Sports Direct 'hack puts staff details in the wild'

Firm allegedly fails to tell its staff their data was at risk

Sports Direct employees' personal details may have been put at risk in a data breach, according to The Register,although the retailer had allegedly not informed its 30,000-strong workforce about the incident.

A hacker or hackers broke into the company's systems last September using a security hole in Sports Direct's staff portal, according to the publication, which broke the story.It reported that the attackers took advantage of a vulnerability in Sport Direct's DNN platform, which had not been updated to include the latest security patch.

Bosses only found out about the breach in December, The Register said.

The details said to have been stolen include the names, emails and postal addresses of employees working at the sporting goods retailer, but it's unclear what the hackers have done with the data.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

According to the ICO, Sports Direct has advised it of the hack and it will be "making enquiries" into how the attack occurred.

A spokesman for Sports Direct said in a statement: "We cannot comment on operational matters in relation to cybersecurity for obvious reasons. However, it is our policy to continually upgrade and improve our systems, and where appropriate we keep the relevant authorities informed."

Dr Jamie Graves, CEO at Zonefox said the way Sports Direct dealt with the breach is not an advisable approach.

"The waySportsDirecthas handled their data breach last year is a perfect example of how not to deal with a cyber attack,"Graves said. "With the looming EU GDPR regulations stating companies must declare a data breach within 72 hours or they will face severe fines, a lot of learning must be done by businesses on how they deal with a breach.

"They have said they filed a report with the ICO, but how quickly that happened has not been disclosed," he added. "This is a classic case of an avoidable breach; an unpatched system with unencrypted details."

Featured Resources

What you need to know about migrating to SAP S/4HANA

Factors to assess how and when to begin migration

Download now

Your enterprise cloud solutions guide

Infrastructure designed to meet your company's IT needs for next-generation cloud applications

Download now

Testing for compliance just became easier

How you can use technology to ensure compliance in your organisation

Download now

Best practices for implementing security awareness training

How to develop a security awareness programme that will actually change behaviour

Download now
Advertisement

Most Popular

Visit/policy-legislation/data-governance/354496/brexit-security-talks-under-threat-after-uk-accused-of
data governance

Brexit security talks under threat after UK accused of illegally copying Schengen data

10 Jan 2020
Visit/microsoft-windows/32066/what-to-do-if-youre-still-running-windows-7
Microsoft Windows

What to do if you're still running Windows 7

14 Jan 2020
Visit/hardware/laptops/354533/dell-xps-13-new-9300-hands-on-review-chasing-perfection
Laptops

Dell XPS 13 (New 9300) hands-on review: Chasing perfection

14 Jan 2020
Visit/operating-systems/25802/17-windows-10-problems-and-how-to-fix-them
operating systems

17 Windows 10 problems - and how to fix them

13 Jan 2020