Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Data Breach - NFL Giants Green Bay Have Their Online Defense Breached
Data Breach Attacks Latest News News & Analysis Threats and Vulnerabilities

NFL Giants Green Bay Have Their Online Defense Breached

Adam ParlettBy Adam ParlettJanuary 10, 2025Updated:March 7, 20254 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
NFL
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Whilst the four-time Superbowl Champions, The Green Bay Packers, have rightly been drawing praise this season for their on-field defensive performances, the Organization’s online defense has been called into question following the disclosure of a significant data breach affecting thousands of their loyal supporters.

Contrasting Fortunes

The last week of 2024 saw the storied franchise triumph 34-0 against the New Orleans Saints to record the first defensive shutout of the current NFL season. In his post-match comments, Packers head coach Matt LaFleur gushed, “Obviously, it’s hard to shutout an opponent in this league. From what I was told, it was the first one this season. So, I was really proud of our defense.”

Fast-forward to the start of 2025, however, and pride in defense is certainly not a sentiment resonating with Packer Nation right now. In a letter to supporters, Chrysta Jorgensen, Director of Retail Operations, had the unenviable task of informing them that a threat actor had hacked its official online retail store and injected a card skimmer script to steal customers’ personal and payment information.

What’s the Score?

The letter alerted customers that between September 23-24, 2024, and October 3-23, 2024, their sensitive data was potentially compromised during the checkout stage when completing purchases on their Packers Pro Shop. This data may include name, address (billing and shipping), email address, credit card type, credit card number, credit card expiration date, and credit card verification number. It was stated, however, that transactions made during this time using a gift card, Pro Shop website account, Paypal, or Amazon Pay were not affected by this malicious code.

Following the discovery, the organization’s IT team took steps to resolve the issue. They started by disabling all payment and checkout functions and investigating alongside external cybersecurity experts to assess any potential impact on customer information. They also instructed the site’s hosting vendor to remove the malicious code, update passwords, and ensure no vulnerabilities remained.

As a gesture of goodwill, Green Bay is offering subsidized access to credit monitoring and identity theft restoration services.

You’re in the Game

Green Bay has advised individuals of the steps they can take if they have been affected, are unsure if they’ve been affected, or are just looking to implement good practices in managing their financial affairs. These include reviewing bank statements, monitoring free credit reports, and promptly reporting any suspicious activity to the relevant financial institution holding your accounts, as well as any appropriate authorities, such as your state attorney general and the Federal Trade Commission (“FTC”). Individuals have also been reminded that they have the right to obtain a police report in the event one has been created for this incident.

Expert Analysis

Cybersecurity experts from Black Duck have been giving their reaction to the breach disclosure. Cybersecurity practice lead John Waller asserts that the hack “underscores the growing threat of e-commerce skimming attacks, where malicious scripts are injected into vulnerable websites to steal sensitive customer data during checkout, often remaining undetected for extended periods as this hack was.” He goes on to point out that organizations implementing The Payment Card Industry Data Security Standard (PCI-DSS) 4.0 (which is set to become mandatory on March 31, 2025) can “significantly reduce the risk of breaches while ensuring compliance with evolving security standards.”

Ray Kelly, fellow at Black Duck, adds that “Card skimmer scripts have been a serious threat to online marketplaces for many years.” He cites the Magecart attacks as another example, along with this case, of why it is so essential to secure the supply chain, as “even a single weak link can have catastrophic consequences for businesses and their customers.”

Huddle Up

This author isn’t the first and certainly won’t be the last to equate American football and cybersecurity defensive strategies to you in print – but in relation to this story, it’s timely, relevant, and I’ll be succinct. The best methods for both disciplines entail blocking threats to protect key targets by prioritizing clear communication, continuous monitoring, and adaptability.

Adam Parlett
Adam Parlett

Adam Parlett is a cybersecurity marketing professional who has been working as a project manager at Bora for over two years. A Sociology graduate from the University of York, Adam enjoys the challenge of finding new and interesting ways to engage audiences with complex Cybersecurity ideas and products.

  • Adam Parlett
    Apache Tomcat Under Siege 2: Well-Hidden Payload
  • Adam Parlett
    NIST Adds SandboxAQ’s HQC as Their Newest PQC Standard
  • Adam Parlett
    Policy Statement Sheds Light on Upcoming UK Cybersecurity Bill
  • Adam Parlett
    New Lazarus Group Scam Targets Crypto Jobseekers

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

7-Eleven Notifies Franchise Applicants After Breach Exposes Personal Data

May 19, 20262 Mins Read

Canvas cyberattack disrupts universities as ShinyHunters threatens massive data leak

May 12, 20267 Mins Read

Zara Owner Inditex Confirms Customer Data Breach Affecting Nearly 200,000 People

May 11, 20263 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}