Paddy Power and BetFair have suffered a data breach

Graham Cluley
Graham Cluley
@

 @grahamcluley.com
 / grahamcluley

Paddy Power and BetFair have suffered a data breach

The gambling firms Paddy Power and BetFair have suffered a data breach, after “an unauthorised third party” gained access to “limited betting account information” relating to up to 800,000 of their customers.

What was exposed? Usernames, email addresses, IP addresses.

However, parent company Flutter says “no passwords, ID documents or usable card or payment details were impacted”. The word “usable” might be doing some heavy-lifting there, I wonder if some partial payment card details were exposed…

Paddypower email
Email sent to affected customers of Paddy Power

An obvious threat is phishing attacks, targeting Betfair and Paddy Power customers – perhaps posing as messages from the companies, in an attempt to trick users into handing over more of their details. So be on your guard!

Flutter says it is carrying out a “full investigation” to understand the scale of the breach, and is working with external cybersecurity experts.

Readers with long memories will recall that this is not the first time that Paddy Power has suffered a data breach, although it appears to have been more proactive in informing its customers this time.

Sign up to our free newsletter.
Security news, advice, and tips.

Graham Cluley is an award-winning keynote speaker who has given presentations around the world about cybersecurity, hackers, and online privacy. A veteran of the computer security industry since the early 1990s, he wrote the first ever version of Dr Solomon's Anti-Virus Toolkit for Windows, makes regular media appearances, and hosts the popular "Smashing Security" podcast. Follow him on LinkedIn, Bluesky and Mastodon, or drop him an email.

What do you think? Leave a comment

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.