Menu
Browse

Cyber Incident Victim: Running Warehouse

Date:

Oct 2021

Location:

United States of America

Summary

A cyberattack targeting Running Warehouse and three affiliated online sports retailers compromised personal and financial data of approximately 1.8 million customers. Threat actors stole names, account passwords, credit and debit card details including CVV codes through an external system breach. The incident was detected weeks after unauthorized access, prompting an investigation that confirmed data exfiltration. The affected companies notified impacted individuals, reported to payment card networks and law enforcement, and engaged digital forensics experts to bolster security measures. Sensitive information exposed in the breach posed significant risks, though identity protection services were not provided to victims.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On October 1, 2021, threat actors breached four affiliated online sports retail websites—Tackle Warehouse, Running Warehouse, Tennis Warehouse, and Skate Warehouse—compromising sensitive payment and personal data belonging to 1,813,224 customers. The attackers exfiltrated full names, financial account numbers, credit card numbers with CVV codes, debit card numbers with CVV codes, and website account passwords during the intrusion. The websites collectively discovered unauthorized access to their systems on October 15, 2021, triggering an immediate investigation with external digital forensics experts. By November 29, 2021, forensic analysis confirmed the scope of data theft and identified affected customers across all four domains. The compromised entities delayed public disclosure until completing their investigation, formally notifying impacted individuals via mailed letters on December 16, 2021.

Cyber Incident Image

The websites reported the incident to payment card networks to flag compromised accounts for fraud monitoring and notified federal law enforcement agencies. Tackle Warehouse’s notification letter confirmed collaboration with digital forensics specialists to implement enhanced security measures across all affiliated platforms, though technical specifics of these improvements were not publicly disclosed. No evidence suggested prolonged unauthorized access beyond the October 1 breach date. Affected customers received no complimentary identity protection services despite the high-risk exposure of CVV codes and financial credentials. The websites characterized the incident as an "external system breach (hacking)" but did not disclose attack vectors, intrusion methods, or whether multiple systems or a centralized database was compromised. Operational disruptions appeared minimal, with all sites maintaining transaction capabilities throughout the investigation period.

Sources
Sources available to members
1 source