---
title: "Hasbro Cyberattack: Vishing Blamed, 6 Months Later"
metaTitle: "Hasbro Confirms Vishing-Driven Breach"
description: "Hasbro confirms its March 2026 breach began with a vishing call, not malware — joining MGM, Caesars, and Clorox in the help-desk attack pattern."
slug: hasbro-vishing-breach
date: "2026-09-29T12:00:00-05:00"
featured: true
image:
  src: "https://cdn.securelogix.dev/hasbro-vishing-attack.webp"
  alt: "Toys arrayed in a way reminiscent of an army."
sourcePublisher:
  name: Tech Insider
  url: "https://tech-insider.org/"
sourceArticle:
  url: "https://tech-insider.org/hasbro-cyberattack-vishing-social-engineering-2026/"
tags: [Vishing, Social Engineering, Data Breach]
status: published
---

Hasbro has confirmed what security researchers had suspected for months: the network intrusion the toy and entertainment giant disclosed back in the spring started with a phone call, not a piece of malware. According to a report published by The Business Journals on September 28, 2026, Hasbro told Massachusetts regulators that the attack traced back to vishing and social engineering, the practice of tricking an employee or help-desk worker into handing over access rather than breaking through a technical defense. The admission arrives roughly six months after Hasbro first flagged unauthorized network access on March 28, 2026, and it puts the maker of Transformers, Monopoly, Dungeons & Dragons, Nerf, and Magic: The Gathering into the same category of victim as MGM Resorts, Caesars Entertainment, Clorox, Marks & Spencer, and Coinbase.

The Hasbro cyberattack is a case study in how long it now takes a public company to fully explain a breach to regulators and customers, and in how little technical sophistication attackers actually need when a phone call gets the job done. Hasbro's own securities filing described unauthorized access, contained systems, and an ongoing investigation, but it took roughly five months for the company to tell state regulators the specific method attackers used...
