UPDATED 20:54 EST / NOVEMBER 22 2020

SECURITY

Manchester United forced to take systems offline following cyberattack

U.K. soccer club Manchester United has been forced to take some systems offline following a cyberattack.

The attack occurred Friday evening U.K. time Nov. 20. The club described the attack only as “a sophisticated operation by organized cybercriminals.”

Manchester United said in a statement Nov. 20 that it had extensive protocols and procedures in place for such an event and had rehearsed for this risk. It added that “our cyber defenses identified the attack and shut down affected systems to contain the damage and protect data.”

Media channels including the club’s website, mobile app and streaming service were unaffected by the attack and no personal data is believed to have been stolen.

Manchester United didn’t release details on what the attack involved, but The Sun today quoted an expert as saying the attack bears “hallmarks of Russian or Chinese hackers.” The fact that the attack came before a game is also claimed by the expert to suggest that “the intention was to cause chaos for the club.”

Without any details on the attack, suggesting it was Russian or Chinese hackers is pure speculation. It could have been North Korean or Iranians hackers as well. The four countries dominate the list of advanced persistent threat groups.

But the attack does sound like ransomware given that the response of the club was to shut down affected systems immediately. That’s a standard response to stopping ransomware from spreading across a network. A ransomware attack is also the sort of attack that an organization, enterprise or in this case a club would rehearse for.

“The club responded very quickly to shut down the attack and to communicate with its key stakeholders and the [U.K.] Information Commissioners Office,” Jon Niccolls, an incident response lead at cybersecurity solutions provider Check Point Software Technologies Ltd., told SiliconANGLE. “It’s an excellent example of how to implement a detailed incident response plan.”

Niccolls also agrees that the attack was likely ransomware, noting that it may have been a “double extortion” attack where the attackers both steal data and encrypt it to disrupt operations.

“These are a fast-growing trend in 2020 and organizations such as football clubs are a prime target as their systems hold the details of hundreds of thousands of people including fans, employees, players as well as sensitive business and payment data,” Niccolls explained. “We would urge all organizations to follow the club’s example and build a strong defense that combines technology and processes: solutions that can prevent these attacks and prevent data leaks and training for employees about the risks of phishing emails, as this is how many ransomware attacks are launched.”

Image: Tinthethao

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.