CSIDB logo
Incident

Running Warehouse

Incident posture

Attack window
Oct 2021
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-27 00:00

Linked entities

Victim
Running Warehouse
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Oct 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack targeting Running Warehouse and three affiliated online sports retailers compromised personal and financial data of approximately 1.8 million customers. Threat actors stole names, account passwords, credit and debit card details including CVV codes through an external system breach. The incident was detected weeks after unauthorized access, prompting an investigation that confirmed data exfiltration. The affected companies notified impacted individuals, reported to payment card networks and law enforcement, and engaged digital forensics experts to bolster security measures. Sensitive information exposed in the breach posed significant risks, though identity protection services were not provided to victims.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On October 1, 2021, threat actors breached four affiliated online sports retail websites—Tackle Warehouse, Running Warehouse, Tennis Warehouse, and Skate Warehouse—compromising sensitive payment and personal data belonging to 1,813,224 customers. The attackers exfiltrated full names, financial account numbers, credit card numbers with CVV codes, debit card numbers with CVV codes, and website account passwords during the intrusion. The websites collectively discovered unauthorized access to their systems on October 15, 2021, triggering an immediate investigation with external digital forensics experts. By November 29, 2021, forensic analysis confirmed the scope of data theft and identified affected customers across all four domains. The compromised entities delayed public disclosure until completing their investigation, formally notifying impacted individuals via mailed letters on December 16, 2021.

The websites reported the incident to payment card networks to flag compromised accounts for fraud monitoring and notified federal law enforcement agencies. Tackle Warehouse’s notification letter confirmed collaboration with digital forensics specialists to implement enhanced security measures across all affiliated platforms, though technical specifics of these improvements were not publicly disclosed. No evidence suggested prolonged unauthorized access beyond the October 1 breach date. Affected customers received no complimentary identity protection services despite the high-risk exposure of CVV codes and financial credentials. The websites characterized the incident as an "external system breach (hacking)" but did not disclose attack vectors, intrusion methods, or whether multiple systems or a centralized database was compromised. Operational disruptions appeared minimal, with all sites maintaining transaction capabilities throughout the investigation period.

Sources

Sources available to members: 1 source.

CSIDB