Oddschecker confirms data breach but “situation contained”
The company behind the hugely popular betting odds comparison site Oddschecker has confirmed that the platform was subject to a data breach.
Cyber attacks are not uncommon in the betting and gaming space. Flutter Entertainment’s Paddy Power and Betfair were subject to a large attack in July last year, for example.
In Oddschecker’s case, an email sent round to a number of account holders this week confirmed that an “IT security incident involving user data” had taken place.
The breach included user’s personal data including passwords, contact details and dates of birth.
However, Oddschecker reassured its users that it has “not identified any evidence” that the data involved was being misused, including being used to send phishing messages to its customers’ personal email addresses.
“We recently identified, contained and resolved an IT security incident involving a limited part of our systems,”a spokesperson for FairPlay Sports Media (FPSM), the company which owns Oddschecker, told SBC News.
“This did not disrupt our usual services and we continue to operate as normal. We are liaising closely with our users, partners and the relevant authorities.”
Oddschecker users encouraged to reset passwords
The company informed its customers that it has been working with a “leading team of external IT specialists to swiftly close down the incident”.
It has also reported the incident to the relevant authorities, which likely includes the UK Information Commission’s Office (ICO).
Oddschecker account holders have also been encouraged to update their passwords, and to update passwords on other accounts if they use the same one across multiple platforms.
The company’s message to customers also noted that “these types of incidents are increasingly common in today’s digital world and affect organisations in all sectors”.
It isn’t wrong at all in this regard.
The huge amount of data processed and personal information held by online bookmakers, casinos, or affiliate platforms as in Oddschecker’s case, makes them a valuable target for cybercriminals – if they can bypass controls and protections.
Data breaches and incidents of cybercriminality have occurred across multiple markets, affecting multiple operators and their consumers. These include cases of IT attacks, cases of operator mishandling of data, or of scam activity.
According to analysis of over 7,185 websites conducted earlier this year by ScamInfo.ai, a scam detections site, over 34.7% of the “critical risk” sites identified were betting and gambling platforms.
In addition to the attack against Paddy Power and Betfair in the UK last year, incidents have also been seen across Africa and North America.
Back in 2022, Entain and MGM Resorts International’s US joint venture BetMGM revealed that “several patron records” had been obtained via a data breach.
In October last year, an ex-employee of online gaming group Boyd Gaming filed a lawsuit against his former employer after a cybersecurity attack against the company was revealed in a Securities and Exchange Commission (SEC) filing.
And in Kenya, a legal storm was whipped up in June when an analysis of WhatsApp communications uncovered a “systematic compromise of subscriber data” at prominent betting operator Betika.
No Comments