DICK'S SPORTING GOODS, INC.
ent_019dd17099b9c58eadca7ff4fb78f0e0
Disclosures
5
State AG · SEC 8-K · 5 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
72,012
as filed · State AG WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- DICK'S SPORTING GOODS, INC.
- Normalized
- dick s sporting goods— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- 0001089063
- Domain
- dickssportinggoods.com
Disclosure history (5)newest first
- Washington State AGas victim2024-09-17
DICK'S Sporting Goods, Inc. reported a cyberattack in Washington affecting 72,012 residents. Unauthorized third-party access occurred between August 21-22, 2024. Customer PII (name, address, email, phone, DOB) was acquired. The company terminated access, investigated, notified law enforcement, and offered 12 months of credit monitoring.
- FEDERALSEC 8-Kas victim2024-08-28
On August 21, 2024, Dick's Sporting Goods discovered unauthorized third-party access to its information systems, including portions containing confidential information. The Company activated its cybersecurity response plan, engaged external cybersecurity experts to investigate, isolate, and contain the threat, and notified federal law enforcement. The Company has no knowledge of business operations disruption and currently believes the incident is not material. Filed under Item 8.01.
- Indiana State AGas victim2022-05-23
Dick's Sporting Goods, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2022-09-18 and was reported on 2022-05-23. 45 Indiana residents were affected. 3,185 individuals affected in total.
- Massachusetts State AGas victim2022-05-20
Dick's Sporting Goods, Inc. (A.D. Starr) reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-05-20. 59 Massachusetts residents were affected. The report records the breach type as electronic.
- Maine State AGas victim2022-05-20
A.D. Starr, a subsidiary of Dick's Sporting Goods, Inc., reported a data breach that originated from a third-party vendor. The incident, described as an external system breach (hacking), occurred on September 18, 2020, and was discovered on March 1, 2022. It affected 3,185 individuals, compromising their names and financial account or credit/debit card numbers along with security codes, access codes, or PINs. Affected individuals were notified in writing on May 23, 2022, and offered 12 months of credit monitoring and identity theft resolution services from Experian.
Subsidiary disclosures (2)filed by group companies
◈ These filings were made by or about subsidiaries of DICK'S SPORTING GOODS, INC. — not by DICK'S SPORTING GOODS, INC. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- New Hampshire State AGvia A.D. Starr2022-05-25
A.D. Starr notified NH DOJ of a security incident impacting ~11 NH residents. Malicious software in third-party vendor Freestyle Solutions' payment processing system compromised credit card data (name, number, CVV, expiration) submitted on adstarr.com between Sept 18, 2020 and Feb 3, 2022. Vendor blocked malware, engaged forensic experts, notified card brands and law enforcement. A.D. Starr offered 1 year of credit monitoring via Experian.
- Montana State AGvia A.D. Starr2022-05-23
A.D. Starr notified Montana residents of a security incident involving malicious software on its vendor's payment processing server. Cardholder data (names, card numbers, CVV, expiration) submitted between Sept 18, 2020, and Feb 3, 2022, may have been compromised. The vendor blocked the malware, engaged forensic experts, and notified law enforcement and card brands. Affected individuals were offered one year of Experian IdentityWorks.