Oddschecker Data Breach Confirmed: User Credentials at Risk of Cyber Attack
AI-GENERATEDPopular comparison site Oddschecker confirms a security incident involving user passwords and birthdays. Reports show 34.7% of high-risk sites are gambling platforms.
The online betting industry is facing another major security challenge as Oddschecker, the prominent odds comparison platform, has officially confirmed a data breach. In an era where digital trust is a currency of its own, this incident impacts a service that serves as a vital hub for millions of sports bettors. FairPlay Sports Media (FPSM), the parent company, notified affected users this week about an IT security incident that compromised a specific segment of their internal systems.
This news arrives as the gambling sector remains under intense scrutiny. Cyber attacks have become a frequent occurrence in the betting and gaming space. Criminals recognize these platforms as goldmines for personal profiles containing sensitive financial data and identity markers. While Oddschecker stated that its services continue to operate normally, the loss of reputation often outweighs technical downtime. Users are being urged to change their passwords not just on Oddschecker, but across all platforms where they might have reused the same credentials.
Numbers and facts
The scale of the breach is reflected in the type of data stolen. According to notifications sent to users, the compromised information includes names, contact details, dates of birth, and passwords. The vulnerability of this specific sector is underscored by external experts. An analysis conducted earlier this year by ScamInfo.ai, which examined over 7,185 websites, revealed that more than 34.7% of sites identified as a "critical risk" belonged to the betting and gambling industry. This explains why portals like Oddschecker are such prime targets.
Historical precedents show that even industry giants are at risk. In July last year, Paddy Power and Betfair, both owned by Flutter Entertainment, were victims of a large-scale cyber attack. Similarly, BetMGM, the joint venture between Entain and MGM Resorts International, disclosed in 2022 that several patron records had been illegally obtained. These cases prove that even companies with massive cybersecurity budgets are not immune to professional hackers.
Background
Management at FairPlay Sports Media is currently focused on damage control. A spokesperson told the media that they are working closely with leading external IT specialists to resolve the situation. The goal is a comprehensive investigation and a strengthening of security protocols to prevent future incidents.
"We recently identified, contained and resolved an IT security incident involving a limited part of our systems. This did not disrupt our usual services and we continue to operate as normal. We are liaising closely with our users, partners and the relevant authorities." - Spokesperson, FairPlay Sports Media (FPSM)
Although the company claims there is no evidence of data being misused so far, the threat of phishing remains high. Criminals often wait months before using stolen email addresses and names to craft convincing fraudulent messages. Therefore, reporting the incident to data protection authorities like the UK Information Commissioner’s Office (ICO) was a critical legal requirement.
Why it matters for German players
For German users utilizing international comparison sites, this breach serves as a serious warning. In Germany, the State Treaty on Gambling 2021 (GlüStV 2021) strictly regulates data security and player protection requirements. Those playing at a German-licensed provider benefit from oversight by the Gemeinsame Glücksspielbehörde der Länder (GGL). This authority maintains a "whitelist" of companies that meet the highest security standards.
A key feature of the German system is the connection to LUGAS, the cross-state gambling supervision system. This system ensures that the monthly deposit limit of 1,000 euros is enforced across all providers, protecting players from overspending. Additionally, Germany enforces a strict 1-euro-per-spin limit on virtual slots. Data breaches like the one at Oddschecker demonstrate how vital it is to only share data where state regulation under German law applies. If data leaks from an unlicensed affiliate or bookmaker, German customers have little legal recourse within their home jurisdiction.
What it means for GGL-licensed casinos
For operators holding a GGL license, this incident reinforces the importance of their strict mandates. The GGL requires licensees not only to protect players from addiction but also to safeguard their IT infrastructure. German providers must prove that customer data is stored securely and that financial transactions are tamper-proof. While international platforms might operate with looser rules in regions like Curacao, the German model is designed for maximum control.
Casinos with a German license are required to undergo regular IT audits. A data leak similar to those seen at Oddschecker or Betika in Kenya (where WhatsApp communications were compromised in June) would trigger immediate investigations by the GGL. For players, this means security is not just a bonus but a legal prerequisite. It is highly recommended to choose betting providers exclusively from the official whitelist, where personal data is protected by the strict provisions of the GlüStV 2021.
Frequently asked questions
What data was stolen in the Oddschecker attack?
According to FairPlay Sports Media, the breach involved personal information such as names, contact details, dates of birth, and passwords. However, the company emphasizes that there is currently no evidence of data being misused for phishing.
Do users need to change their passwords now?
Yes, the company has urged all affected customers to reset their passwords immediately. It is also highly recommended to update these passwords on other websites to prevent potential damage from credential-stuffing attacks.
How common are cyber attacks in the gambling industry?
Such incidents are very common as the industry processes massive amounts of valuable data. A study by ScamInfo.ai shows that 34.7% of all critical-risk websites on the internet are related to betting and gambling.
Are German online casinos safer from such attacks?
Providers with a GGL license must follow the strictest IT security standards under the State Treaty on Gambling 2021. Through regular audits and state supervision in Germany, the protection level for personal data and deposits is significantly higher than on unregulated or foreign platforms.
Share
About the author

Lisa Lustich
Editor-in-chief & casino tester
Lisa Lustich has been testing German-language online casinos since 1997 and runs the Lustich.de newsroom. More than 400 published reviews, certified player-protection advisor (BZgA training, 2019).
All articles by Lisa Lustich →Sources & further reading
- Joint Gambling Authority of the German Federal States (GGL): gluecksspiel-behoerde.de
- Whitelist of permitted online operators: GGL-Whitelist
- BZgA problem-gambling helpline: 0800 1 372 700 (free, anonymous, 24/7)
- Editorial methodology: Editorial guidelines Lustich.de
Gambling can be addictive. Please play responsibly. Help and counselling at 0800 1 372 700 (BZgA, free & anonymous).
Read this article in 9 languages
Related topics
Further Reading
AI-GENERATEDSBC Summit 2026: New Global Payment Compliance Track Added for Lisbon Event
The SBC Summit in Lisbon expands its 2026 agenda to include a dedicated track for global payment compliance and anti-money laundering strategies.
AI-GENERATEDCrypto.com Debuts Tokenized Stocks: 24/7 Trading for 1,500 U.S. Equities
Crypto.com has launched tokenized assets, granting users access to 1,500 U.S. stocks and ETFs with a minimum investment of just $1.
AI-GENERATEDSS Lazio and Polymarket Mutually Terminate Sponsorship Due to Regulatory Shifts
SS Lazio and crypto platform Polymarket have ended their deal early. Remarkably, Polymarket will still pay the full contract amount for the 2026/2027 season.










