October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

DICK’S Sporting Goods Locked Employee Accounts After August 2024 Cybersecurity Incident

DICK’S Sporting Goods confirmed unauthorized access to systems containing some confidential information in August 2024. Employee email and account shutdowns were reported separately, but the company did not identify affected data or confirm customer information exposure.
From TheFinanceBase Team5 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

DICK’S Sporting Goods confirmed unauthorized third-party access to its information systems on August 21, 2024. In an August 28 SEC filing, the company said some affected systems contained “certain confidential information,” that it had contained the threat and notified federal law enforcement, and that its investigation was continuing. The filing did not say what information was accessed or whether customer or employee personal data was taken.

BleepingComputer separately reported that DICK’S shut down email and locked some employee accounts while it verified identities and restored access. Those operational details came from an anonymous source and an internal memo, not from the SEC filing.

What happened and when

Date What is known
August 21, 2024 DICK’S said it discovered unauthorized third-party access.
August 21–28 The company activated its incident-response plan, isolated and contained the threat, hired outside cybersecurity experts and notified federal law enforcement.
August 28, 2024 DICK’S filed its disclosure with the SEC. News coverage then described employee account and email disruptions.

The company’s filing is the strongest public evidence. It describes an unauthorized-access incident; media reports called it a data breach or cyberattack. Unauthorized access does not, by itself, prove that information was viewed, copied or removed. A legally reportable consumer-data breach would generally require more specific findings about affected personal information and individuals.

Read DICK’S Form 8-K filing.

What DICK’S officially confirmed

  • Unauthorized third-party access was discovered on August 21.
  • Some affected systems contained portions with “certain confidential information.”
  • The company activated its response plan and engaged external cybersecurity experts.
  • DICK’S investigated, isolated and contained the threat.
  • Federal law enforcement was notified, although the agency was not named.
  • At the time of the filing, DICK’S said it had no knowledge that the incident disrupted business operations.
  • The company considered the incident not material based on the information then available, while reserving the ability to reassess as facts developed.

Why employee accounts were reportedly locked

BleepingComputer reported, citing an anonymous source, that DICK’S shut down email and locked employees out of internal accounts. The report said access was restored after employees completed identity verification, including camera-based checks in some cases. An internal memo reportedly instructed employees to use personal email or text messages for company communications while systems were unavailable.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Those actions are consistent with a containment measure: disabling accounts can prevent an intruder from continuing to use compromised credentials while investigators reset access and review systems. The SEC filing does not state how many employees were affected, how long the lockout lasted or exactly which systems were disabled, so the report should not be read as a company-wide account of every employee’s experience.

BleepingComputer’s report also said phone lines at multiple local stores were unavailable. That claim was not included in DICK’S SEC disclosure.

Were stores, online orders or customers affected?

DICK’S said it had no knowledge of a disruption to business operations when it filed the Form 8-K. That statement does not necessarily mean that every internal system worked normally. Reported email, account-access and store-phone problems could coexist with stores and online sales continuing.

The available disclosures do not establish that stores closed, online orders stopped, payment processing failed or customers could not shop. They also do not establish that customer accounts or payment information were compromised.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Was customer or employee data exposed?

That has not been publicly established. “Certain confidential information” is broad language. It could refer to business, operational, employee, vendor or customer information, but the filing does not identify the category.

Established Not identified publicly
Unauthorized access occurred. Exact data types or number of records.
Affected systems included confidential information. Whether information was viewed or exfiltrated.
The threat was investigated and contained. Whether customer or employee personal information was involved.
Outside experts and law enforcement were engaged. The entry method, attacker or any ransom demand.

There is no public confirmation in the cited disclosures that names, passwords, payment-card numbers, Social Security numbers, loyalty data or health information were stolen. It is equally inappropriate to claim that no data was taken while the investigation remained open.

Was this ransomware?

The SEC filing does not mention ransomware, malware, extortion, a ransom demand or a named threat actor. Disabling email and employee accounts is not enough to identify the incident as ransomware. “Cybersecurity incident” or “unauthorized-access incident” is the most accurate description based on the public record.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What “not material” means

“Not material” is a securities-reporting judgment about the incident’s significance to the company, based on information available when DICK’S filed. It does not mean that no information was accessed, that no employee or customer faced risk, or that later findings could not change the assessment. Materiality for investors is different from the privacy significance of an individual account or record.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What employees should do

  1. Use only verified DICK’S channels, managers or IT contacts for account-recovery instructions.
  2. Be skeptical of messages sent to personal email or phones during a disruption; an attacker may imitate emergency instructions.
  3. Never provide a password, multifactor authentication code or identity document to an unverified caller or message sender.
  4. Do not reuse a DICK’S password on another service. Change reused passwords and enable multifactor authentication where available.
  5. Preserve suspicious messages and report them through the company’s designated security process.

What customers should do

  • Review DICK’S account activity and payment-card statements for transactions you do not recognize.
  • Use a unique password for any DICK’S account and change it if it was reused elsewhere.
  • Enable multifactor authentication if the account offers it.
  • Treat unexpected breach-related emails, refunds, coupons, order notices and password-reset links as potential phishing attempts; reach DICK’S through a known website or support number instead of the message.
  • Do not assume you need paid credit monitoring or a credit freeze unless DICK’S or another authoritative notice confirms exposure of sensitive identity or financial data.

What remains to watch

Further clarity would come from a DICK’S breach notice, an updated SEC filing, state attorney-general notice, law-enforcement announcement or court filing. Those sources could identify affected data, people, notification steps or later business impact. The public disclosures cited here do not establish the attacker, initial access method, exfiltration, record count, restoration time, later identity-theft harm or whether breach-notification letters were sent.

The Bottom Line

DICK’S confirmed an unauthorized-access incident and a continuing investigation, not a fully characterized customer-data breach. Employee lockouts and email shutdowns were reported as containment actions, while the type and scope of any accessed information remained undisclosed.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.