Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Sports Direct Data Breach
News & Analysis

Sports Direct Data Breach

ISBuzz TeamBy ISBuzz TeamFebruary 10, 2017Updated:July 8, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
FanDuel Cautions Users Of Data Breach In Vendor Hack
FanDuel Cautions Users Of Data Breach In Vendor Hack
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Following the news that Sports Direct suffered a data breach as the result of an unpatched staff portal – and failed to inform its own staff, IT security experts from Kaspersky Lab, SentinelOne, TrapX, RES and ZoneFox  commented below.

David Emm, Principal Security Researcher at Kaspersky Lab:

David Emm“Customers that entrust private information to the care of a business should be safe in the knowledge it is kept in a secure manner. Whilst security solutions significantly mitigate the risk of a successful attack, there are also other measures businesses can take in order to provide thorough protection. These measures include running fully updated software, performing regular security audits on the website code and penetration testing the infrastructure. It’s crucial that businesses ensure that all passwords are protected using secure hashing and salting algorithms. The best way for organisations to combat these types of cyber-attacks is at the beginning; by having an effective cyber-security strategy in place before the company becomes a target.

Consumers have no control over the security of their online providers.  However, they can mitigate the risk of a security breach.  We would recommend that everyone uses unique, complex passwords for all their online accounts. It’s a growing concern that many people use the same password and personal details across multiple online accounts, meaning if their details have been compromised by one attack they could find other accounts suffer too.   We would also urge people to take advantage of two-factor authentication, where a provider offers this.

This breach once again underlines the need for regulation.  It’s to be hoped that GDPR (General Data Protection Regulation), which comes into force in May 2018, will motivate firms to, firstly, take action to secure the customer data they hold, and secondly, to notify the ICO of breaches in a timely manner”

Andy Norton, Risk Officer EMEA at SentinelOne:

andy-norton“In comparison to other leading retailers, the section on operational risk oversight relating to cyber risk in the sports direct annual report seems minimal. Other retailer reports, announce the appointment of a CISO, explanation of the committee structure on how the board is briefed on cyber risk, and statements on continuous vigilance and incident response.

The information Commissioners office has been notified by sports direct on the breach and they will decide the appropriate course of action based on sports directs handling of the situation against best practises.”

Kevin Eley, VP of Sales EMEA at TrapX:

kevin-eley“The frequency of successful attacks on network leading to subsequent data breach is unfortunately only set to increase in 2017. Yet more well-known brands will be reported in the press as having been the victim of a successful cyber-attack. Organisations will need to consider innovative new approaches to protecting their sensitive data since traditional approaches are clearly failing.

However, it is also important that organisations adopt a responsible and mature approach to reporting breaches to the stakeholders that have affected. If the reports of the Sports Direct breach are to be believed, and affected stakeholders were not notified; then it is nothing short of woeful and can only lead to a further erosion of employees trust in the brand. That cannot be a good state of affairs at all!”

Jason Allaway, VP UK & Ireland at RES:

jason-allaway“Sports Direct is another example that no organisation, regardless of its size or the industry it operates in, is safe from a potential security breach.

Sports Direct, the UK’s largest sports retailer, was undone by unpatched software used for its staff portal. For a company of its size to hold critical staff data behind an insecure platform is a daunting thought. We expect every organisation to stay up to date with its security and we expect it even more from high street giants employing thousands of people. Not downloading the most recent patches to software can leave you exposed to these kinds of issues – patches are developed for a reason, and cyber criminals are always innovating to stay one step ahead.

This is a stark reminder not only to Sports Direct but every company that vigilance should be implemented as gospel. Every organisation should always assume they have been infiltrated. As such, penetration tests should be carried out regularly. It’s even worth getting friendly hackers to expose – and then patch up – any existing vulnerabilities before they can be exploited.

Sports Direct should treat this episode as a valuable lesson and an opportunity to ramp up their security processes. For other companies, it’s another reminder that you can’t hide a breach from your employees, let alone everyone else”

Dr Jamie Graves, CEO at ZoneFox:

jamie-graves “The way Sports Direct has handled their data breach last year is a perfect example of how not to deal with a cyber attack. Keeping their 30,000-strong workforce in the dark for over a year is simply unacceptable. And it’s not just morally dubious; with the looming EU GDPR regulations stating companies must declare a data breach within 72 hours or they will face severe fines, a lot of learning must be done by businesses on how they deal with a breach. They have said they filed a report with the ICO, but how quickly that happened has not been disclosed. This is a classic case of an avoidable breach; an unpatched system with unencrypted details. This is infosec 101 and they got it wrong.”

“It’s one thing having the right technology and experts in place to spot these attacks, but it’s equally as important is what you do after detection. Companies need to become more alert to such breaches and realise that they are all vulnerable. Too many businesses focus on threats that come from outside their organisations, which while a warranted focus, simply does not cover all bases, such as threats from inside the organisation and weak links in outdated software. Organisations must ensure they have visibility and control their data, which would have immediately alerted them to the data being taken.”

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}