Recommended Free Tools
DICK’S Sporting Goods confirmed unauthorized third-party access to its information systems on August 21, 2024. In an August 28 SEC filing, the company said some affected systems contained “certain confidential information,” that it had contained the threat and notified federal law enforcement, and that its investigation was continuing. The filing did not say what information was accessed or whether customer or employee personal data was taken.
BleepingComputer separately reported that DICK’S shut down email and locked some employee accounts while it verified identities and restored access. Those operational details came from an anonymous source and an internal memo, not from the SEC filing.
What happened and when
| Date | What is known |
|---|---|
| August 21, 2024 | DICK’S said it discovered unauthorized third-party access. |
| August 21–28 | The company activated its incident-response plan, isolated and contained the threat, hired outside cybersecurity experts and notified federal law enforcement. |
| August 28, 2024 | DICK’S filed its disclosure with the SEC. News coverage then described employee account and email disruptions. |
The company’s filing is the strongest public evidence. It describes an unauthorized-access incident; media reports called it a data breach or cyberattack. Unauthorized access does not, by itself, prove that information was viewed, copied or removed. A legally reportable consumer-data breach would generally require more specific findings about affected personal information and individuals.
What DICK’S officially confirmed
- Unauthorized third-party access was discovered on August 21.
- Some affected systems contained portions with “certain confidential information.”
- The company activated its response plan and engaged external cybersecurity experts.
- DICK’S investigated, isolated and contained the threat.
- Federal law enforcement was notified, although the agency was not named.
- At the time of the filing, DICK’S said it had no knowledge that the incident disrupted business operations.
- The company considered the incident not material based on the information then available, while reserving the ability to reassess as facts developed.
Why employee accounts were reportedly locked
BleepingComputer reported, citing an anonymous source, that DICK’S shut down email and locked employees out of internal accounts. The report said access was restored after employees completed identity verification, including camera-based checks in some cases. An internal memo reportedly instructed employees to use personal email or text messages for company communications while systems were unavailable.
#1 Best Overall
Those actions are consistent with a containment measure: disabling accounts can prevent an intruder from continuing to use compromised credentials while investigators reset access and review systems. The SEC filing does not state how many employees were affected, how long the lockout lasted or exactly which systems were disabled, so the report should not be read as a company-wide account of every employee’s experience.
BleepingComputer’s report also said phone lines at multiple local stores were unavailable. That claim was not included in DICK’S SEC disclosure.
Were stores, online orders or customers affected?
DICK’S said it had no knowledge of a disruption to business operations when it filed the Form 8-K. That statement does not necessarily mean that every internal system worked normally. Reported email, account-access and store-phone problems could coexist with stores and online sales continuing.
The available disclosures do not establish that stores closed, online orders stopped, payment processing failed or customers could not shop. They also do not establish that customer accounts or payment information were compromised.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
Was customer or employee data exposed?
That has not been publicly established. “Certain confidential information” is broad language. It could refer to business, operational, employee, vendor or customer information, but the filing does not identify the category.
| Established | Not identified publicly |
|---|---|
| Unauthorized access occurred. | Exact data types or number of records. |
| Affected systems included confidential information. | Whether information was viewed or exfiltrated. |
| The threat was investigated and contained. | Whether customer or employee personal information was involved. |
| Outside experts and law enforcement were engaged. | The entry method, attacker or any ransom demand. |
There is no public confirmation in the cited disclosures that names, passwords, payment-card numbers, Social Security numbers, loyalty data or health information were stolen. It is equally inappropriate to claim that no data was taken while the investigation remained open.
Rank #4
Was this ransomware?
The SEC filing does not mention ransomware, malware, extortion, a ransom demand or a named threat actor. Disabling email and employee accounts is not enough to identify the incident as ransomware. “Cybersecurity incident” or “unauthorized-access incident” is the most accurate description based on the public record.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What “not material” means
“Not material” is a securities-reporting judgment about the incident’s significance to the company, based on information available when DICK’S filed. It does not mean that no information was accessed, that no employee or customer faced risk, or that later findings could not change the assessment. Materiality for investors is different from the privacy significance of an individual account or record.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Best Value
What employees should do
- Use only verified DICK’S channels, managers or IT contacts for account-recovery instructions.
- Be skeptical of messages sent to personal email or phones during a disruption; an attacker may imitate emergency instructions.
- Never provide a password, multifactor authentication code or identity document to an unverified caller or message sender.
- Do not reuse a DICK’S password on another service. Change reused passwords and enable multifactor authentication where available.
- Preserve suspicious messages and report them through the company’s designated security process.
What customers should do
- Review DICK’S account activity and payment-card statements for transactions you do not recognize.
- Use a unique password for any DICK’S account and change it if it was reused elsewhere.
- Enable multifactor authentication if the account offers it.
- Treat unexpected breach-related emails, refunds, coupons, order notices and password-reset links as potential phishing attempts; reach DICK’S through a known website or support number instead of the message.
- Do not assume you need paid credit monitoring or a credit freeze unless DICK’S or another authoritative notice confirms exposure of sensitive identity or financial data.
What remains to watch
Further clarity would come from a DICK’S breach notice, an updated SEC filing, state attorney-general notice, law-enforcement announcement or court filing. Those sources could identify affected data, people, notification steps or later business impact. The public disclosures cited here do not establish the attacker, initial access method, exfiltration, record count, restoration time, later identity-theft harm or whether breach-notification letters were sent.
The Bottom Line
DICK’S confirmed an unauthorized-access incident and a continuing investigation, not a fully characterized customer-data breach. Employee lockouts and email shutdowns were reported as containment actions, while the type and scope of any accessed information remained undisclosed.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




