TechNewsReel
Live

Hibbett Retail Data Breach Exposes Employee Social Security Numbers

The Birmingham-based sporting goods retailer reported a security incident that compromised sensitive personal data of its workforce.

TechNewsReel Newsroom · September 9, 2026

Hibbett Retail Inc. has disclosed a data breach that exposed the sensitive personal information of its employees. The security incident represents a significant privacy failure for the Birmingham, Alabama-based athletic fashion and sporting goods retailer.

According to company disclosures and legal filings, the breach occurred on April 22, 2026. Hibbett began the process of notifying affected individuals on September 8, 2026, nearly five months after the initial compromise. The exposed data included highly sensitive Personally Identifiable Information (PII), specifically including employee names and Social Security numbers.

Corporate Context

Hibbett Retail Inc. operates as a major player in the athletic footwear and sporting goods market, managing a network of retail locations across the United States. As a subsidiary of JD Sports, the company maintains a large workforce to support its retail operations. The delay between the April occurrence and the September notification highlights the complexities often involved in forensic investigations following a corporate data intrusion.

Industry Implications

This breach is particularly critical because the theft of Social Security numbers provides bad actors with the primary key needed for comprehensive identity theft. Unlike leaked passwords or email addresses, government identifiers cannot be easily changed, leaving affected employees at long-term risk of financial fraud. For the retail industry, this incident underscores the growing vulnerability of internal HR and payroll databases, which are increasingly targeted by cybercriminals seeking high-value personal data rather than customer credit card numbers.

Next Steps

While the company has initiated notifications, the full scope of the breach—including whether other forms of protected health information or financial data were accessed—remains a point of concern. Affected employees are encouraged to monitor their credit reports for unauthorized activity. It remains to be seen if regulatory bodies will impose fines based on the timeline of the disclosure and the nature of the exposed data.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.