ArbiterSports detected unauthorized access to its network and an attempted encryption of systems. An investigation revealed that a backup database copy containing user account credentials (username/password), names, addresses, dates of birth, email addresses, and Social Security numbers was exfiltrated. Though encryption was prevented, the unauthorized party demanded payment to delete the files. ArbiterSports reached an agreement and received confirmation of deletion. Breach window: June 3 – July 14, 2020.