Skip to main content

The Packers were targeted by hackers, putting credit cards in danger

Green Bay Packers helmet and logo.
Evan Siegle / Green Bay Packers / Packers.com

The Green Bay Packers just fell victim to hackers — or rather, the team’s online store did. The bad news? That means your credit card information could be in danger if you’ve recently shopped at the NFL team’s official online retail store. The Packers released a notice of a data breach, notifying its customers about the October hack. Here’s what we know.

Hackers managed to access the store and insert a card skimmer script to steal payment and personal information. The data affected includes credit card types, expiration dates, numbers, and verification numbers, which could put customers at risk of credit card fraud. Hackers also got access to names, addresses, and email addresses, says Bleeping Computer.

Recommended Videos

The NFL team had already turned off all payment and checkout capabilities after discovering on October 23 that the site had been compromised. The Green Bay Packers hired cybersecurity experts to investigate the incident and determine whether any customer information had been accessed. Thanks to the investigation, they discovered that personal and payment information was stolen between September and early October 2024.

“Based on the results of the forensic investigation, on December 20, 2024, we discovered that the malicious code may have allowed an unauthorized third party to view or acquire certain customer information entered at the checkout that used a limited set of payment options on the Pro Shop website between September 23 and 24, 2024, and October 3 and 23, 2024.”

Jordan Love, the quarterback of the Green Bay Packers.
NFL

There is some good news in all of this. If customers paid for their items using PayPal, Amazon Pay, a Pro Shop website account, or a gift card, their information was not affected. The NFL team also took action.

“We also immediately required the vendor that hosts and manages the Pro Shop website to remove the malicious code from the checkout page, refresh its passwords, and confirm there were no remaining vulnerabilities,” said Chrysta Jorgensen, the Packers’ director of retail operations.

Sansec, a Dutch security company, notified the Packers of the breach. According to Sansec, the threat actors used a JSONP callback (JSON with Padding, which means a technique that enables cross-domain requests) as well as YouTube’s oEmbed features to bypass the Content Security Policy (CSP) and carry out their attack.

The Green Bay Packers offered those affected three years of credit monitoring and identity theft restoration services. If you bought anything in the Packers’ online store during the period of September to October 2024, make sure to monitor your credit card statements for fraudulent activities.

This isn’t the first time hackers have targeted the NFL. Multiple teams were targeted back in 2023, and a total of 15 NFL teams had their social media accounts breached.

Judy Sanhz
Judy Sanhz is a Digital Trends computing writer covering all computing news. Loves all operating systems and devices.
Your American Express credit card info may have been hacked
WWDC

American Express has put out a data breach advisory after third-party merchants experienced a hacking incident targeting its payment hardware, as reported by Bleeping Computer.

The financial services company detailed that the breach occurred in Massachusetts and is associated with an "American Express Travel Related Services Company." It resulted in several merchants suffering "unauthorized access to its system." Customers' credit card information, including account numbers, names, and card expiration data, may have been exposed in the process.

Read more
AMD and Apple face a dangerous new security flaw
A hacker typing on an Apple MacBook laptop while holding a phone. Both devices show code on their screens.

Researchers from cybersecurity firm Trail of Bits just found a vulnerability that affects some of the biggest brands in tech, namely Apple, AMD, and Qualcomm. The vulnerability, dubbed LeftoverLocals, affects graphics cards made by those companies. That makes it pretty widespread, with it affecting devices ranging from PCs and servers to tablets and smartphones. This flaw, if exploited, could allow attackers to access and steal data from vulnerable devices.

Normally, when working in a shared environment -- such as a workstation or a cloud computing infrastructure -- each user only has access to their own data and resources, even when working on the same hardware. However, LeftoverLocals bypasses these security measures and uses GPU memory to let potential attackers steal data from the other users on that same hardware.

Read more
Hackers targeted 1Password after Okta breach, but your logins are safe
A dark mystery hand typing on a laptop computer at night.

Security credentials like usernames and passwords are a tempting target for hackers, and even the best password managers can come under threat from time to time. That was the case recently with the popular password manager 1Password, which recently disclosed (via Bleeping Computer) that its Okta support system was breached by malicious hackers.

Fortunately, it doesn’t appear that any customer data was stolen, so if you use 1Password, your login info should be safe for now. However, it’s always good to regularly update your passwords (or use passkeys) just in case they fall into the wrong hands.

Read more