Cyber Incident Victim: Gatherwell Limited
Date:
Nov 2023
Location:
United Kingdom
Summary
A data breach impacted direct debit users of the Havant Borough Community Lottery, managed by Gatherwell Limited. The incident originated from a cyber attack targeting third-party payment processor London & Zurich, which handled direct debit collections for the lottery, while Gatherwell's own systems remained unaffected. Only supporters who enrolled in direct debit services before early November were compromised, with no exposure for participants using alternative payment methods.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On December 1, 2023, Gatherwell Limited, the regulated lottery manager operating Havant Borough Community Lottery on behalf of Havant Borough Council, was notified of a data security incident. The breach specifically affected customers who had enrolled in direct debit payment services for the lottery on or before November 8, 2023. Investigations revealed the compromise originated from a cyber attack targeting London & Zurich (L&Z), a third-party payment processor contracted by Gatherwell to handle direct debit collections. Gatherwell confirmed its own lottery management systems remained unaffected by the intrusion. The attack vector and nature of unauthorized access to L&Z's systems were not disclosed in public communications.

The incident exclusively impacted individuals using direct debit payments for lottery entries, with no risk exposure for customers utilizing alternative payment methods. Havant Borough Council emphasized this distinction in its public notification, directing affected parties to a dedicated informational resource via hyperlink. No specifics regarding the compromised data categories—such as financial details, contact information, or personal identifiers—were disclosed. Similarly, the council’s communication did not quantify the number of affected customers or describe containment measures implemented by L&Z or Gatherwell. The public advisory focused on confirming the breach’s origin, delineating its scope, and directing impacted users to official channels for further guidance.
