CSIDB logo
Incident

Flutter Entertainment

Incident posture

Attack window
Nov 2025
Location
Ireland
Status
Unknown
CIA posture
Available to members
Updated
2026-08-17 17:22

Linked entities

Victim
Flutter Entertainment
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Nov 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Flutter Entertainment owns the Betfair and Paddy Power brands, and up to 800,000 customers of these services were hit by a data breach. The incident was covered in a news article that highlighted the scale of the exposure. Both brands operate in the online gambling industry and serve a large international user base. The breach affected a significant number of users.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

The Irish Times reported on September 1, 2025, that up to 800,000 customers of Betfair and Paddy Power were affected by a data breach. The article, identified by Source Report ID 42563cb1-1fa4-4496-9b5a-7b0c818b33bf, describes the incident as impacting customers of the two gambling brands owned by Flutter Entertainment. The report does not specify the date when the breach occurred or how it was discovered. It also does not detail the types of personal information that may have been exposed. The article notes that the breach affected a substantial number of individuals, highlighting the scale of the incident. The source material provides no information about the attackers' methods or motivations. No technical details about compromised systems are included in the report. The article does not mention any regulatory notifications or legal actions taken. It also does not describe any containment or remediation efforts undertaken by the companies. The report concludes with the figure of up to 800,000 affected customers as the primary disclosed fact.

Because the article lacks specifics, the narrative cannot elaborate on the sequence of events, the vulnerability exploited, or the data categories compromised. The absence of details means that any description of detection timelines, incident response actions, or impact assessments would be speculative. Therefore, the only verifiable information from the source is the statement that up to 800,000 Betfair and Paddy Power customers were hit by a data breach. The article’s publication date confirms when this information became publicly available. No further specifics about the breach’s origin, duration, or resolution are provided in the source material. Consequently, the account remains limited to the disclosed scale and the fact of public reporting. The narrative ends here, adhering strictly to the information supplied.

Sources

Sources available to members: 1 source.

CSIDB