{"id":4337,"date":"2024-07-05T08:00:00","date_gmt":"2024-07-05T13:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/cloud-security\/euro-2024-becomes-latest-sporting-event-to-attract-cyberattacks"},"modified":"2024-07-05T08:00:00","modified_gmt":"2024-07-05T13:00:00","slug":"euro-2024-becomes-latest-sporting-event-to-attract-cyberattacks","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/07\/05\/euro-2024-becomes-latest-sporting-event-to-attract-cyberattacks\/","title":{"rendered":"Euro 2024 Becomes Latest Sporting Event to Attract Cyberattacks"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltfb8071e9f3199ded\/6685865b732a200c24d7fe88\/kovop-uefa-football-dark-shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/euro-2024-becomes-latest-sporting-event-to-attract-cyberattacks.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/euro-2024-becomes-latest-sporting-event-to-attract-cyberattacks.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">With the Euro 2024 football tournament \u2014 soccer, to our US readers \u2014 reaching the final eight teams in the quarterfinals, cybercriminal activity has ramped up around the tournament and is posing risks for fans and their employers.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In a report published last month, threat intelligence firm Cyberint found that more than 15,000 credentials belonging to Union of European Football Associations (UEFA) customers have already been exposed on underground forums, identified by the uefa.com domain in URLs connected with the usernames and passwords. In addition, another 2,000 credentials have appeared for sale on the Dark Web.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While most credentials belong to consumers, individuals often will sign up for a service with their work email address, giving cyberattackers a potential lead to pursue for future attacks, says Darja Feldman, threat intelligence team lead at Cyberint.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Employees should be instructed not to share, or not to use, their corporate credentials to sign up for non-business services,&#8221; she says, adding that employees should also specifically be warned against reusing passwords. &#8220;The lack of hygiene with passwords, where people just reuse their corporate accounts \u2014 not just the email, but also the passwords \u2014 for third-party services give a vector for the threat actor to get into company accounts.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It&#8217;s a timely reminder given that major sporting events are often the target of cyberthreat actors. Destructive attacks targeted digital infrastructure for the 2018 Winter Olympics, originally appearing to come from the North Korean Lazarus group, but later found to be the work of the Russia-linked Fancy Bear APT, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/olympic-destroyer-s-false-flag-changes-the-game\" rel=\"noopener\">which conducted a false-flag operation<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. Hackers have also <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/nfl-multiple-nfl-teams-twitter-accounts-hacked-and-hijacked\" rel=\"noopener\">targeted the Twitter accounts<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> of teams in the United States&#8217; National Football League (NFL), China-linked threat actors <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/how-the-2022-qatar-world-cup-soccer-was-nearly-hacked\" rel=\"noopener\">aimed to disrupt the 2022 World Cup in Qatar<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, and cybersecurity experts warn that <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/russia-cyber-operations-summer-olympics\" rel=\"noopener\">the coming Summer Olympics in Paris could be next target<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"A Yellow Card for Euro 2024 Cyber Ops\">A Yellow Card for Euro 2024 Cyber Ops<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Cyberattackers have already targeted Euro 2024 beyond stealing credentials, with suspected Russia-linked hackers leveling a distributed denial-of-service (DDoS) attack at the online broadcast of Poland&#8217;s Group D opener against Estonia. Pawel Olszewski, Poland&#8217;s deputy minister of digital affairs, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/ddos-attack-poland-uefa-euro-opening-match\" rel=\"noopener\">blamed the Russian Federation for the attack<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. Russia&#8217;s team has been <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.espn.com\/soccer\/story\/_\/id\/37632117\/euro-2024-uefa-confirms-russia-ban-tournament-belarus-enter-draw-german-plea\" rel=\"noopener\">barred from the tournament<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">DDoS attacks can be among the most pernicious for live sporting events, cybersecurity firm <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.radware.com\/security\/threat-advisories-and-attack-reports\/euro-2024-cybersecurity-threats\/\" rel=\"noopener\">Radware stated in a June 10 advisory<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. The company pointed to the frequent <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/apex-legends-tourney-spoiled-by-hackers\" rel=\"noopener\">DDoS attacks that disrupt e-sports matches<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, for instance, such as tournaments around the popular League of Legends video game.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Euro 2024 \u2014 and other sporting events \u2014 will likely see more DDoS attacks in the future, Radware said.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Given the scale and global interest in the tournament, it is a high-value target for cybercriminals and nation-state actors,&#8221; the company stated. &#8220;This <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/olympics-could-face-disruption-from-regional-powers\" rel=\"noopener\">threat was highlighted during the Tokyo 2020 Olympics<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, where reports of millions of cyberattacks were prevented, underscoring the scale of cyberthreats to large international events.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"A Prelude to Paris Olympics Cyberthreats\">A Prelude to Paris Olympics Cyberthreats<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In the first quarter of 2024, Europe had already seen twice as many attacks compared to the last quarter of 2023, Juhan Lepassaar, head of the European Union Agency for Cybersecurity (ENISA), told the Associated Press. He squarely blamed Russian cyber operations and hackers for the increase.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;This is part of the Russian war of aggression, which they fight physically in Ukraine, but digitally also across Europe,&#8221; he said in late May, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/apnews.com\/article\/europe-election-cybersecurity-russia-ukraine-5b0cca725d17a028dd458df77a60440c\" rel=\"noopener\">according to the Associated Press<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, adding, &#8220;I do believe that we have a societal challenge ahead of us to understand digital security in the same way that we understand security in the everyday traffic environment.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Overall, the level of credential collecting, phishing attacks, DDoS attacks, and other threat activity has not necessarily increased in underground markets, but it has shifted to focus on the Euro 2024 tournament. And, as the 2024 Summer Olympics approaches, Cyberint&#8217;s Feldman expects attackers&#8217; focus to shift again.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We do expect attack attempts by major state-sponsored threat actors on the Olympics,&#8221; she says. &#8220;Everything is almost the same as UEFA, the same [types of attacks] are going to happen with the Olympics \u2014 with credentials, with ticket fraud, with all kinds of scams, all kinds of malicious apps and malicious files that are being sent around to people and to customers.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Russian and Belarusan athletes will be allowed to compete in the 2024 Olympics, but only as neutral participants, without any flags or emblems, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.bbc.com\/sport\/olympics\/67663582\" rel=\"noopener\">the International Olympic Committee has ruled<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. Whether that means fewer attacks from hacktivists and nation-state actors remains to be seen.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cloud-security\/euro-2024-becomes-latest-sporting-event-to-attract-cyberattacks\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>With the Euro 2024 football tournament \u2014 soccer, to our<\/p>\n","protected":false},"author":12,"featured_media":4338,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4337","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/euro-2024-becomes-latest-sporting-event-to-attract-cyberattacks.jpg?fit=1920%2C1080&ssl=1",1920,1080,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/euro-2024-becomes-latest-sporting-event-to-attract-cyberattacks.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/euro-2024-becomes-latest-sporting-event-to-attract-cyberattacks.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/euro-2024-becomes-latest-sporting-event-to-attract-cyberattacks.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/euro-2024-becomes-latest-sporting-event-to-attract-cyberattacks.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/euro-2024-becomes-latest-sporting-event-to-attract-cyberattacks.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/euro-2024-becomes-latest-sporting-event-to-attract-cyberattacks.jpg?fit=1920%2C1080&ssl=1",1920,1080,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/euro-2024-becomes-latest-sporting-event-to-attract-cyberattacks.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/euro-2024-becomes-latest-sporting-event-to-attract-cyberattacks.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/euro-2024-becomes-latest-sporting-event-to-attract-cyberattacks.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/euro-2024-becomes-latest-sporting-event-to-attract-cyberattacks.jpg?fit=1920%2C1080&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4337","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4337"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4337\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4338"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4337"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4337"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4337"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}