MultipleTechnologyInformationRansomwareExtortion DemandCapture Stored DataRansom DemandedRansom PaidData ExfiltratedCustomer Data InvolvedData PublishedPIIIDENTITY_BASICIDENTITY_GOVERNMENTCREDENTIALSAUTHENTICATIONMediumResolved
ArbiterSports
bd_4b6ad401f65020f2 · schema v1 · pii pii-v1
Full breach record for ArbiterSports →ArbiterSports detected unauthorized access to its network and an attempted encryption of systems. An investigation revealed that a backup database copy containing user account credentials (username/password), names, addresses, dates of birth, email addresses, and Social Security numbers was exfiltrated. Though encryption was prevented, the unauthorized party demanded payment to delete the files. ArbiterSports reached an agreement and received confirmation of deletion. Breach window: June 3 – July 14, 2020.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-193406
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 24, 2020
- Raw hash
- a07d1360fd978ba6466b435e04daab55f34d2cc2743cda7371f48958e5850621
Reporting entity
- Name
- ArbiterSportsnorm: arbitersports
- Domain
- arbitersports.squarespace.com
Victim entity
- Name
- ArbiterSportsnorm: arbitersports
- Domain
- arbitersports.squarespace.com
- Industry
- Technologyllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Aug 24, 2020
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENTCREDENTIALSAUTHENTICATION
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid AccountsT1041 Exfiltration Over C2 ChannelT1074 Data Staged
- Threat actor
- ExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.