Credit Card Info of 1.8 million People Stolen from Sports Gear Sites

Credit Card Info of 1.8 million People Stolen from Sports Gear Sites

Four affiliated online sports gear sites have disclosed a cyberattack where threat actors stole credit cards for 1,813,224 customers.

While not much is known about the attack, a law firm representing the four websites stated that personal information and credit card information, including full CVV, were stolen on October 1st, 2021.

Also Read: 4 Things to Know When Installing CCTVs Legally

The affected websites are the following:

The sites first learned of the breach on October 15th, and after an investigation, confirmed on November 29th the customers that had their payment information stolen.

The details that have been compromised as a result of this incident are the following:

  • Full name
  • Financial account number
  • Credit card number (with CVV)
  • Debit card number (with CVV)
  • Website account password

After the conclusion of the investigation, the websites sent notices to the affected individuals on December 16th, 2021.

None of the published notices to impacted customers provide any details on the nature of the incident, so the actual means of obtaining the data remains unknown.

However, as the description states, “External system breach (hacking),” this appears close to be a database breach rather than the implantation of card skimmers on the websites, although both scenarios are likely.

Whatever the case is, if you have purchased anything from these four websites, you should treat incoming communications with vigilance, monitor your bank account and credit card statements, and report any suspicious transactions immediately.

Also Read: 5 Most Frequently Asked Questions About Ransomware

“Upon becoming aware of the incident, Tackle Warehouse took the measures referenced above. We also reported the incident to the payment card brands in an attempt to prevent fraudulent activity on the affected accounts,” reads Tackle’s notification letter to customers.

“We also reported the incident to law enforcement and have worked closely with the digital forensics firm to enhance the security of our sites to facilitate safe and secure transactions.”

Unfortunately, the affected customers have not been offered an identity protection service this time, even though the compromised data is extremely sensitive information.

We have reached out to all the affected entities to learn more about the attack, and we will update this post as soon as we receive a response.

Privacy Ninja

Recent Posts

Role of Enhanced Access Controls in Safeguarding Personal Data in Telecommunications

Role of Enhanced Access Controls in Safeguarding Personal Data in Telecommunications that every Organisation in…

2 weeks ago

Role of Effective Incident Response Procedures in Strengthening Data Security

Effective Incident Response Procedures in Strengthening Data Security that every Organisation in Singapore should know…

2 weeks ago

Strengthening Your Cyber Defenses: The Crucial Role of Regular Vulnerability Scanning

Crucial Role of Regular Vulnerability Scanning that every Organisation in Singapore should know. Strengthening Your…

2 weeks ago

Enhancing Data Security with Multi-Factor Authentication

Enhancing Data Security with Multi-Factor Authentication that every Organisation in Singapore should know. Enhancing Data…

3 weeks ago

A Strong Password Policy: Your Organization’s First Line of Defense Against Data Breaches

Strong Password Policy as a first line of defense against data breaches for Organisations in…

3 weeks ago

Enhancing Website Security: The Importance of Efficient Access Controls

Importance of Efficient Access Controls that every Organisation in Singapore should take note of. Enhancing…

4 weeks ago