[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f23bvmjuhppbu4":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":26,"seoTitle":16,"seoTitleEn":27,"seoDescription":16,"seoDescriptionEn":28,"logoUrl":29,"isVerified":4,"isSensitive":30,"isSpamList":30,"isMalware":30,"company":31},"68e3266eda11adda488251a6","ecb","England Cricket Data Breach","england-cricket","ecb.co.uk","2024-03-23T00:00:00.000Z","2024-03-29T01:10:19.000Z","2026-07-03T14:51:06.409Z","2026-07-18T23:50:01.657Z","Third party breach","",[],43299,"known",null,"unknown","Medium",[24,25],"Email addresses","Passwords","\u003Cp>The England Cricket data breach is an incident that occurred during the March 2024 period through the icoachcricket site associated with the England and Wales Cricket Board, linked to 43,299 records. The record contains email addresses and password fields. Although the number of data classes appears small, breaches containing passwords are high priority because the risk grows rapidly if the same password is used on other accounts.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>The primary data fields in this record are email addresses and passwords. It is observed that the passwords are reported in formats stored with bcrypt, salted MD5, or both methods. These passwords should not be described in plain text; however, weak or reused passwords can be cracked over time or tried on other accounts.\u003C\u002Fp>\u003Cp>The combination of a password and email is narrower than communication or address information, but it is a more critical risk in terms of account security. Attackers may try the same email and password pair on different sports, social media, email, payment, or education platforms. Therefore, the user needs to consider not only the England Cricket account but also all accounts where the password is repeated.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The incident date is March 23, 2024, and the number of affected records is recorded as 43,299. Security records indicate that the data on the icoachcricket site includes email addresses and hashed password fields. The current data classes are compatible with this limited but significant scope, and the records are in a verified status.\u003C\u002Fp>\u003Cp>The scope does not include additional fields such as name, address, payment card, or date of birth. Therefore, a broad personal profile leak should not be described to the user. The correct risk is the possibility of the email and password fields being used to access other accounts. The hash structure does not mean that the password is secure; it only indicates that it is not stored in plain text.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Users at risk may be individuals who have created an account on icoachcricket or associated England Cricket accounts, including coaches, athletes, club staff, and users accessing educational materials. Those who use the same password for club, school, or personal email accounts are prioritized.\u003C\u002Fp>\u003Cp>In the context of sports and education, users may be accustomed to messages about courses, certificates, coach accounts, or membership renewals. Fake password reset or account suspension messages can be sent via email. Caution should be exercised against urgent action pressure in these messages.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Users in the matching field should change the password on their England Cricket or icoachcricket account and separate all accounts using the same password one by one. Email account security is a priority; because if the email is compromised, the recovery processes of other accounts are also at risk.\u003C\u002Fp>\u003Cp>Instead of opening incoming links directly, the user should log in through the known web address or application of the relevant service. The fact that the caller knows the name, email, address, or past transaction information does not prove they are trustworthy. One-time verification codes, payment card information, or account passwords should not be shared in any support conversation.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>In the long term, a password manager, unique passwords, two-factor authentication on applicable accounts, and the habit of removing unnecessary personal information from accounts reduce risk. Reusing the same email address across different platforms makes it easier to combine different breaches; therefore, using separate email or alias addresses for critical accounts can be considered.\u003C\u002Fp>\u003Cp>A permanent solution to violations involving passwords is not to reuse passwords on any account. Separate passwords should be used for sports clubs, educational platforms, and personal accounts; if possible, two-step verification should be enabled, and old accounts should be closed.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>LeakData check shows whether the queried email address is found in this record or not. A positive result does not necessarily mean that all data fields definitively belong to that user; however, it should be considered a sufficient warning for precautionary measures. A negative result only indicates that there is no match in this dataset and does not rule out the possibility of appearing in other breaches.\u003C\u002Fp>\u003Cp>If a positive result is obtained, the user should immediately change the password and investigate accounts where the same password is used. A negative result means there is no match in this record; however, the same email address may appear in other password breaches.\u003C\u002Fp>","England Cricket Data Breach (43.3 Thousand Reported Records)","England Cricket Data Breach. 43.3 Thousand reported records were reported. Reported data: Email addresses, Passwords. Review the scope, risks, and protective…","\u002Fuploads\u002Flogo\u002Fecb_co_uk.webp",false,{"name":32,"sector":33,"country":34,"website":10,"websiteArchiveUrl":16,"websiteStatus":16,"websiteCheckedAt":20},"England Cricket","Sports","United Kingdom"]