Welsh Rugby Union investigated leak of supporters club member data
- Organization
- Welsh Rugby Union
- Exploit
- Misconfiguration
- Industry
- Sports Governing Body
The Welsh Rugby Union said in May 2024 that it had opened an investigation into a suspected data security breach involving members of its official supporters club, after researchers reported finding member records in a publicly accessible cloud storage location.
The exposure was identified by researchers at Cybernews, who said an unsecured Amazon Web Services S3 bucket held 1,419 text files covering 69,317 supporters club members. Reported fields included names, dates of birth, home addresses, telephone numbers, email addresses and details of the membership each person had purchased. The WRU disputed the headline figure, saying the data contained duplicates and that the true number of individuals was lower.
In a statement published on its website, the governing body said the incident concerned data held by an engaged third party rather than its own systems, and that it was working closely with the provider, which had begun its own inquiry. It added that all of the data had since been removed from the online source, that a review of its systems had found no other vulnerabilities or suspicious activity, and that no password or payment information had been compromised.
The WRU said it was complying with relevant reporting requirements to the Information Commissioner's Office. As of late May 2024 it had not named the service provider involved or said how many individuals it ultimately notified.