DataBreachLegalCenter.com
MonitoringCalifornia AG filing · September 8, 2026

Hibbett Retail Data Breach: Understanding Your California Notification

Hibbett Retail, Inc. disclosed a data breach to California authorities on September 8, 2026, impacting customer data from an incident on April 22, 2026. If you received a notification, your Full Name, Email Address, Mailing Address, Phone Number, Password or Credential Hash, Purchase and Order History, Payment Card Information, or Loyalty Account Details may have been exposed, creating potential risks.

State
California
Breach date
April 22, 2026
Reported
September 8, 2026

What may have been exposed

  • Full Name
  • Email Address
  • Password or Credential Hash
  • Mailing Address
  • Purchase and Order History
  • Payment Card Information
  • Phone Number
  • Loyalty Account Details

Hibbett Retail, Inc., a prominent sporting goods and athletic footwear retailer, reported a data security incident to the California Attorney General on September 8, 2026. This report indicates that customer information was accessed without authorization during an incident that occurred on or about April 22, 2026.

The breach involved various categories of customer personal information. If you received a notification letter from Hibbett Retail, your exposed data may include your Full Name, Email Address, Password or Credential Hash, Mailing Address, Purchase and Order History, Payment Card Information, Phone Number, and Loyalty Account Details.

Exposure of these data types can lead to significant risks for those affected. Bad actors may use this information for fraudulent transactions, to attempt to access other online accounts using your compromised credentials, or to send sophisticated phishing emails. It is important to be vigilant for any unusual activity across your accounts and communications.

If you received a data breach notification letter from Hibbett Retail, Inc., it's a formal acknowledgment that your private information was compromised due to security shortcomings. Review the letter carefully to understand what specific data types were affected in your case. Consider monitoring your accounts for suspicious activity and changing relevant passwords, especially if you reuse them across multiple services.

Under California law, companies like Hibbett Retail, Inc. have a duty to safeguard consumer data through reasonable security measures. When a breach occurs, individuals may have legal recourse. Our firm is currently investigating claims related to the Hibbett Retail data breach and offers a free, no-obligation case review to help you understand your situation and potential next steps.

What to do if you were affected

Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.

  • Watch your financial accounts

    Review bank and card statements for unfamiliar activity and turn on transaction alerts. Report anything you don't recognize to your bank right away.

  • Secure your online accounts

    Change the password on any account that reused an exposed password and turn on two-factor authentication wherever it's offered.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Source: California Attorney General filing

Related data breach cases