The Need for Digital Defense: Cyber Threats to Sports Organizations

By Justin W. Bogle*                                              Posted: 04/12/2021

As demonstrated in the last year, technology has become enmeshed with people’s daily lives to a previously unthinkable degree.[1]  Unfortunately, this tight bond has enabled an explosion of cyber-attacks at every level of society.[2]  As a recent report by the British government’s National Cyber Security Centre (NCSC) makes abundantly clear, the world of sports has not escaped this dangerous trend.[3]  While the phrase “cyber-attacks” appears monolithic, there are many different, but related, types of cyber threats an organization can face.[4]  Bad actors have utilized these techniques to attack sports groups around the world, often in search of financial or personal information.[5]  Thankfully, sports organizations can mitigate these risks, so long as they follow relatively simple step to protect themselves.[6]

“Cyber-Attacks” Broken Down

While there are a number of ways to mount cyber-attacks, the NCSC recently identified three main types that have been used against sports organizations: Business Email Compromise (BEC), cyber-enabled fraud, and ransomware.[7]  BEC, which according the NCSC is the largest threat, is the practice of attempting to obtain fraudulent access to email and other accounts.[8]  Bad actors attempt to gain access to senior level employees’ email accounts through techniques such as “spear phishing” or sending emails, text messages, and other messages to trick employees into giving up confidential information.[9]  These attacks facilitate fraudulent access, often so bad actors can access financial data.[10]  Recently, this practice has grown easier, as more organizations move to software-as-a-service (SaaS) options, such as Office 365, that allows access to multiple platforms with one sign-on.[11]  The second major type of cyber-attack is cyber fraud, where attackers attempt to trick users into utilizing fake websites or responding to fraudulent emails to gain access to confidential systems.[12]  Finally, the third primary method of attack identified by the NCSC comes from ransomware.[13]  Unlike the earlier two types of cyber-attacks, where bad actors are seeking to gain access to systems unnoticed, ransomware attacks lock out rightful users from their systems until the bad actors are paid, hence the name.[14]  The unfortunate reality is that about 70% of British sports organizations have experienced at least one of these kinds of cyber-attacks.[15]

A Bruising Series of Hits

Unfortunately for the sporting world, there have been a series of cyber-attacks at different levels over the past few years.[16]  In early 2016, the Milwaukee Bucks announced that they had been the subject of a cyber-attack.[17]  A team staffer received what he thought was an email from the team president and sent along sensitive employee financial information, including names, addresses, and social security numbers.[18]  Furthermore, in the summer of the same year, a Russian-backed hacker group known as “Fancy Bear” attacked the World Anti-Doping Agency (WADA).[19]  The group managed to gain access to WADA’s systems through a spear phishing attack and leaked athletes’ personal information onto the internet.[20]   In 2020, the popular British football team Manchester United was the victim of a cyber-attack.[21]  While the team has not provided clear details on exactly what happened, they were reportedly locked out of their internal systems, potentially due to a ransomware attack.[22] This is not a one-time issue, or something that can be ignored, but rather an ongoing threat that the sports world needs to adjust to.[23]

How to Play Defense

While this threat is real and serious, organizations are not without tools to better protect themselves.[24]  A simple, but key, measure would be to institute multi-factor authentication (MFA) for login credentials.[25]  MFA is the practice of requiring a user to enter secondary information after their password, such as a randomly generated code, before they can access their account.[26]  Such extra steps may be burdensome on the average user but can protect otherwise vulnerable systems from common attacks.[27]  To protect against cyber-enabled fraud, the NCSC recommends both training employees to spot and avoid suspicious emails and utilizing more technical methods to make it more difficult for suspicious emails to be sent or received.[28]  To defend against ransomware, organizations will need to utilize more technical resources.[29]  Updated security software, regular system backups, and segregated systems are necessary to make sure that any potential damage is as limited as possible.[30]  Ultimately, this threat is unlikely to subside, so the best strategy for athletic organizations to overcome potential threats in this digital age is a strong defense.

