4 Apr 2017

IAAF suffers cyber attack

10:01 am on 4 April 2017

The governing body of global athletics, the IAAF, said it had suffered a cyber attack which it believes has compromised information about athletes' medical records.

IAAF

IAAF Photo: Supplied

An IAAF statement said the hacking group known as Fancy Bear was believed to be behind the attack in February and that it targeted information concerning applications by athletics for Therapeutic Use Exemptions.

The IAAF said it had contacted athletes who had applied for TUEs since 2012 and its president, Sebastian Coe, apologised.

Our first priority is to the athletes who have provided the IAAF with information that they believed would be secure and confidential, he said. "They have our sincerest apologies and our total commitment to continue to do everything in our power to remedy the situation."

TUEs are issued by sports federations and national anti-doping organizations to allow athletes to take certain banned substances for verified medical needs.

The IAAF said that data on athlete TUEs was "collected from a file server and stored on a newly created file".

"The attack by Fancy Bear, also known as APT28, was detected during a proactive investigation carried out by cyber incident response (CIR) firm Context Information Security," the IAAF said

It was not known if the information was stolen from the network, the IAAF said, but the incident was "a strong indication of the attackers' interest and intent, and shows they had access and means to obtain content from this file at will".

IAAF boss Sebastian Coe.

IAAF boss Sebastian Coe. Photo: PHOTOSPORT

The attack was uncovered after British company Context Information Security conducted a investigation of the IAAF's systems at the request of the athletics body.

Context Information Security said in a separate statement that it was a "sophisticated intrusion" and that "the IAAF have understood the importance and impact of the attack and have provided us comprehensive assistance."

Fancy Bear, widely believed to be from Russia, could not immediately be reached for comment.

Last year, the same group hacked into the World Anti-Doping Agency (WADA) database and published the confidential medical records of several dozen athletes.

Those included cyclist Bradley Wiggins, the 2012 Tour de France winner and Britain's most decorated Olympian with eight medals, who was revealed to have used TUEs before key races.

Wiggins retired last year under something of a cloud after it was revealed he took corticosteroid triamcinolone for asthma, although he broke no anti-doping rules.

The IAAF banned Russia's athletics federation after a WADA commission report found evidence of state-sponsored doping. Almost all Russia's athletes missed the track and field events at the Rio Olympics last year and are likely to also miss the world athletics championships in London in August.

-Reuters