Header image

Leeds United Confirms Cyber-Attack Saw Payment Details Compromised

Attack took place between 19th and 24th February 2025.

Leeds United has confirmed that it suffered a cyber-attack in February, which saw some card details compromised.

In a statement, Leeds said the attack took place between 19th and 24th February 2025. The attack targeted its retail website, “resulting in the card details of a small number of customers being compromised.”

The club said it has communicated with all of those directly impacted and a forensic investigation was undertaken by a specialist third-party as soon the club discovered the breach, and measures were implemented to stop and recover from the attack.

“The club is disappointed that the attack was successful despite layers of cybersecurity, and offer our sincere apologies to anyone who has been adversely affected,” it said.

Commenting, Jake Moore, global cybersecurity advisor at ESET, said these types of attacks are able to penetrate a website and take copies of all payments with ease whilst hiding undercover.

“In a short space of time, cyber-criminals would have been able to swipe card payment details from all transactions from within the time frame affecting all customers from that time,” he said. “Although this digital heist can often go under the radar, it highlights the importance of robust protection, due diligence by all websites handling user’s  financial data and for website admins to monitor any anomalies, however small.”


Dan Raywood
Dan Raywood Senior Editor SC Media UK

Dan Raywood is a B2B journalist with more than 20 years of experience, including covering cybersecurity for the past 16 years. He has extensively covered topics from Advanced Persistent Threats and nation-state hackers to major data breaches and regulatory changes.

He has spoken at events including 44CON, Infosecurity Europe, RANT Conference, BSides Scotland, Steelcon and ESET Security Days.

Outside work, Dan enjoys supporting Tottenham Hotspur, managing mischievous cats, and sampling craft beers.

Dan Raywood
Dan Raywood Senior Editor SC Media UK

Dan Raywood is a B2B journalist with more than 20 years of experience, including covering cybersecurity for the past 16 years. He has extensively covered topics from Advanced Persistent Threats and nation-state hackers to major data breaches and regulatory changes.

He has spoken at events including 44CON, Infosecurity Europe, RANT Conference, BSides Scotland, Steelcon and ESET Security Days.

Outside work, Dan enjoys supporting Tottenham Hotspur, managing mischievous cats, and sampling craft beers.

Upcoming Events

02
Apr
Webinar

Benchmarking Security Skills and How to Ensure Secure-by-Design in the Enterprise

Consider how to prove the return on investment when implementing a secure-by-design initiative

image image image