Flutter Entertainment

Flutter Entertainment

Flutter Entertainment, which owns Paddy Power and Betfair, suffered a data breach affecting up to 800,000 users. Personal information including IP addresses, email addresses, and online activity data was compromised. While no passwords, ID documents, or usable card or payment details were impacted, cybersecurity experts warn that the breached data could be used for spear phishing attacks. Customers are advised to remain vigilant for detailed emails that might refer to their previous betting habits and encourage them to click links or give away credit card information.

Source: https://www.bbc.com/news/articles/cz7l29zved9o

TPRM report: https://scoringcyber.rankiteo.com/company/flutter-entertainment

"id": "flu603071425",
"linkid": "flutter-entertainment",
"type": "Breach",
"date": "7/2025",
"severity": "50",
"impact": "",
"explanation": "Attack limited on finance or reputation: Loss of bank statements, self-assessment details, and other people's National Insurance numbers"
{'affected_entities': [{'customers_affected': 'Up to 800,000 users',
                        'industry': 'Online Gambling',
                        'location': ['UK', 'Ireland'],
                        'name': 'Flutter Entertainment',
                        'size': '4.2 million average monthly players across '
                                'all its brands',
                        'type': 'Company'}],
 'attack_vector': 'Hacking',
 'customer_advisories': 'Remain vigilant',
 'data_breach': {'number_of_records_exposed': 'Up to 800,000',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'Medium',
                 'type_of_data_compromised': ['IP addresses',
                                              'email addresses',
                                              'online activity data']},
 'description': 'A data breach at Paddy Power and Betfair, owned by Flutter '
                'Entertainment, has compromised personal information including '
                'IP addresses, email addresses, and online activity data of up '
                'to 800,000 users. The company has contained the incident and '
                'advised users to remain vigilant against spear phishing '
                'attacks.',
 'impact': {'brand_reputation_impact': 'Medium',
            'data_compromised': ['IP addresses',
                                 'email addresses',
                                 'online activity data'],
            'identity_theft_risk': 'High',
            'payment_information_risk': 'Low'},
 'investigation_status': 'Contained',
 'recommendations': ['Remain vigilant against spear phishing attacks'],
 'references': [{'source': 'BBC'}],
 'response': {'communication_strategy': 'Advised users to remain vigilant',
              'containment_measures': 'Incident contained',
              'incident_response_plan_activated': 'Yes'},
 'title': 'Paddy Power and Betfair Data Breach',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.