Retail chain Dick’s Sporting Goods has disclosed a cyberattack that potentially resulted in unauthorized access to confidential information.
In a regulatory filing with the Securities and Exchange Commission (SEC), Dick’s Sporting Goods said it discovered unauthorized third-party access to its information systems on August 21. The breach exposed portions of the company’s IT systems containing confidential information.
The company said it immediately activated its cyber response plan and engaged with security experts to investigate, isolate, and contain the attack. “The company has no knowledge that this incident has disrupted business operations,” it said.
While an investigation is ongoing, the retail chain said it did not believe that the attack was material. Federal law enforcement has been notified.
What Dick’s Sporting Goods did not say was how the attackers gained access to its network, whether personal information was stored on the compromised systems, and whether any threat actor attempted to extort it following the attack.
SecurityWeek has not seen any known ransomware groups claiming responsibility for the attack.
Given the company’s description of the incident, it is likely either that the attackers were not part of a ransomware group or that its security team discovered the intrusion before file-encrypting malware could be deployed.
SecurityWeek has emailed Dick’s Sporting Goods for additional information on the attack and will update this article as soon as a reply arrives.
Founded in 1948, the retailer operates over 850 Dick’s Sporting Goods, Golf Galaxy, Public Lands, Moosejaw, Going Going Gone! and Warehouse Sale stores, an online store, a mobile app, Dick’s House of Sport and Golf Galaxy Performance Center, and mobile live streaming platform GameChanger.
Related: Cloud Misconfigurations Expose 110,000 Domains to Extortion
Related: Oil Giant Halliburton Confirms Cyber Incident, Details Scarce
Related: Staples Confirms ‘Cybersecurity Risk’ Disrupting Online Stores
Related: Extortionist Hacker Group SnapMC Breaches Networks in Under 30 Mins