
The personal information of Paddy Power and Betfair customers has been hacked in a data breach… although the firms have denied that passwords or payment details have been compromised.
However, Flutter – the parent company of the brands – refused to rule out the possibility that email addresses, the first line of postal addresses and usernames could have been taken as part of the breach.
And the conglomerate has called on their customers to be ‘vigilant’ over the potential misuse of the information stolen.
Regrettable Impact
Any customers that were part of the potential breach have been contacted today (Tuesday July 8) by Flutter via email.
“We are writing to inform you of a data incident on Flutter’s Exchange Platform,” the email from Betfair reads.
“The nature of this incident means that, regrettably, some of your personal information has been impacted.
“Importantly, this does not include passwords, ID documents or any usable card or payment details. However, if certain types of personal information were accessed, there is a risk that criminals may use this information to conduct phishing against you or attempt to impersonate you.”
A spokesperson for Flutter later reiterated the party line to the Racing Post, although it has been confirmed that come personal data could have been compromised in the breach, which was reportedly caused by ‘unauthorised access’ to central databases being given.
“Immediately upon becoming aware of this incident, we informed relevant regulators and authorities and initiated a full investigation, supported by external IT security experts, to understand what happened and how we can better protect our networks and customers,” the spokesperson commented.
“The unauthorised access has been removed and the incident contained. Our investigation concluded that the affected information was isolated to limited betting account information.”
Although there’s no evidence to link the two hacks, the British Horseracing Authority (BHA) was also the target of a data breach as recently as June.
The nature of that attack was so significant that the BHA’s offices were closed and staff asked to work from home following the ransomware breach.
“We recently identified and began investigating an IT incident. We are working at pace with external specialists to determine what happened in more detail and safely restore our systems,” a spokesperson revealed.
Although the episode occurred just days ahead of the Epsom Derby Festival, no racing fixtures were affected.
But these data hacks can be expensive. Retail giant Marks and Spencer was hacked earlier this year, revealing that the incident cost them an eye-watering £300 million in lost profits.
The major cyber attack on Marks and Spencer has been reportedly linked to a notorious teenage hacking gang.
The group, known as ‘Scattered Spider’, has previously targeted major US companies, including MGM Resorts and Caesars Casino. @richardgaisford has the latest. pic.twitter.com/QKgOF2exdB
— Good Morning Britain (@GMB) April 30, 2025
It has been suggested that a notorious hacking group are behind the breaches, with suggestions that other gambling firms – including MGM Resorts and Caesars – have also been targeted.
Data Danger
![]()
Unfortunately, this isn’t the first time that betting firms have hit the headlines for all the wrong reasons as far as data usage is concerned.
In February, it was reported that gambling operators were sharing customer data with Facebook without permission or consent – leading to some users of the social media platform to be bombarded with ads for bookmakers and online casinos.
Some betting firms have used an invisible ‘tracker’, embedded within their websites, to spy on users and then share their activity with Meta, the parent company of Facebook.
The Observer newspaper tested 150 different betting sites, finding that 52 of them – including Sporting Index, Hollywoodbets and Bwin – had harvested data to Facebook.
According to the legal sector, this is a clear breach of data protection laws; however, at the time of writing, no action has been taken against those involved.
Previously, Sky Bet’s parent company had been reprimanded by the Information Commissioner’s Office (ICO) for ‘unlawfully processing people’s data.’
ICO found that Sky Bet was sharing data with ‘technology partners’, principally advertisers, before customers had a chance to accept or reject cookies – something the authority described as ‘not lawful, transparent or fair.’
And in January 2025, Sky bet were hauled to the High Court over claims they had bombarded a former problem gambler with adverts and promotional messaging – despite the individual opting out of such communications.
The judge ruled in the individual’s favour, who was then free to sue Sky Bet for damages.