Menu
Browse

Cyber Incident Victim: Real Sociedad

Date:

Oct 2023

Location:

Spain

Summary

A football club based in San Sebastián experienced a cybersecurity incident compromising servers containing personal data of subscribers, shareholders, and supporters. The breach exposed names, identity card numbers, email and postal addresses, telephone numbers, and—for subscription holders—bank account details used for direct debit payments. While financial losses were deemed unlikely due to limited exposed banking information, the organization implemented technical and organizational measures to resolve the incident and maintain system functionality. Authorities including the Data Protection Agency were notified, with stakeholders advised to exercise caution regarding suspicious electronic communications.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On October 17, 2023, Real Sociedad, a football club based in San Sebastián, Spain, detected a cyberattack targeting its IT services. The breach compromised multiple servers storing identification and contact data for subscribers, shareholders, RS Fan members, and RS Laguna supporters. Attackers accessed personal information including full names, national identity card numbers, email addresses, physical mailing addresses, and telephone numbers. For subscribers, the intrusion additionally exposed bank account numbers used for processing membership fee direct debits. The club confirmed the incident involved unauthorized access to internal systems but did not specify the exact attack vector or perpetrator group. No operational disruptions to matches or stadium functions were reported, though the breach directly impacted data security for an unspecified number of individuals associated with the club.

Cyber Incident Image

Real Sociedad implemented technical and organizational measures to contain the incident, ensuring continued functionality of critical systems. The club notified Spain’s Data Protection Agency and other relevant authorities while initiating an internal response protocol. Affected parties received email communications advising vigilance against suspicious electronic messages and fraudulent attempts to exploit the leaked data. The club emphasized that compromised banking details were limited to account numbers for automated membership payments, asserting this exposure would not enable unauthorized withdrawals or direct financial losses. Forensic investigations proceeded with law enforcement involvement, though no recovery timeline or data decryption status was disclosed. No ransomware demands or explicit threats of data publication were mentioned in available reports as of the incident disclosure date.

Sources
Sources available to members
2 sources