CSIDB logo
Incident

Sky

Incident posture

Attack window
Jan 2023
Location
Germany
Status
Historical
CIA posture
Available to members
Updated
2025-10-15 00:00

Linked entities

Victim
Sky
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jan 2023
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Sky experienced a cyberattack resulting in unauthorized access to a limited number of customer accounts, prompting immediate security measures to halt the breach. The company confirmed attackers could not access full payment details due to standard data masking but may have temporarily obtained limited personal information, with no evidence of misuse beyond unauthorized subscription additions for some affected individuals. Investigations remain ongoing, and impacted customers were notified while data protection authorities were informed. The organization assured no financial harm would occur to affected parties and expressed regret for potential inconveniences caused by the incident.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In early January 2023, Sky confirmed a cybersecurity incident affecting its customer accounts after multiple subscribers received breach notifications. A company spokesperson stated that cybercriminals had gained unauthorized access to a limited number of Sky customer accounts, though the exact entry method remained under investigation. Sky implemented immediate IT security measures to terminate the unauthorized access upon detection. The company launched an internal investigation and notified relevant data protection authorities in accordance with regulatory requirements. Affected customers received direct communications confirming the breach timeline, with Sky emphasizing that accounts not contacted through verified channels by January 27, 2023, remained unaffected. Preliminary findings indicated attackers potentially accessed personal data during the limited breach window, though full payment information remained protected through standard data masking protocols that obscured all but the last five digits of IBAN and credit card numbers.

Sky's investigation remained ongoing as of the initial disclosure, with no evidence of substantive data misuse beyond unauthorized subscription upgrades observed in some compromised accounts. The company declined to specify the number of impacted subscribers but publicly acknowledged potential inconveniences to affected customers while committing to prevent financial losses stemming from the incident. Forensic analysis suggested attackers obtained temporary access to personally identifiable information, though the complete scope of exposed data fields remained undetermined during the initial response phase. Sky maintained that security protocols prevented full payment data exposure and established procedures to reverse fraudulent subscription charges. The broadcaster's communications emphasized containment of the breach through prompt access termination and ongoing coordination with regulatory bodies throughout the investigation process.

Sources

Sources available to members: 1 source.

CSIDB