Incident

Welsh Rugby Union supporters' club member data leaked through an unsecured AWS S3 bucket


Learn More

The Welsh Rugby Union (WRU) has launched an investigation into a data leak involving data from some of its official supporters’ club members, which was held by a third-party service provider. The leak reportedly resulted from a publicly accessible Amazon Web Services (AWS) Simple Storage Service (S3) bucket that exposed 1,419 text files containing details of 69,317 members.

The exposed data includes:

  • Full names
  • Dates of birth
  • Home addresses
  • Phone numbers
  • Email addresses
  • Dates of membership purchase
  • Methods of payment for membership
  • Types of membership purchased

The WRU assured that the data has been removed from the online source and confirmed that no passwords or payment information were compromised.  They are conducting a thorough investigation and complying with the Information Commissioner’s Office (ICO) reporting requirements. The third-party service provider is also conducting an in-depth inquiry.

Welsh Rugby Union supporters' club member data leaked through an unsecured AWS S3 bucket