Cyber Incident Victim: Datasport
Date:
Jan 2024
Location:
Switzerland
Summary
A cyberattack on Swiss sports services provider Datasport compromised data of up to one million amateur athletes, including names, phone numbers, and email addresses. The stolen information—primarily consisting of publicly shared user data from event registrations and performance tracking platforms—was subsequently offered for sale in a hacker forum, with over 900,000 records linked to Swiss residents and additional entries from neighboring countries. While security-sensitive details like passwords and payment information remained unaffected, the breach initially appeared limited before investigations revealed its full scale.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On January 22, 2024, Swiss sports services company Datasport suffered a cyberattack resulting in the theft of personal data belonging to up to one million amateur athletes. The compromised dataset included names, telephone numbers, and email addresses, though the company confirmed no security-sensitive information such as passwords or financial payment details were accessed. Datasport CEO Thomas Bachofner stated most affected information was voluntarily published by users on the Datasport.com platform and therefore already publicly accessible. Initial assessments indicated only limited records were compromised, but subsequent investigation revealed the breach's full scale. By late January, a data package containing approximately 1.3 million records appeared for sale on a hacker forum, with over 900,000 entries linked to Swiss residents and the remainder attributed to individuals from neighboring countries.

The intrusion occurred on January 22, though Datasport did not immediately recognize the attack's magnitude. Criminal actors gained unauthorized access to athlete profiles created through Datasport's platform, which manages registration processes, timing systems, and bib number distribution for mass participation sports events. While the company emphasized the non-sensitive nature of most stolen data, the exposure of contact details creates potential risks for targeted phishing or spam campaigns against affected individuals. No evidence suggests operational systems supporting race timing or results services were compromised. Datasport's public response focused on clarifying the breach scope and reiterating that user-published information constituted the majority of exfiltrated data, with no indication of deeper system infiltration beyond athlete profile records.
