WRU launch investigation as members' details leaked in suspected security breach

-Credit: (Image: Huw Evans Picture Agency Ltd)
-Credit: (Image: Huw Evans Picture Agency Ltd)


The Welsh Rugby Union have launched an investigation into a suspected cyber security breach concerning some official supporters’ club members’ data held by a third party.

It has been reported that 70,000 of its members have had their data leaked because the WRU allegedly left a publicly accessible Amazon Web Services (AWS) Simple Storage Service (S3) bucket. This exposed 1,419 text files with details on 69,317 of WRU’s members.

According to reports some of the data leaked included full names, dates of birth, home addresses, phone numbers, email addresses, date of membership purchase, method of paying for membership and the type of membership purchased. A leak as big as this gives malicious actors the chance to exploit the data to perform social engineering attacks.

SIGN UP: Get the new exclusive Inside Welsh rugby newsletter for full insight into what's really going on around all the big issues. This special offer will get you full access for the entire year for just £10 instead of £40.

Exposed email addresses and phone numbers provide fertile ground for spear phishing or other targeted social engineering campaigns.

A WRU statement said: "The Welsh Rugby Union can confirm an investigation is under way into a suspected cyber security breach concerning some official supporters’ club members’ data held by an engaged third party.

"The WRU takes the privacy and security of its supporters’ club members’ personal data extremely seriously and is carrying out a robust and full investigation into these reports, including complying with relevant reporting requirements to the ICO (Information Commissioner’s Office). We believe they relate to one of our service provider’s systems and we are working closely with the provider, which is also implementing its own in-depth inquiry.

"All of this data has since been removed from the online source and it has already been established that no password or payment information has been compromised. No other vulnerabilities or suspicious activities have been found in WRU systems after a thorough review of all systems and processes.

"We can also reassure all supporters' club members and other customers that we remain extra vigilant in this space and continue to engage with our respected cyber security partners on best practice across the business. Further updates will be issued as soon as available."