Oddschecker confirms data breach involving passwords, contact details and dates of birth
Oddschecker has confirmed an “IT security incident involving user data” and told account holders to reset their passwords. For high-risk operators and affiliate platforms, the useful part is not the headline itself but the mechanics: personal data was involved, the incident was contained, and the company has already notified relevant authorities.
- FairPlay Sports Media (FPSM), which owns Oddschecker, said it “recently identified, contained and resolved an IT security incident involving a limited part of our systems.” The company added that the breach did not disrupt normal services and that it continues to operate as usual.
- The incident affected user personal data, including passwords, contact details and dates of birth. Oddschecker also said it has “not identified any evidence” that the data was being misused, including for phishing messages sent to customers’ personal email addresses.
- The company said it has been working with a “leading team of external IT specialists” to close down the incident and has reported it to the relevant authorities, which likely includes the UK Information Commission’s Office (ICO). Account holders were encouraged to update their passwords, and to change them on other accounts if they reuse the same credentials across multiple platforms.
- Oddschecker’s message to users said these incidents are “increasingly common in today’s digital world,” and the point lands neatly for the betting sector: bookmakers, casinos and affiliate platforms hold large volumes of personal data, which makes them useful targets once controls are bypassed.
- Fraud and cyber incidents have shown up across multiple markets. Earlier this year, ScamInfo.ai said that, in an analysis of over 7,185 websites, over 34.7% of the “critical risk” sites it identified were betting and gambling platforms. The article also points to previous attacks on Flutter Entertainment’s Paddy Power and Betfair in the UK, as well as incidents in Africa and North America.
For PSPs, acquirers and partner banks, the operational question is straightforward: if an affiliate platform or bookmaker is holding passwords, DOBs and contact details, incident response and password hygiene stop being “IT issues” and become part of counterparty risk.
Weekly high-risk digest
Regulation, sanctions and payment news across your verticals — once a week, free.
Please check your inbox and click the link to confirm your subscription.
Please enter a valid email address!