Cyber Incident Victim: NetPlay TV Group Ltd
Date:
Jan 2020
Location:
United Kingdom
Summary
A data breach at SuperCasino, an online gambling platform, exposed sensitive customer information, prompting the organization to notify affected users. The company stated that financial details, including credit card and payment information, as well as identity verification documents and user passwords, remained uncompromised. While the incident was attributed to hackers by the platform, the exact nature of the breach—whether it resulted from external intrusion, internal misconduct, or an accidental exposure—remained unclear at the time of reporting.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On or around January 26, 2020, the online gambling platform SuperCasino experienced a data breach resulting in the exposure of customer information. The incident came to public attention after registered users received an email notification from SuperCasino disclosing the leak. The company asserted that hackers did not access financial details, including credit card information, payment data, or documents uploaded for identity verification purposes. SuperCasino also stated that user passwords remained uncompromised in the breach. The organization did not specify the exact number of affected individuals or the types of non-financial data exposed beyond general references to "customer info." No technical details regarding attack vectors, intrusion methods, or system vulnerabilities were provided in the notification to customers or in public statements reported by media outlets covering the incident.

SuperCasino's breach notification failed to clarify whether the incident resulted from external hacking activity, internal misconduct by an employee, or accidental exposure through misconfigured systems. DataBreaches.net attempted to obtain clarification regarding the breach's origin by contacting SuperCasino but received no response prior to the publication of their article on January 26, 2020. The company did not disclose detection timelines, containment measures, or forensic investigation details. While SuperCasino minimized the incident's severity by emphasizing the protection of financial data and credentials, the exposure of personal information still created potential risks for affected customers. The lack of transparency regarding the breach mechanism and scope left significant questions unanswered about the security failure's nature and the adequacy of protective measures for user data.
