NBA notifies fans after breach at third-party email provider
- Organization
- National Basketball Association
- Exploit
- Third-Party Data Breach
- Industry
- Sports
The National Basketball Association began notifying fans in March 2023 that an unauthorised party had obtained a copy of their names and email addresses from a third-party service provider the league uses for email and mobile app communications.
The NBA did not name the provider. It said its own systems were not involved and that usernames, passwords and other information fans had shared with the league were not affected. The league did not disclose how many people were notified or when the underlying breach occurred.
Because the stolen data pairs real names with email addresses, the NBA warned recipients that they faced a higher risk of phishing and social engineering. Its notice advised fans to check that messages came from an nba.com address, to confirm that links pointed to trusted sites, and not to open unexpected attachments, adding that the league would never ask for account credentials by email.
The NBA said it had engaged outside cybersecurity experts and was working with the affected provider while the investigation continued. SecurityWeek noted that the timing invited speculation about a link to the Mailchimp breach disclosed earlier in 2023, but no connection was established.