CSIDB logo
Incident

Gatherwell Limited

Incident posture

Attack window
Nov 2023
Location
United Kingdom
Status
Historical
CIA posture
Available to members
Updated
2026-01-05 21:48

Linked entities

Victim
Gatherwell Limited
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Nov 2023
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A data breach impacted direct debit users of the Havant Borough Community Lottery, managed by Gatherwell Limited. The incident originated from a cyber attack targeting third-party payment processor London & Zurich, which handled direct debit collections for the lottery, while Gatherwell's own systems remained unaffected. Only supporters who enrolled in direct debit services before early November were compromised, with no exposure for participants using alternative payment methods.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On December 1, 2023, Gatherwell Limited, the regulated lottery manager operating Havant Borough Community Lottery on behalf of Havant Borough Council, was notified of a data security incident. The breach specifically affected customers who had enrolled in direct debit payment services for the lottery on or before November 8, 2023. Investigations revealed the compromise originated from a cyber attack targeting London & Zurich (L&Z), a third-party payment processor contracted by Gatherwell to handle direct debit collections. Gatherwell confirmed its own lottery management systems remained unaffected by the intrusion. The attack vector and nature of unauthorized access to L&Z's systems were not disclosed in public communications.

The incident exclusively impacted individuals using direct debit payments for lottery entries, with no risk exposure for customers utilizing alternative payment methods. Havant Borough Council emphasized this distinction in its public notification, directing affected parties to a dedicated informational resource via hyperlink. No specifics regarding the compromised data categories—such as financial details, contact information, or personal identifiers—were disclosed. Similarly, the council’s communication did not quantify the number of affected customers or describe containment measures implemented by L&Z or Gatherwell. The public advisory focused on confirming the breach’s origin, delineating its scope, and directing impacted users to official channels for further guidance.

Sources

Sources available to members: 1 source.

CSIDB