DataBreachCaseFile.com
MonitoringVermont AG filing · September 8, 2026

Hibbert Retail Suffers Data Breach, Customer Data Exposed

Hibbert Retail, Inc. experienced a cybersecurity incident that compromised customer data, as disclosed in filings to the Vermont Attorney General. The breach exposed various personal and financial details, posing risks such as targeted scams and potential financial fraud for affected individuals. An investigation into the incident is currently ongoing.

State
Vermont
Reported
September 8, 2026

What may have been exposed

  • Full Name
  • Email Address
  • Password or Credential Hash
  • Mailing Address
  • Purchase and Order History
  • Payment Card Information

Public disclosures filed with the Vermont Attorney General on September 8, 2026, indicate that Hibbert Retail, Inc. suffered a data security breach. The incident compromised digital infrastructure storing customer information from its extensive retail and e-commerce operations. This filing serves to formally document the cybersecurity event.

The nature of the cybersecurity incident was unspecified, but it led to unauthorized access to customer records. Given the company's broad online and in-store presence, Hibbert Retail, Inc. routinely handles a significant volume of personal consumer data, which was reportedly affected in this event.

The exposed data categories include Full Name, Email Address, Password or Credential Hash, Mailing Address, Purchase and Order History, and Payment Card Information. The compromise of these data types carries distinct risks for individuals. Exposed email addresses and full names can lead to increased phishing attempts, while mailing addresses may facilitate postal scams. Hashed passwords, even if encrypted, can be vulnerable to cracking, potentially leading to unauthorized access to online accounts.

Exposure of Payment Card Information directly raises the risk of fraudulent transactions. Purchase and Order History, when combined with other exposed data, can be used by malicious actors for highly personalized and convincing social engineering attacks. Individuals should be vigilant for any suspicious activity across their accounts.

Customers who receive a notification regarding this breach should immediately change any passwords that might be similar to the one used for Hibbert Retail accounts, especially if they reuse passwords across multiple services. It is also advisable to enable multi-factor authentication (MFA) on all online accounts where available to add an extra layer of security. Affected individuals should closely monitor their payment card statements and credit reports for any unauthorized charges or unusual activity.

The investigation into the Hibbert Retail, Inc. data breach is currently in a monitoring status, as per the official filing.

Source: Vermont Attorney General filing

More Vermont data breach cases