PokerStars US notifies 110,291 people of MOVEit related data theft
- Organization
- TSG Interactive US Services Limited (PokerStars)
- Exploit
- Supply Chain Attack
- Industry
- Online Gaming
TSG Interactive US Services Limited, the entity that runs PokerStars in the United States, began notifying customers and employees in July 2023 that their personal information had been copied during the MOVEit Transfer campaign.
The company said unauthorized parties accessed data held in the file transfer application between May 30 and May 31, 2023, exploiting a zero day flaw in Progress Software's MOVEit product. PokerStars said it learned of the vulnerability on June 2, promptly disabled access to the affected application and brought in outside forensic specialists.
Breach notices filed with state regulators, including the Maine Attorney General's office, put the number of affected people at approximately 110,291, among them nine Maine residents. The exposed data included names, addresses and Social Security numbers belonging to both customers and employees. PokerStars operated in New Jersey, Michigan and Pennsylvania at the time.
Notification letters went out on July 20, 2023. The company offered affected individuals 24 months of complimentary Experian identity monitoring, notified law enforcement and said its services continued to run normally. The Clop extortion group was widely reported to be behind the wider MOVEit campaign, though PokerStars did not publicly attribute the incident.