Menu
Browse

Cyber Incident Victim: USA Cycling

Date:

Mar 2016

Location:

United States of America

Summary

USA Cycling experienced a cybersecurity breach where an unauthorized party accessed databases, potentially compromising members' names, mailing and email addresses, dates of birth, and account passwords. The organization confirmed no financial or medical data was exposed as such information was not stored in its systems. Upon discovering the incident, the organization engaged cybersecurity experts and authorities to secure its infrastructure, subsequently mandating password resets for all current and former members via emailed instructions while advising those who reused credentials elsewhere to update them.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

USA Cycling experienced a cybersecurity breach between late February and early March 2016, with the organization detecting unauthorized database access approximately two weeks after the initial intrusion. The governing body confirmed the incident on March 16, 2016, after discovering that attackers had compromised systems containing member registration data. The breach potentially exposed personal information of current and former members, including full names, physical mailing addresses, email addresses, dates of birth, and account passwords stored in USA Cycling's systems. No financial records, Social Security numbers, medical information, or banking details were compromised because the organization did not maintain such data in its databases. The attackers specifically targeted membership information systems rather than financial transaction platforms, limiting the scope to personally identifiable information and authentication credentials.

Cyber Incident Image

Upon identifying the breach, USA Cycling immediately engaged law enforcement authorities and contracted external cybersecurity experts to investigate the incident and secure affected systems. The organization disabled all member account access on its website as a containment measure, requiring password resets for every account before allowing renewed login capabilities. On March 18, 2016, USA Cycling began notifying all current and former members via email, providing individualized password reset links and instructions to change credentials both on their platform and any other services where members might have reused the same passwords. The organization publicly acknowledged the breach through official statements expressing regret for the incident while emphasizing that no ongoing security risks remained following their remediation efforts. This incident disrupted member access to online services for an unspecified period and necessitated widespread credential updates across the cycling organization's digital infrastructure.

Sources
Sources available to members
1 source