
Hibbett Retail, Inc. is notifying employees that an unknown third party gained unauthorized access to its systems and may have acquired files containing personnel records during an April 2026 security incident.
The company said in a breach notification dated September 8, 2026, that it detected suspicious activity on its computer network and responded by securing its systems, notifying law enforcement, and engaging external forensic cybersecurity experts to investigate.
The forensic investigation determined that an unknown third party had unauthorized access to Hibbett's systems between April 22 and April 25, 2026. During that period, the intruder may have accessed and acquired files containing HR records related to current and former employees, as well as their dependents and/or beneficiaries.
Hibbett is an Alabama-based sporting goods retailer and a wholly owned subsidiary of UK-based JD Sports. As of February 2024, the company operated 1,169 stores across 36 US states, including Hibbett Sports, City Gear, and Sports Additions locations, and employed approximately 12,500 people. JD Sports completed its acquisition of Hibbett in 2024 after agreeing to buy the retailer for approximately $1.08 billion.
Following the intrusion, Hibbett said it spent several months conducting an in-depth review of the affected records to determine what information was involved and identify individuals requiring notification.
The redacted notification states that the affected records contained the recipient's name and additional personal information, although the specific additional data element is obscured in the supplied copy.
Hibbett said it is not aware of any fraud or identity theft resulting from the incident. Impacted individuals are being offered a complimentary one-year Experian IdentityWorks Credit 3B membership, providing monitoring across Experian, Equifax, and TransUnion, identity restoration assistance, and up to $1 million in identity-theft insurance.
The company has not disclosed how the attacker initially gained access to its network, and the notification does not characterize the incident as ransomware.
At the time of writing, no ransomware group or data-extortion operation has publicly claimed responsibility for the attack.
Affected individuals should consider enrolling in the offered monitoring service and closely watch their financial and credit accounts for suspicious activity. Those concerned that their information could be misused can also consider placing a fraud alert or security freeze on their credit files.u







Leave a Reply