Menu
Browse

Cyber Incident Victim: Classic Football Shirts

Date:

Jul 2021

Location:

United Kingdom

Summary

A cybersecurity breach at Classic Football Shirts exposed customer data through a third-party provider, leading to fraudulent cashback phishing emails sent from spoofed addresses containing an extra 's'. The company confirmed unauthorized access to names, addresses, email addresses, and order histories but stated payment information remained uncompromised as it wasn't stored internally. Some customers reported financial losses, including unauthorized transactions exceeding $700, prompting the firm to advise vigilance and card cancellations for those who engaged with the phishing link. Affected individuals criticized the inadequate data protection measures while acknowledging the company's prompt breach disclosure.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On July 8, 2021, Classic Football Shirts, a Manchester-based retailer specializing in vintage football apparel, experienced a cybersecurity incident involving unauthorized access to customer data through a third-party provider’s systems. The breach led to phishing emails being sent to customers at approximately 20:00 BST on July 8, falsely offering cashback on previous orders. These emails originated from the address [email protected], which contained an extra ‘s’ compared to the legitimate domain (classicfootballshirts.co.uk). The company detected the fraudulent activity at 20:30 BST—30 minutes after the emails were dispatched—and promptly advised customers via social media not to interact with the links. Classic Football Shirts clarified that payment information and passwords remained uncompromised, as card details were never stored on their systems. They instructed affected individuals to contact their banks to cancel cards if they had submitted financial information through the phishing form.

Cyber Incident Image

The incident exposed customer names, email addresses, physical addresses, and order histories, triggering widespread concern among clients. Multiple customers reported the phishing attempt’s deceptive domain structure, while one verified victim, Fernando Paredes, confirmed a fraudulent $700 (£504) transaction after interacting with the link. His bank initiated an investigation following the card cancellation. Customers criticized the company’s data protection measures as “unprofessional” and expressed apprehension about the third-party provider’s security vulnerabilities. Classic Football Shirts publicly apologized for the “inconvenience caused” and emphasized ongoing vigilance but did not disclose the breach’s scale or identify the compromised vendor when queried by the BBC. The company, founded in 2006, maintained its reputation as a global supplier of retro football kits despite the operational disruption and reputational impact stemming from the attack.

Sources
Sources available to members
1 source