Bologna FC confirmed ransomware attack after RansomHub leaked club data
- Organization
- Italy - Bologna FC 1909
- Exploit
- Ransomware
- Industry
- Sports and Entertainment
Bologna FC 1909 confirmed on November 29, 2024 that a ransomware attack had hit its internal systems and that corporate data had been stolen. The Serie A club warned that possessing the stolen files, or helping to publish or circulate them, was a serious criminal offense. It did not say what ransom had been demanded or whether anything was paid.
The RansomHub group claimed the intrusion and listed the club on its dark web leak site, running a countdown that expired at midday UTC on November 29. RansomHub said it held about 200 gigabytes of material, including financial records, sponsorship agreements, commercial strategy and business plans, transfer documents, medical files on players and staff, stadium and infrastructure details, and personal data on employees, supporters and youth players.
Samples posted by the group included what it presented as manager Vincenzo Italiano's employment contract, showing an annual salary of 4.575 million euros alongside tax identifiers and bank account details, according to The Register. Another file was a passport scan of former assistant manager Emilio De Leo. Player contracts and passports reportedly dated back to at least 2017.
RansomHub added pressure by claiming the documents would show breaches of European data protection law and of FIFA and UEFA financial rules. The club described the incident as a criminal act and acknowledged that the stolen data might be published.