Menu
Browse

Cyber Incident Victim: Denver Broncos

Date:

Jan 2020

Location:

United States of America

Summary

A hacking group compromised social media accounts of multiple National Football League teams and the league itself, briefly taking control of platforms including Twitter, Facebook, and Instagram. The attackers used the access to post promotional messages, demonstrating vulnerabilities in account security. The incident affected several high-profile teams with large followings, though control was restored within hours. The group's actions aimed to draw attention to inadequate protective measures such as weak passwords and lack of multi-factor authentication.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On January 22, 2020, the hacking group OurMine initiated a series of social media account takeovers, beginning with Eduardo Saverin, Facebook co-founder and angel investor. This marked their resurgence after a hiatus from public attention since 2017. Over subsequent days, they compromised accounts belonging to Will Smith (CEO of FooVR), Bobby Berk (Queer Eye star), Enrique Hernández (L.A. Dodgers player), Matt Raub (film director), and the Dave Moss YouTube channel, collectively impacting over one million followers. The attacks escalated on January 27 when OurMine simultaneously hijacked the official social media accounts of six National Football League teams and the NFL itself. Affected platforms included Twitter, Facebook, and Instagram, with varying combinations per victim: the Dallas Cowboys lost Instagram and Facebook access; Buffalo Bills and Minnesota Vikings had both Instagram and Facebook compromised; Houston Texans' Facebook was breached; Kansas City Chiefs and Green Bay Packers had Twitter accounts hijacked along with the Packers' Facebook; while the NFL's Twitter and Facebook accounts were also compromised.

Cyber Incident Image

The attackers maintained control for approximately two hours, during which they used the platforms to promote their group and demonstrate security vulnerabilities. OurMine announced these breaches via their Twitter account before it was suspended. No data theft or financial motives were indicated, with the group emphasizing their intent to expose inadequate security practices. The incident impacted accounts with tens of millions of combined followers, disrupting normal operations but causing no lasting technical damage. Affected organizations regained control swiftly, though the breach highlighted risks associated with high-profile accounts lacking robust authentication measures. The coordinated timing across multiple teams and the league suggested deliberate targeting of the NFL's digital infrastructure during a period of heightened visibility.

Sources
Sources available to members
1 source