
Date Discovered: July 26, 2026 (Discovery date reported in Hibbett’s Texas Attorney General filing. The notification letter does not separately specify a discovery date.)
Date Ended: April 25, 2026
Notice Date: September 8, 2026
Credit Monitoring: 12 Months of Experian IdentityWorks Credit 3B credit monitoring and identity theft protection
Status: Class Action Lawsuit Investigation


What happened in the Hibbett Retail data breach?

Hibbett Retail, Inc. disclosed a data breach involving personnel records after an unauthorized third party accessed its computer systems between April 22 and April 25, 2026. The company’s filing with the Texas Attorney General reports 109,732 affected individuals overall, including 15,223 Texans. Washington’s Attorney General separately reports 510 affected Washington residents. Hibbett’s notification letter explains that the records concerned current and former employees, their dependents, and beneficiaries, including employees of affiliated companies. Texas Attorney General Data Security Breach Reports; Washington Attorney General Data Breach Notifications Directory

According to Hibbett, an investigation determined that the intruder may have accessed and acquired files stored on its network, including records maintained for human resources purposes. The company says it secured its systems, notified law enforcement, and engaged outside forensic cybersecurity specialists after discovering suspicious activity. The method used to gain access has not been identified in the notification letter. The notice does not attribute the incident to phishing, stolen credentials, a particular software vulnerability, or ransomware.

The Texas filing identifies July 26, 2026, as the discovery date, while Hibbett’s individual notification letter is dated September 8, 2026. The letter describes a detailed review of the affected records over several months but does not provide specific dates for completing the forensic investigation or records review. It also does not explain how that description relates to the discovery date reported in Texas. California and Washington listed the breach on September 8, and Texas published its report on September 9, 2026. These reporting and notification dates are separate from the unauthorized access that occurred in April. Texas Attorney General Data Security Breach Reports; California Attorney General Submitted Breach Notification Sample; Washington Attorney General Data Breach Notifications Directory

Together, the Texas and Washington filings identify the potentially exposed information as names, addresses, dates of birth, Social Security numbers, driver’s license or state identification numbers, passport numbers, military identification numbers, student identification numbers, financial and banking information, medical information, and health insurance information. Washington specifically identifies health insurance policy or identification numbers. The reported categories do not establish that every affected person had every type of information exposed; recipients should consult their own letters for the information involved in their particular cases. Texas Attorney General Data Security Breach Reports; Washington Attorney General Data Breach Notifications Directory

Hibbett stated in its September 8 notice that it was unaware of fraud or identity theft connected to the incident. The company also reported taking steps to reduce the risk of a similar event, without describing those measures in detail. Its sample notice offers recipients one year of complimentary Experian IdentityWorks Credit 3B, including credit monitoring through Experian, Equifax, and TransUnion, identity restoration assistance, and up to $1 million in identity theft insurance, subject to policy terms and exclusions. No credit card is required to enroll, and enrollment does not affect the recipient’s credit score.

Individuals receiving a Hibbett Retail data breach letter should review the information identified in their notice and follow its instructions for activating the offered protection before the stated deadline. The enrollment deadline and activation code are redacted in the public sample. Hibbett also encourages recipients to review account statements and credit reports and promptly report suspicious activity. The available notice describes an incident involving employment-related records; it does not identify customer shopping accounts or retail purchase records as affected.


How did the Hibbett Retail breach occur?

The Hibbett Retail data breach occurred when an unknown third party gained unauthorized access to the company’s computer systems between April 22 and April 25, 2026. According to Hibbett’s notification letter, the intruder may have accessed and acquired files containing personnel records relating to current and former employees, their dependents, and beneficiaries.

The exact method of entry has not been disclosed in the notice. Hibbett does not identify phishing, stolen credentials, a software vulnerability, or ransomware as the cause. The notice confirms unauthorized system access but does not explain how the intruder obtained that access.


When did the Hibbett Retail breach occur?

The Hibbett Retail data breach reportedly took place on or around between April 22 and April 25, 2026.


How many people were affected by the Hibbett Retail breach?

The Texas Attorney General’s Hibbett filing reports 109,732 individuals affected overall, including 15,223 Texans. Texas Attorney General Data Security Breach Reports


What information was exposed in the Hibbett Retail breach?

  • According to Hibbett Retail’s filing with the Texas Attorney General, the information affected included:
    • Names
    • Addresses
    • Social Security numbers
    • Driver’s license numbers
    • Other government-issued identification numbers, such as passport or state ID numbers
    • Financial information, such as account numbers or credit or debit card numbers
    • Medical information
    • Health insurance information
    • Dates of birth
    • Military identification numbers
    • Student identification numbers
    These are the categories reported in the filing; not every affected person necessarily had every category exposed. Hibbett’s notification letter explains that the files included personnel records concerning current and former employees, their dependents, and beneficiaries. Individuals should consult their own notification letter for the information involved in their particular case. Texas Attorney General Data Security Breach Reports; Washington Attorney General Data Breach Notifications Directory

Has Hibbett Retail offered free credit monitoring and/or identity theft protection services?

  • Yes. Hibbett Retail is offering one year of free Experian IdentityWorks Credit 3B credit monitoring and identity theft protection, according to its September 8, 2026 notification letter. The services include:
    • Three-bureau credit monitoring through Experian, Equifax, and TransUnion.
    • Identity restoration assistance, including continued restoration support after the membership expires through Experian’s ExtendCARE service.
    • Up to $1 million in identity theft insurance, subject to policy terms, conditions, and exclusions.
    No credit card is required to enroll, and enrollment does not affect the recipient’s credit score. Recipients should use the activation code and enrollment deadline in their notification letter.

Hibbett Retail data breach timeline:

Date Event
April 22–25, 2026 An unauthorized third party accessed Hibbett Retail’s computer systems and may have accessed and acquired files, including personnel records concerning current and former employees, their dependents, and beneficiaries.
July 26, 2026 Discovery date reported in Hibbett’s Texas Attorney General filing. The notification letter does not separately specify a discovery date.
Following discovery; specific dates not disclosed Hibbett says it secured its systems, notified law enforcement, and engaged outside forensic cybersecurity specialists. The company also reviewed the affected records to determine what personal information was involved.
September 8, 2026 Hibbett dated its individual notification letters, offering eligible recipients one year of complimentary Experian IdentityWorks Credit 3B credit monitoring and identity protection services.
September 8, 2026 California and Washington listed the breach. Washington reported 510 affected residents.
September 9, 2026 Texas published Hibbett’s report. Its underlying public data identified 109,732 affected individuals overall, including 15,223 Texans.

Who is Hibbett Retail?

Hibbett Retail, Inc. is a retailer based in Birmingham, Alabama, specializing in athletic footwear, clothing, and accessories. The company serves customers through physical stores, its website, and the Hibbett mobile app. Its merchandise includes sneakers, running shoes, sports apparel, and casual clothing for adults and children, with products from brands such as Nike, Jordan, adidas, and New Balance. Hibbett Retail Website


What should you do if you received a Hibbett Retail data breach letter?

If you received a Hibbett Retail data breach letter, review it carefully and take steps based on the specific information involved:

    • Keep the letter and identify what was exposed. Your notice should describe the information affected in your case. Save the letter, envelope, and records of any related expenses or suspicious activity.
    • Enroll in the free protection offered. Hibbett’s sample notice offers one year of Experian IdentityWorks Credit 3B, including three-bureau credit monitoring and identity restoration assistance. Use the activation code and deadline in your letter. No credit card is required.
    • Consider freezing your credit, particularly if your Social Security number was exposed. Contact Equifax, Experian, and TransUnion separately. Freezes are free and do not affect your credit score. You can also place a free, one-year fraud alert through one bureau, which must notify the other two. FTC: Credit Freezes and Fraud Alerts
    • Review credit reports and financial accounts. Look for unfamiliar accounts, inquiries, withdrawals, or charges. If account or payment-card information was involved, contact your bank or card issuer promptly about appropriate safeguards.
    • Check medical and insurance records if those details were exposed. Review bills and explanations of benefits for care you did not receive. Report unfamiliar services or claims to the provider and insurer. If an identification-document number was exposed, contact its issuing agency for guidance.
    • Watch for impersonation attempts. Be cautious about unexpected calls, texts, or emails referencing Hibbett or the breach. Verify requests independently before sharing personal information, passwords, or verification codes.
    • Act promptly if you discover misuse. Contact the affected institution and Experian’s identity restoration service, and report identity theft through IdentityTheft.gov. Keep copies of reports, correspondence, and any resulting costs.

Hibbett Retail Data Breach Notice

The notice describes the Hibbett Retail data breach, including the type of information that may have been involved and the steps offered to affected individuals.

Open the Hibbett Retail Data Breach Notice in a New Tab


Sources and additional information about the data breach:


Class Action FAQ

A class action lawsuit is a case brought on behalf of a group of people who were harmed in a similar way by the same company or organization.

A class representative, sometimes called a named plaintiff or lead plaintiff, is a person who volunteers to bring the lawsuit on behalf of the larger group. They help represent the interests of everyone in the class. There may be more than one class representative in a class action.

A person who was harmed may start a class action if many other people were harmed in a similar way.

Usually, no. In many class action cases, the lawyers are paid only if the case is successful.

Sometimes you do not need to do anything. Other times, you may need to submit a claim form by a deadline to receive money or benefits.


Infographic summarizing the Hibbett Retail data breach, including the number of affected individuals, the categories of information involved, and the publicly confirmed reporting timeline.
Hibbett Retail data breach infographic summarizing the number of people affected, the types of information involved, and the publicly confirmed timeline. Information current as of September 8, 2026.


About This Data Breach Resource

This page was created to give affected individuals and researchers a clear, comprehensive explanation of the Hibbett Retail data breach. It summarizes what is currently known about the incident, including the timeline, how the breach was discovered, the types of information involved, the number of people affected when available, important notice dates, and steps individuals may want to take after receiving a data breach notification.

This resource is independently written and organized to help readers understand the breach without having to review multiple notices, state attorney general filings, company statements, and related materials. When available, this page relies on primary sources and identifies key facts, unanswered questions, and updates as new information becomes public.

This page is especially relevant for readers searching for information about the Hibbett Retail data breach, Hibbett Retail data breach notice, Hibbett Retail class action investigation, what information was exposed, how many people were affected, and what affected individuals should do next.

Abington Cole + Ellery reviews data breach incidents involving sensitive personal information, financial information, and protected health information. This page is intended to help affected individuals understand the publicly reported facts, the types of information that may have been involved, and practical steps that may reduce the risk of identity theft or medical identity theft.

The information on this webpage is provided for general informational purposes only and does not constitute legal advice. Nothing on this page should be relied upon as legal advice for any particular situation. Submitting information through this page does not create an attorney-client relationship.

For more information about steps you can take to possibly reduce the risk harm arising from a data breach, please review the following article: What are some steps you can take if you've been the victim of a data breach?

This website is not associated with nor authorized by Hibbett Retail or any affiliated companies. If you have received any other data breach notifications, you may want to review Abington Cole + Ellery's current list of data breach investigations.