Paddy Power and Betfair Lose Customer Data Following Security Breach

Posted on: Last Updated: Views: 188
Erik Gibbs

Author:

Expertise: Global Gaming, Asia Gaming, US Gaming, Sports Gambling

A Paddy Power sign over a betting shop in the UK. (Source: Paddy Power)

LISTEN TO THIS ARTICLE:

Alongside basic account data, the breach also exposed details about recent activity on some user accounts. This includes technical metadata such as device IDs and IP addresses. Although no passwords or financial data such as credit card information or government-issued identification documents were accessed, the leaked data may still leave affected individuals vulnerable to fraudulent activity, such as phishing or impersonation attempts.

Flutter issued a public statement confirming the breach and stated that it had taken prompt action upon discovering the incident. The company notified the relevant regulatory bodies and law enforcement agencies and initiated a full investigation into the source and scope of the breach.

External IT security experts were brought in to assist with the inquiry and to reinforce the company’s cybersecurity defenses. Flutter said the unauthorized access was successfully removed and the incident has since been contained.

The operator emphasized that the breach was limited in scope, affecting only certain elements of users’ betting account information. According to the company’s investigation, more sensitive data such as payment card details, passwords and ID documents were not compromised. Flutter also confirmed that all users whose information was affected are being contacted directly and informed of the breach.

While Flutter stated that there is no evidence to suggest the stolen data has been misused to date, it acknowledged the risk that malicious actors could attempt to exploit the exposed information. Customers are being warned to be vigilant against potential phishing scams and fraudulent communications designed to extract more sensitive personal or financial data.

Gaming Industry a Major Cybersecurity Threat Target

The breach has brought renewed attention to cybersecurity vulnerabilities within the online gambling sector. The incident at Paddy Power and Betfair follows a separate cyber-attack targeting the British Horseracing Authority just days earlier. The increased frequency of such events highlights the growing need for heightened digital security measures across the broader gaming and sports industries.

According to recent remarks made by Marks & Spencer chief executive Stuart Machin, 43% of businesses in the UK have experienced a cyber-attack within the past year. The statistic reflects a broader trend of rising cyber threats facing companies that hold large volumes of customer data, particularly in sectors where digital platforms are central to operations.

Flutter reiterated its commitment to safeguarding customer information, stating that protecting users’ personal data is a top priority. The company continues to assess its systems and implement enhancements to prevent future breaches.

Regulators are expected to review the findings of the investigation and determine whether further actions or penalties are necessary based on data protection compliance standards.

RELATED TOPICS: Business