CSIDB logo
Incident

Stars Group

Incident posture

Attack window
May 2023
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-01-07 02:26

Linked entities

Victim
Stars Group
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
May 2023
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cybersecurity incident involving PokerStars resulted from an external system breach, compromising personal data including names and Social Security numbers. The breach affected over 110,000 individuals, including nine Maine residents, with written notifications issued to impacted parties. No identity theft protection services were offered following the incident, which was discovered shortly after unauthorized access occurred. The organization's legal representative facilitated breach disclosures without indicating prior related incidents within the preceding year.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On May 30-31, 2023, TSG Interactive US Services Limited, operating as PokerStars, experienced an external system breach involving unauthorized access to its systems through hacking. The breach was discovered on June 2, 2023, two days after the initial intrusion period. The compromised data included affected individuals' names combined with their Social Security Numbers, a combination posing significant identity theft risks. The incident impacted 110,291 individuals globally, including nine residents of Maine. PokerStars, headquartered at 251 Little Falls Drive in Wilmington, Delaware, engaged legal representation from Norton Rose Fulbright to manage breach disclosures, with attorney Will Daugherty serving as the primary contact for regulatory communications.

PokerStars notified affected Maine residents via written correspondence dispatched on July 20, 2023, as documented in the filing titled "EXPERIAN_Job42179d20_TSGPlatforms(Ireland)Limited(Flutter)_L01_SAS_1.pdf." The company fulfilled its obligation to alert consumer reporting agencies due to the breach exceeding 1,000 impacted Maine residents. No identity theft protection services were offered to victims, and no prior breaches had been reported by the entity within the preceding 12 months. The breach notification emphasized the confirmed acquisition of sensitive personal identifiers but did not disclose technical details regarding attack vectors, system vulnerabilities, or containment measures. Regulatory filings confirmed the incident's classification as an external cybersecurity compromise without elaborating on operational disruptions or financial consequences.

Sources

Sources available to members: 1 source.

CSIDB