NBA fans are being warned their data might have been hacked

Stephen Curry #30 of the Golden State Warriors reacts after the Phoenix Suns missed a basket
(Image credit: Getty Images / Ezra Shaw)

Basketball fans interested in getting regular email updates from the NBA may have had some of their personal data stolen, the body has confirmed.

The NBA has sent out a “Notice of cybersecurity incident” to an “unknown number” of fans, BleepingComputer reported. 

In the notice, the organization said that some fans who were signed up for email marketing services such as newsletters may have had their names and emails taken by an unknown threat actor. This data was kept by a third party newsletter service tasked with sending out email notifications and news.

Passwords are safe

"We recently became aware that an unauthorized third party gained access to, and obtained a copy of, your name and email address, which was held by a third-party service provider that helps us communicate via email with fans who have shared this information with the NBA," the NBA said. 

Other data remains secure, the organization added: "There is no indication that our systems, your username, password, or any other information you have shared with us have been impacted."

This information suggests it was clearly a supply-chain attack, however, the NBA did not say who the targeted third party is, nor how it was breached. 

It did warn its users that whoever obtained this data can now use it in phishing and identity theft attacks: 

"Given the nature of the information, there may be heightened risk of you receiving 'phishing' emails from email accounts appearing to be affiliated with the NBA, or of being targeted by other so-called 'social engineering' attacks (where an individual seeks to trick the target into sharing confidential information or otherwise taking actions contrary to his or her own interest," the NBA said.

The organization concluded the update by saying that the NBA will never ask its fans for any type of account information. 

To be on the safe side, it added, fans are urged to be on the safe side whenever getting an email that seems to be from the NBA. They can do that by making sure the email was sent from an @NBA address, and that any links shared in the email point to a trusted website. Finally, fans are advised to never open email attachments they weren’t expecting to receive. 

Via: BleepingComputer

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A person holding a credit card in one hand while typing on a laptop keyboard with the other.
Green Bay Packers online store used to steal fan credit card details
A computer being guarded by cybersecurity.
Wacom warns users their data may have been stolen in breach
Avast cybersecurity
Zapier tells customers their data may have been accessed
A man looking at a tablet with a brown Best Buy package on the desk in front of him
Huge Christmas data breach - 14 million shipping records leaked, putting shoppers at risk
How to prevent cyberattacks
NTT admits hackers accessed details of almost 18,000 corporate customers in cyberattack
Data leak
Top collectibles site leaks personal data of nearly a million users
Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
Monster Hunter Wilds
Monster Hunter Wilds Title Update 1 launches in early April, adding new monsters and some of the best-looking armor sets I need to add to my collection
Zotac Gaming RTX 5090 Graphics Card
Nvidia Blackwell stock woes are compounded by price hikes as more RTX 5090 GPUs soar in pricing, and I’m sick and tired of it all at this point
A collage of Elizabeth Olsen's Scarlet Witch and Tatiana Maslany's She-Hulk
Marvel fans are already tired of Doomsday and Secret Wars cast gossip as two more superheroes get linked with roles in the next two Avengers movies
Four operators survey Verdansk. One holds a sniper rifle, one binoculars, another holds is landing with their parachute, while the last wears a skull mask
New Call of Duty: Warzone trailer shows a beautiful rebuilt Verdansk, but some fans want more: 'it won't be the same unfortunately'
An Apple Music pink/pixellated poster advertising DJ with Apple Music
DJ with Apple Music lands, allowing subscribers to build and mix DJ sets directly from its +100 million-song catalog