National Basketball Association (NBA)

National Basketball Association (NBA)

The National Basketball Association (NBA) announced a data breach following a compromise at a third-party company offering a newsletter service.

With the assistance of outside cybersecurity specialists, NBA initiated an investigation into the security breach to ascertain the severity of the situation.

Although the NBA insisted that its systems were unaffected, the data breach notification provided to fans indicated that the event may have affected an undetermined number of people.

The organization claims that an unauthorized third party gained access to and copied the names and email addresses of some of its supporters. Usernames, passwords, and other information were not compromised by the data leak.

Source: https://securityaffairs.com/143693/data-breach/nba-data-breach.html

TPRM report: https://scoringcyber.rankiteo.com/company/national-basketball-association

"id": "nat41621023",
"linkid": "national-basketball-association",
"type": "Data Leak",
"date": "03/2023",
"severity": "25",
"impact": "2",
"explanation": "Attack limited on finance or reputation"
{'affected_entities': [{'customers_affected': 'Undetermined number of people',
                        'industry': 'Sports',
                        'name': 'National Basketball Association (NBA)',
                        'type': 'Organization'}],
 'attack_vector': 'Third-Party Service Compromise',
 'customer_advisories': 'Data Breach Notification',
 'data_breach': {'data_exfiltration': 'Yes',
                 'personally_identifiable_information': 'Yes',
                 'type_of_data_compromised': ['Names', 'Email Addresses']},
 'description': 'The National Basketball Association (NBA) announced a data '
                'breach following a compromise at a third-party company '
                'offering a newsletter service. With the assistance of outside '
                'cybersecurity specialists, NBA initiated an investigation '
                'into the security breach to ascertain the severity of the '
                'situation. Although the NBA insisted that its systems were '
                'unaffected, the data breach notification provided to fans '
                'indicated that the event may have affected an undetermined '
                'number of people. The organization claims that an '
                'unauthorized third party gained access to and copied the '
                'names and email addresses of some of its supporters. '
                'Usernames, passwords, and other information were not '
                'compromised by the data leak.',
 'impact': {'data_compromised': ['Names', 'Email Addresses'],
            'systems_affected': 'Third-Party Newsletter Service'},
 'initial_access_broker': {'entry_point': 'Third-Party Newsletter Service'},
 'investigation_status': 'Investigation Initiated',
 'response': {'communication_strategy': 'Data Breach Notification to Fans',
              'third_party_assistance': 'Outside Cybersecurity Specialists'},
 'threat_actor': 'Unauthorized Third Party',
 'title': 'NBA Data Breach via Third-Party Newsletter Service',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.