News: 1741176015

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Leeds United kick card swipers into Row Z after 5-day cyberattack

(2025/03/05)


English football club Leeds United says cyber criminals targeted its retail website during a five-day assault in February and stole the card details of "a small number of customers."

The attack took place between February 19 and 24, it said in a statement.

The Register asked Leeds United for more details about the raid, whether any other details beyond payment card data were compromised, and exactly how many fans were affected, but it declined to comment further.

[1]

Its statement, however, went on to say that those who were impacted by the theft have already been notified directly and the club continues to liaise with the UK's data protection watchdog, the Information Commissioner's Office (ICO).

[2]

[3]

"A forensic investigation was undertaken by a specialist third party as soon the club discovered the breach, and measures were implemented to stop and recover from the attack," said Leeds United.

"The club is disappointed that the attack was successful despite layers of cybersecurity, and offer our sincere apologies to anyone who has been adversely affected."

[4]

Jake Moore, global cyber security advisor at Slovak security shop ESET, claimed it's likely the attackers were able to lift card details used in every transaction processed by the club shop in the five days it was compromised.

"These types of attacks are cleverly able to penetrate a website and take copies of all payments with ease whilst hiding undercover," he said. "In a short space of time, cybercriminals would have been able to swipe card payment details from all transactions from within the time frame affecting all customers from that time.

"Although this digital heist can often go under the radar, it highlights the importance of robust protection, due diligence by all websites handling user's financial data, and for website admins to monitor any anomalies, however small.

[5]

"Anyone affected by this breach should contact their bank immediately to cancel the compromised card, request a replacement, and follow the bank's fraud prevention guidance."

The English Football League (EFL), the governing body for the league in which Leeds United plays and currently leads, the Championship, [6]reportedly issued alerts in September 2024 after cyberattacks led to break-ins at the email systems of rival clubs Bristol City and Sheffield Wednesday.

[7]RansomHub claims to net data hat-trick against Bologna FC

[8]The amber glow of bork illuminates Brighton Station

[9]NFL to begin using face scanning tech across all of its stadiums

[10]Michael Dell lends support to bid for Everton Football Club

Crafty crims managed to gain access to both clubs' email systems and sent phishing links to fans. The EFL warned all 72 clubs under its remit not to open emails purporting to be from Bristol City's CFO Vicki Long or Sheffield Wednesday's finance director John Redgate.

League One club Charlton Athletic also disclosed its own cybersecurity problems earlier that same month, although it was separate from the email compromises at the Championship clubs and related to legacy IT infrastructure after recently migrating to the cloud.

Given the large sums of money associated with the sport, it makes sense that clubs are targeted by cybercriminals, including ransomware groups. Most recently Italy's [11]Bologna FC was hit by RansomHub in November, while the [12]San Francisco 49ers – who play the other football – were also attacked in 2022 by the extortionists at BlackByte. ®

Get our [13]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Z8iDNO8-7pcEO11KTVWmvQAAAJg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Z8iDNO8-7pcEO11KTVWmvQAAAJg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Z8iDNO8-7pcEO11KTVWmvQAAAJg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Z8iDNO8-7pcEO11KTVWmvQAAAJg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Z8iDNO8-7pcEO11KTVWmvQAAAJg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.dailymail.co.uk/sport/football/article-13891103/EFL-issues-cyber-attack-warning-TWO-Championship-clubs-breached-panicked-teams-recruit-external-agencies-fend-hackers.html#:~:text=They%20included%20links%20and%2C%20despite,chief%20financial%20officer%20Vicki%20Long.

[7] https://www.theregister.com/2024/11/30/bologna_fc_ransomhub/

[8] https://www.theregister.com/2024/09/04/bork/

[9] https://www.theregister.com/2024/08/06/nfl_face_scanning_tech/

[10] https://www.theregister.com/2024/06/10/michael_dell_everton_fc/

[11] https://www.theregister.com/2024/11/30/bologna_fc_ransomhub/

[12] https://www.theregister.com/2022/02/14/49ers_ransomware_blackbyte/

[13] https://whitepapers.theregister.com/



Inevitable cost of business . . .

m4r35n357

. . . on the internet.

We really did manage to survive before 1991, you know!

Re: Inevitable cost of business . . .

Charlie Clark

Dirty Leeds!

Charlie Clark

Pah! As if any self-respecting tyke is going to use anything as new fangled as the King's money! It's Earnshaws or nowt!

Rollin Rollin Rollin...

AskJeevesAI

All I'm going to say is I saw this coming a very very very very very very very very very long time ago....if you don't change your baseline standards or follow them at all it will come and sting you in the bottom :-)

This is now going to happen to every industry...good luck out there!

The "other" football

MiguelC

You mean the one mostly played by hand?

Machine-Independent, adj.:
Does not run on any existing machine.