Menu
Browse

Cyber Incident Victim: Arizona Cardinals

Date:

Jan 2020

Location:

United States of America

Summary

A group identified as OurMine briefly hijacked social media accounts of multiple National Football League teams and the league itself, impacting platforms including Twitter, Facebook, and Instagram. The attackers compromised accounts belonging to several teams, collectively followed by tens of millions, posting promotional content during the short-lived takeovers. The incident was part of a broader campaign targeting high-profile individuals and entities to demonstrate security vulnerabilities, with the hackers advocating for improved protective measures like multi-factor authentication.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On January 22, 2020, the hacking group OurMine resumed public activity by compromising the social media accounts of multiple high-profile individuals and organizations, beginning with Facebook co-founder Eduardo Saverin. This marked their first major campaign since 2017. Over the following days, the group expanded their targets to include entertainment industry figures such as Will Smith (CEO of FooVR), Bobby Berk (Queer Eye star), Enrique Hernández (LA Dodgers player), Matt Raub (film director), and the Dave Moss YouTube channel. The attacks culminated on January 27 with coordinated takeovers targeting seven National Football League franchises and the NFL's official accounts. Specific teams confirmed affected included the Dallas Cowboys (Instagram/Facebook), Buffalo Bills (Instagram/Facebook), Houston Texans (Facebook), Minnesota Vikings (Instagram/Facebook), Kansas City Chiefs (Twitter), Green Bay Packers (Twitter/Facebook), and the NFL's primary Twitter and Facebook accounts.

Cyber Incident Image

The attackers briefly gained control of these accounts, using them to post promotional messages during a two-hour window before being removed. OurMine simultaneously announced these compromises through their own Twitter account, which was subsequently suspended by the platform. No data theft or financial motives were disclosed, with the group characterizing the actions as demonstrations of security vulnerabilities. The incident exposed tens of millions of combined followers to unauthorized content but resulted in no reported permanent account damage. Organizations regained control through standard recovery protocols, though specific technical remediation steps weren't publicly detailed beyond industry-standard recommendations about password hygiene and two-factor authentication referenced in contemporaneous reporting. The campaign highlighted persistent risks to organizational social media assets despite available security measures.

Sources
Sources available to members
1 source