HISA Implements Password Reset and Enhanced Security Measures Following Data Breach
The Horseracing Integrity and Safety Authority (HISA) has initiated a mandatory password reset for all portal users, set to begin on Monday, August 24, as part of an ongoing response to a data breach. Users will be required to update their credentials upon logging in with their current passwords, along with verifying or updating their registered email addresses and mobile numbers.
In addition to the password reset, HISA has increased the sensitivity of its security monitoring tools. Users may now receive alerts for unusual login attempts, such as those originating from different geographic locations or devices. These notifications will prompt users to confirm whether the activity was legitimate or report unauthorized access.
The breach investigation is tied to Marshall Gramm, a former HISA owner charged with fraud and multiple rule violations after allegedly gaining unauthorized access to confidential horse health information. The incident has prompted HISA to strengthen its security protocols to prevent further exposure of sensitive data.
Horseracing Integrity and Safety Authority TPRM report: https://www.rankiteo.com/company/horseracing-integrity-and-safety-authority
"id": "hor1787430537",
"linkid": "horseracing-integrity-and-safety-authority",
"type": "Breach",
"date": "8/2026",
"severity": "60",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'customers_affected': 'All portal users',
'industry': 'Horseracing',
'name': 'Horseracing Integrity and Safety Authority '
'(HISA)',
'type': 'Regulatory Authority'}],
'attack_vector': 'Unauthorized Access',
'customer_advisories': 'Mandatory password reset and verification of contact '
'details',
'data_breach': {'sensitivity_of_data': 'High',
'type_of_data_compromised': 'Confidential horse health '
'information'},
'description': 'The Horseracing Integrity and Safety Authority (HISA) '
'initiated a mandatory password reset for all portal users and '
'enhanced security measures following a data breach. The '
'breach is linked to a former HISA owner charged with fraud '
'and unauthorized access to confidential horse health '
'information.',
'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
'unauthorized access to sensitive data',
'data_compromised': 'Confidential horse health information',
'operational_impact': 'Mandatory password reset, enhanced security '
'monitoring',
'systems_affected': 'HISA Portal'},
'initial_access_broker': {'high_value_targets': 'Confidential horse health '
'information'},
'investigation_status': 'Ongoing',
'motivation': 'Fraud, Rule Violations',
'post_incident_analysis': {'corrective_actions': 'Password reset, enhanced '
'monitoring, verification of '
'user contact details',
'root_causes': 'Unauthorized access by a former '
'owner'},
'references': [{'source': 'HISA Announcement'}],
'regulatory_compliance': {'legal_actions': 'Fraud and rule violation charges '
'against Marshall Gramm'},
'response': {'communication_strategy': 'User notifications for password reset '
'and unusual login attempts',
'containment_measures': 'Mandatory password reset, verification '
'of email addresses and mobile numbers',
'enhanced_monitoring': 'Yes',
'remediation_measures': 'Increased sensitivity of security '
'monitoring tools, alerts for unusual '
'login attempts'},
'threat_actor': 'Marshall Gramm (Former HISA Owner)',
'title': 'HISA Data Breach and Unauthorized Access Incident',
'type': 'Data Breach'}