CSIDB logo
Incident

Cleveland Browns

Incident posture

Attack window
Jan 2020
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-01 00:00

Linked entities

Victim
Cleveland Browns
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Jan 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The OurMine hacking group briefly compromised social media accounts of multiple NFL teams and the league, gaining unauthorized access to platforms including Twitter, Facebook, and Instagram. They posted promotional messages to highlight security vulnerabilities, temporarily disrupting the teams' online communications. The incident underscored risks associated with insufficient account protections.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On January 22, 2020, the hacking group OurMine resumed public activity by compromising the Twitter account of Eduardo Saverin, Facebook co-founder and angel investor. This marked their first high-profile account takeover of the year after a period of reduced visibility since 2017. Between January 22-27, the group expanded their targets to include multiple celebrity and organizational accounts. They compromised Twitter profiles belonging to Will Smith (CEO of FooVR), Bobby Berk (Queer Eye star), Enrique Hernández (LA Dodgers player), Matt Raub (film director), and the Dave Moss YouTube channel, collectively affecting over 1.1 million followers. The hackers used these breaches to post promotional content from their @OurMine Twitter account before it was suspended by the platform.

The campaign escalated significantly on January 27 when OurMine simultaneously hijacked social media accounts of six NFL teams and the league itself. Affected organizations included the Dallas Cowboys (Instagram/Facebook), Buffalo Bills (Instagram/Facebook), Houston Texans (Facebook), Minnesota Vikings (Instagram/Facebook), Kansas City Chiefs (Twitter), Green Bay Packers (Twitter/Facebook), and the NFL's official Twitter and Facebook accounts. The attackers maintained control for approximately two hours, during which they posted announcements of the breaches through the compromised accounts. The coordinated attack impacted platforms with tens of millions of combined followers. No data theft or financial motives were indicated in available reports, with the group's communications suggesting the intrusions were conducted to demonstrate security vulnerabilities in high-profile accounts. The NFL and affected teams regained control of their accounts within hours, though specific technical remediation measures weren't disclosed in public reporting.

Sources

Sources available to members: 1 source.

CSIDB