Hasbro’s $25 million hit from a March 28 cyberattack
In early April the toy maker revealed that a breach on March 28 forced several systems offline and knocked roughly $25 million off its top line.
What went wrong
Attackers slipped into an employee account, harvested Social Security numbers, bank details, credit‑card data and driver‑license info for 436 staff members in Massachusetts. Hasbro moved quickly to shut down the compromised account and cut off the intruder’s foothold.
Technical response
The company disabled the affected account, terminated any unauthorized sessions, and rolled out extra safeguards across its network. Restoration work kept critical services down for a short window while forensic teams pieced together the timeline.
Who’s in the cross‑hairs
The breach hits 436 Massachusetts employees – their personal identifiers and financial records are now exposed. The broader employee base may or may not be affected; the company has not disclosed numbers beyond the state.
What you can do now
- Audit privileged accounts daily and revoke access that isn’t actively used.
- Enforce multi‑factor authentication for any remote or internal logins.
- Deploy continuous monitoring to flag anomalous activity on employee credentials.
- Notify affected personnel promptly and offer credit‑monitoring services.
- Review incident‑response playbooks to ensure rapid containment similar to Hasbro’s actions.
