Packers_Pro_Shop

Thousands of credit cards stolen in Green Bay Packers store breach

Share:

​American football team Green Bay Packers says cybercriminals stole the credit card data of over 8,500 customers after hacking its official Pro Shop online retail store in a September breach.

In breach notification letters sent to affected individuals this week, the National Football League (NFL) team said it immediately disabled all checkout and payment capabilities after being notified on October 23 that the packersproshop.com website was breached.

While the letters didn’t share the number of impacted customers impacted, the football team said in documents filed with Maine’s Attorney General on Monday that the incident affected 8,514 people.

A follow-up investigation found that the attackers injected a credit card stealer in the store’s checkout page to harvest personal and payment information. However, the Packers said the attacker couldn’t intercept information from any payments made using gift cards, a Pro Shop website account, PayPal, or Amazon Pay.

“We also immediately required the vendor that hosts and manages the Pro Shop website to remove the malicious code from the checkout page, refresh its passwords, and confirm there were no remaining vulnerabilities,” the Packers’s Director of Retail Operations Chrysta Jorgensen explained.

“Based on the results of the forensic investigation, on December 20, 2024 we discovered that the malicious code may have allowed an unauthorized third party to view or acquire certain customer information entered at the checkout that used a limited set of payment options on the Pro Shop website between September 23-24, 2024 and October 3-23, 2024.”

The breach impacted information entered on the Pro Shop website at checkout, including names, addresses (billing and shipping), email addresses, credit card types and numbers, card expiration dates, and credit card verification numbers (CVVs).

The Packers has yet to share how the threat actor hacked its Pro Shop website; however, Dutch e-commerce security company Sansec, which spotted the Packers store breach in early October, found that the card skimming attack used YouTube’s oEmbed feature and a JSONP callback to bypass the Content Security Policy (CSP).

​”In this attack, a script was injected from https://js-stats.com/getInjector. This script harvested data from input, select, and textarea fields on the site, exfiltrating the captured information to https://js-stats.com/fetchData,” Sansec said in a December 31 report.

The NFL team offers affected people three years of identity theft restoration and credit monitoring services through Experian and advises them to track their account statements for fraudulent activity.

Anyone observing identity theft or fraud attempts should report them to their bank and the appropriate authorities, including the Federal Trade Commission (FTC) and the state attorney general.

In September 2022, the San Francisco 49ers also notified over 20,000 individuals that attackers stole their personal information (including Social Security numbers) in a February 2022 breach later claimed by the Blackbyte ransomware gang.

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
12:46 am, Apr 20, 2025
weather icon 7°C
L: 6° | H: 8°
scattered clouds
Humidity: 78 %
Pressure: 1008 mb
Wind: 8 mph NE
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 32%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 5:53 am
Sunset: 8:04 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
6° | 8°°C 0.23 mm 23% 10 mph 87 % 1008 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
8° | 16°°C 0.41 mm 41% 9 mph 95 % 1014 mb 0 mm/h
Tue Apr 22 10:00 pm
weather icon
7° | 15°°C 1 mm 100% 7 mph 85 % 1022 mb 0 mm/h
Wed Apr 23 10:00 pm
weather icon
7° | 9°°C 1 mm 100% 8 mph 96 % 1024 mb 0 mm/h
Thu Apr 24 10:00 pm
weather icon
7° | 15°°C 0.8 mm 80% 7 mph 97 % 1027 mb 0 mm/h
Today 1:00 am
weather icon
7° | 8°°C 0 mm 0% 8 mph 77 % 1008 mb 0 mm/h
Today 4:00 am
weather icon
6° | 7°°C 0 mm 0% 8 mph 78 % 1008 mb 0 mm/h
Today 7:00 am
weather icon
8° | 8°°C 0 mm 0% 9 mph 79 % 1008 mb 0 mm/h
Today 10:00 am
weather icon
13° | 13°°C 0 mm 0% 9 mph 69 % 1007 mb 0 mm/h
Today 1:00 pm
weather icon
15° | 15°°C 0 mm 0% 10 mph 60 % 1007 mb 0 mm/h
Today 4:00 pm
weather icon
13° | 13°°C 0.23 mm 23% 7 mph 75 % 1006 mb 0 mm/h
Today 7:00 pm
weather icon
12° | 12°°C 0 mm 0% 6 mph 80 % 1007 mb 0 mm/h
Today 10:00 pm
weather icon
10° | 10°°C 0 mm 0% 4 mph 87 % 1008 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€74,859.23
0.85%
Ethereum(ETH)
€1,419.98
1.62%
Tether(USDT)
€0.88
0.00%
XRP(XRP)
€1.83
0.97%
Solana(SOL)
€122.52
4.17%
USDC(USDC)
€0.88
0.01%
Dogecoin(DOGE)
€0.138203
-0.23%
Shiba Inu(SHIB)
€0.000011
0.69%
Pepe(PEPE)
€0.000007
3.17%
Scroll to Top