FanDuel says user data possibly stolen in recent MailChimp breach

Phishing
(Image credit: wk1003mike / Shutterstock)

Sensitive data belonging to the FanDuel users was compromised in the recent MailChimp data breach, the of sports betting site has told customers.

An email sent to FanDuel customers confirmed their full names and email addresses were accessed as a consequence of the MailChimp cyberattack, and warning them to stay vigilant against potential phishing attacks. 

"Recently, we were informed by a third-party technology vendor that sends transactional emails on behalf of its clients like FanDuel that they had experienced a security breach within their system that impacted several of their clients," BleepingComputer cited a FanDuel 'Notice of Third-Party Vendor Security Incident'. 

TechRadar Pro needs you! We want to build a better website for our readers, and we need your help! You can do your bit by filling out our survey and telling us your opinions and views about the tech industry in 2023. It will only take a few minutes and all your answers will be anonymous and confidential. Thank you again for helping us make TechRadar Pro even better.

D. Athow, Managing Editor

Passwords are safe

"On Sunday evening, the vendor confirmed that FanDuel customer names and email addresses were acquired by an unauthorized actor. No customer passwords, financial account information, or other personal information was acquired in this incident."

While FanDuel didn’t name the vendor in the notification, it later confirmed to media that it was referring to MailChimp.

The company also added that as this wasn’t a breach of its own internal systems, sensitive information including “passwords, financial account information, or other personal information” was not accessed. 

While just getting people’s names and emails might not be much, it’s enough for a phishing attack which could be more devastating, and could result in people losing access to valuable accounts, private data, and possibly even money from their devices and endpoints. Now, FanDuel is warning its users to keep both eyes open:

"Remain vigilant against email "phishing" attempts claiming an issue with your FanDuel account that requires providing personal or private information to resolve the problem," the notification further claims. "FanDuel will never email customers directly and request personal information to resolve an issue."

FanDuel also urged its customers to regularly update their passwords, and to make sure those passwords are strong and not used on other platforms at the same time. Furthermore, it told everyone to activate multi-factor authentication (MFA) if they hand’t already done so.

Via: BleepingComputer

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Avast cybersecurity
Zapier tells customers their data may have been accessed
Smartphone with new logo X twitter app background. Application twitter old blue bird change X black and white new.
Phishing campaign targets prominent X users, accounts at risk
A person holding a credit card in one hand while typing on a laptop keyboard with the other.
Green Bay Packers online store used to steal fan credit card details
Someone holding a passport with two boarding passes inside it
Top digital loan firm security slip-up puts data of 36 million users at risk
Data leak
Top collectibles site leaks personal data of nearly a million users
A man looking at a tablet with a brown Best Buy package on the desk in front of him
Huge Christmas data breach - 14 million shipping records leaked, putting shoppers at risk
Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring