{"id":5457,"date":"2024-09-24T18:08:53","date_gmt":"2024-09-24T23:08:53","guid":{"rendered":"https:\/\/www.darkreading.com\/cybersecurity-operations\/6-cybersecurity-headaches-sports-organizations-have-to-worry-about"},"modified":"2024-09-24T18:08:53","modified_gmt":"2024-09-24T23:08:53","slug":"6-cybersecurity-headaches-sports-organizations-have-to-worry-about","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/09\/24\/6-cybersecurity-headaches-sports-organizations-have-to-worry-about\/","title":{"rendered":"6 Cybersecurity Headaches Sports Organizations Have to Worry About"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt4e7edd47f5e19c0e\/66f34620f9b67562259c03df\/stadium-Robert_Landau-alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/6-cybersecurity-headaches-sports-organizations-have-to-worry-about.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/6-cybersecurity-headaches-sports-organizations-have-to-worry-about.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Professional sporting events have long been prime targets for violent attacks and terrorism, given their vast audiences. In recent years, these events have become <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.microsoft.com\/en-us\/security\/security-insider\/intelligence-reports\/cyber-signals-issue-5-cyberthreats-increasingly-target-the-worlds-biggest-event-stages\/\" rel=\"noopener\">targets of cyber-attacks<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> as adversaries exploit venue operations to disrupt events, abuse payment systems for fraud, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/inside-baseball-red-sox-cloud-security-game\" rel=\"noopener\">breach networks to steal data<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, and take advantage of how athletes interact with fans.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While game time is pivotal, there are many other vulnerabilities to which sports franchise operators and event organizers must apply resources, including a growing and increasingly fragmented ecosystem of stakeholders like broadcast and streaming partners, ticket distributors, and legalized gambling platforms.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We&#8217;ve done pretty well so far,&#8221; said Betsy Cooper, director of the Aspen Institute tech policy hub, during a panel at the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.aspencybersummit.org\/2024-agenda\" rel=\"noopener\">2024 Aspen Cyber Summit<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in Washington, DC. Despite the expanded threat, operators of major franchises, leagues, and international events (such as the Olympic games in Paris) believe their proactiveness has prevented devastating events that other industries have faced.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Athletes Need More Training\">Athletes Need More Training<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Athletes are increasingly relying on social media and technology platforms to engage with fans and develop their brand. &#8220;I represent a lot of athletes, and a lot of them depend heavily on social media to build their brand and build their audience,&#8221; Jaia Thomas \u2014 founder of Diverse Representation, a group of African American agents, attorneys, managers, PR reps, and financial advisors for athletes and entertainers \u2014 said during the panel discussion. &#8220;A lot of mistakes happen along the way, and they&#8217;re not always the most tech-savvy people.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">These athletes are also quite young and may be unaware that using these platforms exposes them to potential ransomware attacks or increased risks of being doxxed. &#8220;You&#8217;re talking about kids, for the most part, that make up these teams, and the education piece needs to be strengthened,&#8221; Eric Tysarczyk, senior vice president of the National Hockey League, said on the panel.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Event Attendees Are Vulnerable\">Event Attendees Are Vulnerable<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Now that most events only accept e-tickets, almost all attendees have phones with them. The NHL says fans need to take precautions with their mobile devices.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Imagine if everyone that was in that arena is walking around with all their personal data taped to their back on a piece of paper, and how attractive that arena would be to a malicious actor to get in and just start cultivating all that data,&#8221; Tysarczyk said.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Partnerships Are Critical for Major Events\">Partnerships Are Critical for Major Events<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Reynold Hoover, the CEO of Los Angeles 2028 Olympic &amp; Paralympic Games, told panel attendees that one of the reasons there were no disruptive cyberattacks during the Summer Olympics in Paris was due to information sharing across law enforcement and partners. The most notable activity leading up to the games was <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/russia-cyber-operations-summer-olympics\" rel=\"noopener\">influence campaigns<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> waged by Russian threat actors. &#8220;The Russians were very active in Paris, trying to disrupt,&#8221; said Hoover, a former Army and National Guard lieutenant general with a background in military intelligence.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The Los Angeles Olympic Games in 2028 is expected to draw as many as 15 million visitors, 15,000 athletes, and 25,000 broadcasters across 800 different sporting events. Hoover said the committee is preparing for threat actors ranging from &#8220;goobers in their basements trying to do something stupid, all the way to nation-state actors.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The Los Angeles 2028 committee has partnered with the Department of Homeland Security, the Cybersecurity and Infrastructure Security Agency, and the Federal Communications Commission, among other US agencies.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We cannot do it alone,&#8221; Hoover said. &#8220;It requires a public-private partnership and open and honest information sharing.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"New Revenue Models Create New Challenges\">New Revenue Models Create New Challenges<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As all the major leagues expand their broadcast distribution rights to streaming providers, they can reach new audiences and gain new revenues. However, an attack that even briefly interrupts a broadcast could be costly in terms of lost advertising revenue, Tysarczyk said. &#8220;We&#8217;re putting a lot of faith in those third-party operating techniques and what their cyber protections are,&#8221; he said.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Further, now that sports gambling is now legal in 38 US states, including Washington, DC, and Puerto Rico, stealing data is more lucrative for threat actors than ever. Non-public information, including health records and other proprietary statistics, is especially valuable. &#8220;[It&#8217;s] the data that people use to develop trends and see where the wagers go and things like that,&#8221; Tysarczyk said.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A broader ecosystem that shares increasing amounts of data needs to ensure that information is air-gapped, which was the focus in Paris this summer, Hoover said. &#8220;It really requires a partnership effort, and it was an all-hands-on-deck effort in Paris to defend the networks,&#8221; he said. &#8220;It&#8217;s a closed network, and so we are very concerned about the integrity of the sport, the safety of our athletes, and the safety of our fans that attend, and making sure that we can protect the data and keep that inbound and the right people are getting the right data.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/6-cybersecurity-headaches-sports-organizations-have-to-worry-about\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Professional sporting events have long been prime targets for violent<\/p>\n","protected":false},"author":12,"featured_media":5458,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-5457","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/6-cybersecurity-headaches-sports-organizations-have-to-worry-about-scaled.jpg?fit=2560%2C1440&ssl=1",2560,1440,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/6-cybersecurity-headaches-sports-organizations-have-to-worry-about-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/6-cybersecurity-headaches-sports-organizations-have-to-worry-about-scaled.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/6-cybersecurity-headaches-sports-organizations-have-to-worry-about-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/6-cybersecurity-headaches-sports-organizations-have-to-worry-about-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/6-cybersecurity-headaches-sports-organizations-have-to-worry-about-scaled.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/6-cybersecurity-headaches-sports-organizations-have-to-worry-about-scaled.jpg?fit=2048%2C1152&ssl=1",2048,1152,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/6-cybersecurity-headaches-sports-organizations-have-to-worry-about-scaled.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/6-cybersecurity-headaches-sports-organizations-have-to-worry-about-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/6-cybersecurity-headaches-sports-organizations-have-to-worry-about-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/6-cybersecurity-headaches-sports-organizations-have-to-worry-about-scaled.jpg?fit=2560%2C1440&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5457","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=5457"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5457\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/5458"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=5457"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=5457"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=5457"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}