Leading golf clubs manufacturer Topgolf Callaway said it suffered a significant data breach that compromised the sensitive personal information of more than one million individuals.
Topgolf Callaway (commonly known as Callaway) is an American global sports equipment manufacturing company that designs, manufactures, markets and sells golf equipment, more specifically clubs and balls and accessories such as bags, gloves, and caps.
In a recent filing with the Office of the Maine Attorney General, Callaway
said that on August 1, it identified unusual activity in its internal network and immediately launched an internal investigation, with assistance from third party cyber security experts, to understand the nature and scope of the security incident.
The investigation revealed that the sensitive personal information of at least 1,114,954 individuals were compromised as a result of a breach, including 2,219 Maine residents. The cyber security incident also impacted customers of Callaway’s subsidiary brands like Odyssey, Ogio, and Callaway Gold Preowned sites that all operate under the same business umbrella.
The compromised data included the names, mailing addresses, email addresses, phone numbers, order history details, account passwords, and answers to security questions for over a million Callaway customers.
“On August 29, 2023, Topgolf Callaway disabled the security questions and reset the user profile password for all involved Maine residents. Topgolf Callaway also emailed notification letters to Maine residents the same day,” the golf clubs manufacturer said.
“Importantly, no full payment card numbers and government identification numbers, such as Social Security numbers, were affected as we do not store this information,” Callaway added.
According to the company’s regulatory filing, Callaway has decided not to provide any identity protection or credit monitoring services to the affected individuals, but it has taken preventive measures to avoid such incidents in the future.
“We have taken numerous increased steps to secure your data, which include additional protective security layers around the data, improving security protocols that govern access to our systems, and continuing to work with external advisors to enhance the security of our systems,” Callaway added.
The company is yet to disclose how threat actors accessed its systems or whether a ransom demand has been made.