Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Attacks - Leeds United Supporters Suffer Cyber Attack
Attacks Data Breach Data Protection Latest News News & Analysis

Leeds United Supporters Suffer Cyber Attack

Adam ParlettBy Adam ParlettMarch 7, 2025Updated:May 2, 20254 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Leeds
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Following the conclusion of some of their matches this season, as with any other season, the sentiment among Leeds United football supporters that they have “been robbed” can be heard reverberating around the ground, on the terraces, and in the streets around their Elland Road stadium. Perceived injustice is a part of the sport, and although keenly felt, their loyal followers can (after a cup of Yorkshire tea) shrug it off and carry on. 

What they won’t be so familiar with, however, is receiving an official communication from the club informing them that they themselves have actually been robbed. This was what some fans had to endure this week when they received an email from the club telling them that they had been directly impacted following a cyber-attack targeting the club’s retail website between 19th and 24th February this year. 

Incident Report 

An attack, Leeds United went on to state in a post on their official website, leedsunited.com, that had “resulted in the card details of a small number of customers being compromised.” The club expressed frustration that attackers had bypassed “layers of cybersecurity” and went on to offer their sincere apologies to anyone adversely affected by the incident. In the statement, they also reassured supporters that their response had been to have “a specialist third party” conduct a “forensic investigation” upon discovering the breach, with steps subsequently taken to halt the attack and reclaim control of their systems. The club said they are also continuing to work with the Information Commissioner’s Office. 

It’s in The Game 

Unfortunately, this isn’t the only case of a football club operating in the second-highest tier of English football, which is also the fifth-best followed league in Europe, falling victim to a cyber-attack this season. The Mail Online reported in September 2024 that two other clubs, Sheffield Wednesday and Bristol City, had been victims of attacks, with numerous supporters of the latter sharing on a popular fans forum that they had received suspicious emails from the club informing them orders made and previously despatched in 2023 “had now been despatched.” In both club’s attacks, phishing emails were sent out from malicious actors pretending to be senior figures at the football club, namely the finance director and chief financial officer, respectively. 

Defensive Work 

Although Leeds United has yet to elaborate on the specificities of their own attack, the details we have would suggest that the attack may well be similar to the one experienced earlier this year by fans of the NFL giants, The Green Bay Packers. In that incident, a threat actor hacked the team’s official online retail store and injected a card skimmer script to steal customers’ personal and payment information. Like Leeds, when Green Bay notified their customers what had happened, they detailed a window of multiple days where sensitive data was potentially compromised. As a gesture of goodwill, Green Bay is offering subsidized access to credit monitoring and identity theft restoration services. Still, as we are not privy to Leeds United’s direct correspondence to affected supporters at this time, we cannot confirm what remediations they may have offered. 

Javvad Malik, Lead Security Awareness Advocate at KNowBe4, praised Leeds United’s handling of the incident. He said, “Leeds’s swift response is commendable and serves as a wake-up call for the entire sports industry.” 

Expert Analysis 

As this blog detailing emerging cybersecurity scams from Tripwire rightly identifies, “Attackers do not care about who they target as long as they get people’s and establishments’ information and credentials.” As major enterprises with tens, sometimes hundreds, of thousands of customers or more, major football clubs are attractive targets for opportunistic cybercriminals seeking to exploit vulnerabilities and leverage the loyalty of supporters. 

James McQuiggan, a Security Awareness Advocate who also operates at KnowBe4, highlighted what steps individuals could take to protect themselves. “Individuals need to be proactive with their financial security by regularly monitoring their bank, credit card, or other financial accounts. Cybercriminals always go after the money and detect unauthorized transactions, and users can alert their financial institutions to prevent further fraudulent activity.” 

Adam Parlett
Adam Parlett

Adam Parlett is a cybersecurity marketing professional who has been working as a project manager at Bora for over two years. A Sociology graduate from the University of York, Adam enjoys the challenge of finding new and interesting ways to engage audiences with complex Cybersecurity ideas and products.

  • Adam Parlett
    Apache Tomcat Under Siege 2: Well-Hidden Payload
  • Adam Parlett
    NIST Adds SandboxAQ’s HQC as Their Newest PQC Standard
  • Adam Parlett
    Policy Statement Sheds Light on Upcoming UK Cybersecurity Bill
  • Adam Parlett
    New Lazarus Group Scam Targets Crypto Jobseekers

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Miasma worm spreads from Red Hat packages to Microsoft repositories

June 11, 20264 Mins Read

Dutch police, NCSC take down major botnet

June 4, 20264 Mins Read

CrowdStrike, Google, and Shadowserver Foundation disrupt Glassworm botnet

June 1, 20265 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}