Arbiter Sports, LLC
ent_dc6ea544fd09a7906516ef04
Disclosures
9
State AG · 9 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
539,309
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Arbiter Sports, LLC
- Normalized
- arbiter sports— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- arbiter.io
Disclosure history (9)newest first
- South Carolina State AGas victim2020-08-28
Arbiter Sports, LLC notified South Carolina residents of a ransomware incident where unauthorized access led to the exfiltration of a database containing usernames, passwords, names, addresses, DOBs, and SSNs. The attacker demanded payment; Arbiter Sports paid and confirmed file deletion. Affected individuals were offered one year of Experian IdentityWorks. Notification sent August 21, 2020.
- New Hampshire State AGas victim2020-08-25
Arbiter Sports, LLC notified the NH Attorney General of a ransomware incident affecting 1,740 NH residents. Unauthorized access was detected in July 2020, leading to an attempt to encrypt systems and exfiltration of a database containing PII and credentials. The attacker demanded ransom, which was paid, and files were deleted. Notifications were sent on August 24, 2020.
- Delaware State AGas victim2020-08-24
Arbiter Sports, LLC reported a ransomware incident affecting 1,790 Delaware residents. Unauthorized access resulted in the exfiltration of a backup database containing usernames, passwords, names, addresses, DOBs, and SSNs. Although encryption was prevented, the attacker demanded payment. Arbiter Sports engaged forensic investigators, notified law enforcement, and provided one year of credit monitoring to affected individuals.
- Hawaii State AGas victim2020-08-24
Arbiter Sports, LLC reported a data breach to the Hawaii Office of Consumer Protection. The office was notified on 2020/08.24. Breach type: Hackers/Unauthorized Access. 1,223 Hawaii residents were affected. Recovered from the Internet Archive after the notice was removed from the OCP table.
- Montana State AGas victim2020-08-24
Arbiter Sports, LLC notified Montana residents of a ransomware incident where unauthorized access to a backup database containing usernames, passwords, names, addresses, DOBs, and SSNs occurred. The attacker demanded ransom, which was paid, and files were deleted. Notices were sent on August 24, 2020.
- Oregon State AGas victim2020-08-24
ArbiterSports, LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2020-08-24. The breach occurred during 6/30/2020 - 7/14/2020. The breach was discovered on 7/15/2020. 539,309 individuals were affected. Notice was sent on 8/24/2020.
- Massachusetts State AGas victim2020-08-24
ArbiterSports, LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-08-24. 11,889 Massachusetts residents were affected. The report records the breach type as electronic.
- Washington State AGas victim2020-08-24
Arbiter Sports, LLC reported unauthorized access to its network in July 2020, where an external actor obtained a backup database containing PII and credentials of 16,465 Washington residents. The actor attempted ransomware encryption but Arbiter prevented it; however, the actor demanded payment for the stolen data. Arbiter paid the ransom, confirmed file deletion, and notified law enforcement. Notifications were sent on August 24, 2020.
- Illinois State AGas victim2020-01-01
ARBITER SPORTS LLC filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-308). The register records the breach as discovered on July 15, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.