CSIDB logo
Incident

The Morton Forum

Incident posture

Attack window
Jun 2025
Location
United Kingdom
Status
Unknown
CIA posture
Available to members
Updated
2026-01-26 16:14

Linked entities

Victim
The Morton Forum
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jun 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A popular football fans' forum experienced a cyber attack targeting its server and software, causing a week-long outage during which users were unable to post. The incident coincided with a site upgrade, and administrators confirmed restoration of full functionality after repairs, with no evidence of compromised personal or sensitive data. The operator publicly acknowledged the disruption and thanked users for their patience while resolving the technical issues.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

The Morton Forum, an independent fan message board unaffiliated with Greenock Morton FC, experienced a cyber attack targeting its server and software infrastructure during late June 2025. The incident caused a complete service outage beginning Tuesday, June 24, rendering the platform inaccessible and preventing user contributions. This disruption coincided with scheduled site upgrades implemented around July 1, though the relationship between maintenance activities and the security breach remains unspecified in available reporting. Administrators publicly confirmed the cyber attack on July 1, 2025, after approximately one week of downtime, characterizing the event as a compromise of critical hosting systems rather than a data-oriented breach. Forum operator Dean McKinnon directed restoration efforts throughout the disruption period, prioritizing system repairs to resume normal operations.

Service restoration concluded by the morning of July 1, with McKinnon announcing full operational recovery to users. Technical remediation involved repairing both server infrastructure and forum software components compromised during the attack. The operator confirmed through public statements that no personal information or sensitive user data was exfiltrated during the incident, limiting confirmed impacts to service availability rather than privacy violations. Primary consequences included seven days of interrupted forum access, suspended user interactions, and administrative resource allocation toward incident response. McKinnon acknowledged user patience during the outage while establishing post-incident communication protocols through direct messages and the platform's contact function to address residual technical issues affecting contributor experience.

Sources

Sources available to members: 1 source.

CSIDB