Powered by MOMENTUM MEDIA
cyber daily logo
Breaking news and updates daily. Subscribe to our Newsletter

‘Confidential’ information stolen in DICK’S Sporting Goods cyber attack

The US’ largest sporting equipment retail chain, DICK’S Sporting Goods, reveals that a cyber attack on its systems resulted in “confidential” information being exfiltrated.

user icon Daniel Croft
Thu, 29 Aug 2024
‘Confidential’ information stolen in DICK’S Sporting Goods cyber attack
expand image

In a company filing with the US Securities and Exchange Commission (SEC), the organisation said that it determined that its systems were breached by an unauthorised user, who gained access to areas responsible for storing data.

“On August 21, 2024, the company discovered unauthorised third-party access to its information systems, including portions of its systems containing certain confidential information,” said DICK’S.

“Immediately upon detecting the incident, the company activated its cyber security response plan and engaged with its external cyber security experts to investigate, isolate and contain the threat. The company has also notified federal law enforcement.”

============
============

The company added that the investigation is ongoing but that findings to date do not indicate that any business operations were halted, nor does it believe that the incident is material.

However, a source close to the matter speaking with BleepingComputer said that email systems were shut down and employees were locked out of accounts in what was likely an attempt to prevent further unauthorised access and lock down the threat actor.

An internal memo to staff from DICK’S described the account lock-out as a “planned activity.

“Your leader will reach out with instructions on next steps and timing. They may contact you via text or personal email, so please monitor those accounts,” it said.

The source also said that account access is being restored slowly by IT staff following facial verification on camera. Additionally, the source said that very few details of the breach were given to employees and that they have been instructed not to put anything in writing or to discuss the matter publicly.

Cyber Daily is yet to identify any threat actors claiming an attack on DICK’S, nor has the company disclosed the nature of the incident. This story will be updated as more information becomes known.

DICK’S was founded in 1948 and operates 857 stores across the US. Over 55,000 people are employed by the company, which reported US$12.98 billion in revenue last year.

Daniel Croft

Daniel Croft

Born in the heart of Western Sydney, Daniel Croft is a passionate journalist with an understanding for and experience writing in the technology space. Having studied at Macquarie University, he joined Momentum Media in 2022, writing across a number of publications including Australian Aviation, Cyber Security Connect and Defence Connect. Outside of writing, Daniel has a keen interest in music, and spends his time playing in bands around Sydney.

newsletter
cyber daily subscribe
Be the first to hear the latest developments in the cyber industry.