From little information that has been released we are aware that:
They announced that they had been the victim of a cyber attack earlier in November
The issue is still on-going, they have been able to restore all systems and they are receiving assistance from the NCSC (National Cyber Security Centre)
They have not as yet recovered their email systems
They have informed the ICO of an incident
They state that they are not aware of any fan data being compromised
The Daily Mail are reporting that it’s a ransomware attack, although this has not been confirmed.
Most papers are wrongly reporting that they would be liable for a “hefty fine” if any fan or customer data has been compromised. (it’s not just personal data of fans that United hold)
Aside of my own allegiances, this is obviously very interesting to me because it relates to what I do on a day to day basis. In addition, you can read between the lines and make some educated guesses about what is happening.
As the issue is on-going it would certainly suggest that ransomware is a likely type of attack.
The NCSC warned only this summer about the increased threat from cyber criminals, with suggestions that nation states such as Russia were very active (remember the attack on Olympians data)
For MUFC to need to report the breach to the ICO it is very likely that some personal data was compromised and it that the actual information compromised could represent a threat to the data subjects rights and freedoms. United will have had to assess the threat to individuals and make that judgement (although I would imagine they would have taken advice on this, perhaps from the ICO) . As such, and on the basis, that they seem confident enough to predict that no fan data forms part of the breach, this means there must be some other personal data at risk which may also include email content. None of the reports make any reference to staff data?
It’s worth noting at this point that when dealing with clients, in 95% of cases the most sensitive data they hold is on their staff.. please make note.. every company has a responsibility under GDPR to provide the technical and organisational measures to protect all their data, including (especially) staff data, which almost certainly will include information relating to their health, and therefore considered “special category” and therefore requiring a higher level of security.
So making some basic assumptions (which are just that at this stage), it is quite possible United are being held to ransom over some data that could reveal all kinds of extremely sensitive data. Aside of some very lucrative contract details, there may very well be emails between United and other clubs, emails between United and staff, including their Directors, owners. I’m quite certain there is much that any football club communicates via email that they wouldn’t want made public. The subject matters could be around injuries, transfers, investments (or lack of it), .
If (and we don’t know) they are being held to ransom this introduces a potentially difficult decision to be made. All of the official advice around ransoms is that they shouldn’t be paid.. doing so would endorse that ransomware is a highly effective and lucrative tactic, but also fund the hackers to mount further attacks other potential victims. This all assumes the hackers are honourable enough to keep their side of the bargain if paid (I heard this being justified by a very large US company that paid a ransom, that the hackers “had a reputation to consider!!). Equally, as demonstrated above, the information could be hugely embarrassing for the club and particularly its employees, to whom they have a duty of care.
It’s worth noting that not all the data currently compromised would represent personal data, nevertheless every company has data (especially Intellectual Property) they don’t want made public and as such every company should be putting in the appropriate measures to identify risks and protect themselves accordingly.
How they have been compromised is certainly not something I would speculate on at this stage, however it is true that social engineering is a strategy being used by many hackers. Literally last night I was talking to friends who had themselves been compromised by a DPD phishing email. What’s more, with almost every client I meet, all staff including Directors have personal social media accounts openly available for anyone to access, and nearly all reveal information that, when considered, just creates unnecessary risk.
So this is definitely a story worth keeping an eye on, however my suspicion is that United will do whatever they need to keep information out of the public eye, and if they are negotiating, no doubt the hackers will be taking advantage of this fact. I think it would be a very uneven negotiating position! Manchester clubs know all about the problems associated with private information being hacked, City were nearly thrown out of the Champions League after their own experience, and I have a feeling there are some very squeaky bums at United right now!
Leave A Comment