Royal Dutch Football Association says hackers stole employee data
- Organization
- Royal Dutch Football Association (KNVB)
- Exploit
- Ransomware
- Industry
- Sports
The Royal Dutch Football Association, known as the KNVB, confirmed on April 4, 2023 that an outside party had broken into the network at its campus in Zeist and stolen personal data belonging to staff. The association said its primary business systems, including email, had not been taken down and that matches and competitions went ahead as scheduled.
The KNVB did not initially specify what categories of employee information were taken or how many of its more than 500 staff were involved, saying the details were still under investigation. It warned that affected employees could become targets for phishing or financial fraud. The breach was reported to the Dutch Data Protection Authority, and the association said it examined all servers on the campus network to establish the scope. Organisations running the two Dutch professional football leagues were also caught up in the incident.
In a statement the KNVB said that despite its security system it had now fallen victim as well, and apologised to employees who might face consequences. It declined at the time to say whether ransomware was involved.
Later in April the LockBit group listed the KNVB on its leak site and threatened to publish roughly 305GB of files, said to include passport copies, bank account numbers, medical records and confidential documents on disciplinary cases involving professional players. In September 2023 the KNVB confirmed it had paid an undisclosed ransom, a decision it said followed advice from the forensics firm Fox-IT. Dutch reporting put the sum at around one million euros, a figure the association did not confirm.