Cyber Incident Victim: Tampa Bay Buccaneers
Date:
Jan 2020
Location:
United States of America
Summary
A hacking group compromised social media accounts of multiple NFL teams and the league itself, briefly seizing control of Twitter, Facebook, and Instagram profiles. The attackers promoted their group while demonstrating security vulnerabilities, impacting accounts with tens of millions of combined followers. Account access was restored within hours, with the incident highlighting risks to high-profile organizations' digital assets.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On January 22, 2020, the hacker group OurMine resumed public activity by compromising the social media accounts of high-profile individuals and organizations, beginning with Facebook co-founder Eduardo Saverin. This marked their first major incident since 2017. Over the following days, the group expanded their targets to include celebrities and influencers such as Will Smith (CEO of FooVR), Bobby Berk (Queer Eye star), Enrique Hernández (LA Dodgers player), Matt Raub (film director), and the Dave Moss YouTube channel, collectively affecting accounts with over one million combined followers. The attacks escalated on January 27 when OurMine simultaneously hijacked multiple National Football League team accounts, including the Dallas Cowboys (Instagram/Facebook), Buffalo Bills (Instagram/Facebook), Houston Texans (Facebook), Minnesota Vikings (Instagram/Facebook), Kansas City Chiefs (Twitter), Green Bay Packers (Twitter/Facebook), and the official NFL accounts (Twitter/Facebook). The compromised accounts collectively served tens of millions of followers.

OurMine maintained control over these accounts for approximately two hours during the January 27 incident, using the platform to announce their exploits via their own Twitter timeline before the account was suspended. No data theft or destructive actions were reported beyond the unauthorized access and promotional posts. The hackers characterized the breaches as demonstrations of inadequate security practices among high-profile entities. Affected organizations regained control through standard account recovery procedures, though specific technical remediation steps weren't disclosed publicly. The incident highlighted vulnerabilities in social media account security across major sports franchises and celebrities, though no financial losses or long-term operational impacts were documented in available reports.
