Friday, June 19, 2026

Security Boulevard Logo

Security Boulevard

The Home of the Security Bloggers Network

Community Chats Webinars Library
  • Home
    • Cybersecurity News
    • Features
    • Industry Spotlight
    • News Releases
  • Security Creators Network
    • Latest Posts
    • Syndicate Your Blog
    • Write for Security Boulevard
  • Webinars
    • Upcoming Webinars
    • Calendar View
    • On-Demand Webinars
  • Events
    • Upcoming Events
    • On-Demand Events
  • Sponsored Content
  • Chat
    • Security Boulevard Chat
    • Marketing InSecurity Podcast
    • Techstrong.tv Podcast
    • TechstrongTV - Twitch
  • Library
  • Related Sites
    • Techstrong Group
    • Cloud Native Now
    • DevOps.com
    • Security Boulevard
    • Techstrong Research
    • Techstrong TV
    • Techstrong.tv Podcast
    • Techstrong.tv - Twitch
    • Devops Chat
    • DevOps Dozen
    • DevOps TV
  • Media Kit
  • About
    • Sponsor

  • Analytics
  • AppSec
  • CISO
  • Cloud
  • DevOps
  • GRC
  • Identity
  • Incident Response
  • IoT / ICS
  • Threats / Breaches
  • More
    • Blockchain / Digital Currencies
    • Careers
    • Cyberlaw
    • Mobile
    • Social Engineering
  • Humor
Data Security Security Bloggers Network Threats & Breaches 

Home » Security Bloggers Network » Betting, Gambling, and Sports Betting Sites: The Costs of ATO

SBN

Betting, Gambling, and Sports Betting Sites: The Costs of ATO

by Enzoic on September 18, 2024

The online betting and gambling industry is thriving, with the global market expected to grow at a compound annual growth rate of 8.54% until 2027. By the end of 2023, this industry was already worth a staggering $95.05 billion. However, this rapid expansion has brought with it a growing threat: cybercrime. Among the most prevalent and damaging attacks plaguing this sector is fraud, specifically fraud stemming from account takeover, where cybercriminals gain unauthorized access to legitimate users’ accounts, often with devastating financial and reputational consequences.

Account takeovers aren’t just a hassle for users—they pose a serious risk to your entire platform.

Let’s take a closer look at how big this problem is, the financial impact it’s having on the industry, along with actionable advice on what companies can do to protect both themselves and their customers.

What is Account Takeover (ATO)?

Account takeover happens when an attacker gains access to a legitimate user’s account, typically through methods such as phishing, credential stuffing (using leaked usernames and passwords), or exploiting weak security measures like poorly protected passwords. Once inside, these fraudsters can siphon off money, steal personal information, and even use the compromised account to place fraudulent bets or withdraw funds.

This type of fraud is especially prevalent in online betting because of the lower barriers to entry and the sheer volume of funds moving through these platforms. Alarmingly, 4% of all login attempts on gambling platforms in 2023 were attempts at account takeover, highlighting how common this problem has become.

The Appeal of Betting Sites to Cybercriminals

The rise in cybercrime targeting the gambling industry is driven by several factors that make these platforms highly attractive to fraudsters:

  • Rapid Growth and Popularity: The betting and gambling sector has seen exponential growth, reaching billions of dollars in revenue. This rapid expansion makes it a prime target for cybercriminals looking to capitalize on poorly secured platforms.
  • Ease of Access: Online betting platforms are easy to sign up for and often have less stringent security protocols compared to industries like banking. This lowers the entry barriers for both legitimate users and criminals looking to exploit vulnerabilities.
  • High Financial Gain: The potential financial rewards for successful account takeover attacks are significant. Research shows that even inexperienced fraudsters can make up to $20,000 a month, while seasoned cybercriminals can rake in as much as $600,000 monthly.

The Scope of Fraud in the Betting Industry

In 2023, the online gambling and sports betting industry was hit hard by fraud. The Onfido Identity Fraud Report highlighted something these platforms should keep in mind: the fraud rate for gambling companies surged from 4.2% in 2022 to 7.6% in 2023, an 80% increase. This rate far exceeds the fraud levels seen in other industries.

The rise in Dark Web activity related to gambling credentials is another alarming indicator. The volume of compromised gaming credentials available for sale has surged, particularly during major events like the Super Bowl or FIFA World Cup, when betting activity peaks. Cybercriminals often sell these stolen credentials in bulk, enabling other fraudsters to access multiple accounts and carry out more account takeovers.

The Cost of ATO to Betting Platforms

The financial toll of account takeover attacks on the betting industry is staggering. Betting platforms are not only losing money from fraudulent activities but also from the cascading effects these breaches have on their business. Consider the following statistics:

  • 40% of online sports bettors have experienced cyber fraud related to their betting accounts, often due to account takeover incidents.
  • Over 50% of sports betting websites suffered cybersecurity incidents in 2023, with many reporting account takeovers.
  • $1 billion is lost annually by the sports betting industry due to cyberattacks, with ATO playing a significant role.

The damage extends beyond the immediate financial losses. When accounts are compromised, customers lose trust in the platform, often resulting in decreased user retention. 25% of betting customers have had their accounts compromised due to weak password security, which underlines the importance of strong authentication practices.

Why Password Policies and Dark Web Monitoring are Crucial

Account takeovers often begin with compromised credentials. These credentials—combinations of usernames, passwords, and sometimes even personal information—are frequently sold on the Dark Web, where they are purchased by cybercriminals looking to exploit them for profit. Studies have shown that 65% of people reuse passwords across multiple sites. A common way credentials become compromised is through users reusing the same passwords across multiple platforms, including third-party sites. When these third-party sites are breached, the reused credentials are also exposed, leaving users vulnerable across multiple accounts.

This means that a single data breach can have far-reaching consequences, as hackers apply stolen credentials to different platforms in what’s known as credential stuffing attacks.

For gambling platforms to protect their customers and themselves from the dangers of ATO, it is essential to monitor for leaked credentials on the Dark Web and proactively address these vulnerabilities. While it’s helpful to encourage strong password management practices, such as using unique credentials for each platform, the only way gaming platforms can protect themselves is through Dark Web monitoring.

Dark Web monitoring tools scan these illicit marketplaces for compromised credentials, allowing platforms to identify and remediate potential threats before they lead to account takeovers. By alerting users when their credentials have been exposed, operators can prompt users to change passwords and implement additional security measures. This can be implemented without negatively impacting the user experience by simply having them reset their password to a strong, uncompromised password at the next login flow.

Password Hygiene and the Benefits of Dark Web Monitoring for Authentication

In addition to promoting strong password practices, Dark Web monitoring offers a seamless solution to prevent ATO without the friction often associated with multi-factor authentication (MFA). Instead of requiring users to adopt complex authentication methods, platforms can enhance security by automatically checking for compromised credentials every time a user logs in.

Many betting platforms, for example, might avoid implementing MFA due to its impact on user experience, with 60% choosing not to implement MFA. MFA introduces friction by requiring users to authenticate through multiple steps, and while it adds security, it only reduces the chances of an account compromise by around 50%.

Dark Web monitoring, on the other hand, provides a much more user-friendly approach. By continuously scanning the Dark Web for stolen credentials and cross-referencing user login data with known breaches, platforms can quickly identify when a user’s password has been compromised. When such activity is detected, the system can automatically prompt the user to reset their password—without affecting the usual login flow. This ensures users maintain secure access without the additional hassle or disruption caused by MFA.

Enzoic APIs Flow

This proactive approach not only reduces the chances of an ATO attack but also maintains a frictionless experience for users, ensuring high engagement levels while still providing strong security. As attacks become more sophisticated, betting platforms that leverage Dark Web monitoring can protect their systems effectively without sacrificing user experience, thereby minimizing both security risks and the potential financial loss that could arise from a data breach.

While Dark Web monitoring can operate independently to ensure security without disrupting the user experience, it can also be implemented alongside MFA to create a layered defense against cyberattacks. By combining the two methods, platforms can provide even stronger protection for user accounts.

Previously, when they identified a compromised account through location signals, their IT team had to work closely with marketing to notify the affected users, which was a time-consuming process. This also impacted the user experience, as some accounts even had fake bets placed. Since they started using Enzoic, they haven’t experienced any account compromises. While there was internal resistance to implementing MFA, the Splash Sports IT team chose to integrate Enzoic as a solution that wouldn’t introduce hurdles for their users. They’ve seen about a 2-3% hit rate on compromised credentials in the last ~20,000 they’ve tested.

– Enzoic Sports Betting Customer

The Way Forward

Cyberattacks on sports betting platforms cost the industry an estimated  $2.3 billion annually by 2024. Beyond the financial losses, the reputational damage can be even more devastating. When users lose trust in the security of a platform, they are unlikely to return, leading to a long-term decline in user engagement and revenue.

The widespread availability of stolen credentials on the Dark Web means that betting platforms must be vigilant in monitoring for potential threats and educating their users about the importance of secure passwords and authentication measures. Without proper defenses, betting platforms risk not only losing money but also the trust of their users, which can be even more costly in the long run. By implementing strong password security and staying one step ahead of cybercriminals, betting platforms can promise their users a more secure betting experience.

 

AUTHOR


Josh Parsons

Josh is the Product Manager at Enzoic, where he leads the development and execution of strategies to bring innovative threat intelligence solutions to market. Outside of work, he can be found at the nearest bookstore or exploring the city’s local coffee scene.

*** This is a Security Bloggers Network syndicated blog from Blog | Enzoic authored by Enzoic. Read the original post at: https://www.enzoic.com/blog/ato-betting-gambling-and-sports-betting-sites/

September 18, 2024September 18, 2024 Enzoic account takeover, Data breaches
  • ← Navigating the Workplace Violence Threat Management Process 
  • USENIX NSDI ’24 – Making Kernel Bypass Practical for the Cloud with Junction →

Techstrong TV

Click full-screen to enable volume control
Watch latest episodes and shows

Tech Field Day Events

Upcoming Webinars

True Agentic SecOps at Lakehouse Scale
Agentic Software Delivery in 2026: How To Bridge The Gap Between AI Ambition and Delivery Confidence
Untangling the EU Cyber Resilience Act
The Software Supply Chain Just Got Harder to See
Building a Resilient Security Culture in the AI Era with AWS & Datadog

Podcast

Listen to all of our podcasts

Secure by Design

2 weeks ago | Jack Poller

Senator Sanders Wants to Own AI Companies — and Hand America’s Adversaries the Keys

3 weeks ago | Jack Poller

NIST’s Nine: The PQC Signature Race Moves to Round Three

3 weeks ago | Jack Poller

The Quantum Arms Race: Why Washington Just Wrote a $2 Billion Check to Nine Companies

1 month ago | Jack Poller

Beyond Moore’s Law: The Hyper-Acceleration of Autonomous AI Cyber Capabilities

1 month ago | Jack Poller

The Exception Economy: When Security Teams Stop Protecting and Start Negotiating

Press Releases

GoPlus's Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

GoPlus’s Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

Subscribe to our Newsletters

Most Read on the Boulevard

Google Sues Chinese Threat Group Using Gemini AI in Phishing Scams
SailPoint Acquires Entro to Continuously Detect and Monitor Non-Human Identities
Databricks Acquires Cybersecurity Startup Panther Labs to Fortify AI Defense
Ten Great Cybersecurity Job Opportunities
Malwarebytes Finds Ad Scams Hidden in 40+ World Cup Streaming Sites
CVSS Is Officially Dead: What CISA’s BOD 26-04 Means for Everyone
Iranian Cyber Group Handala Claims Cal Water Hack
Claude Fable 5’s pricing makes Sonar Context Augmentation a potent cost lever
CISA to Require Federal Agencies to Patch Some Vulnerabilities Within 3 Days
Claude Fable 5 and Mythos 5 “abruptly disabled” after US gov. ban

Industry Spotlight

NYC Sewers Crawling With Rats and Potential Bad Actors 
Cybersecurity Featured Industry Spotlight Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threats & Breaches 

NYC Sewers Crawling With Rats and Potential Bad Actors 

June 18, 2026 Teri Robinson | Yesterday 0
Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks
Cloud Security Cybersecurity Data Privacy Data Security Featured Incident Response Industry Spotlight Malware Mobile Security Network Security News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threats & Breaches Vulnerabilities 

Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks

April 12, 2026 Jeffrey Burt | Apr 12 Comments Off on Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks
The Day the Security Music Died
AI and Machine Learning in Security Cybersecurity Featured Industry Spotlight Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

The Day the Security Music Died

April 8, 2026 Alan Shimel | Apr 08 Comments Off on The Day the Security Music Died

Top Stories

Job Seekers Make for Vulnerable Targets
Cybersecurity Data Privacy Data Security Featured News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

Job Seekers Make for Vulnerable Targets

June 19, 2026 Teri Robinson | 45 minutes ago 0
MSG Breach: Knicks Take the NBA Championship, ShinyHunters Takes the Data 
Cybersecurity Data Security Featured News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

MSG Breach: Knicks Take the NBA Championship, ShinyHunters Takes the Data 

June 18, 2026 Teri Robinson | Yesterday 0
Trying to Control AI is Like Holding Sand
AI and Machine Learning in Security Cybersecurity Featured News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

Trying to Control AI is Like Holding Sand

June 17, 2026 Alan Shimel | 1 day ago 0

Security Humor

Randall Munroe’s XKCD 'Bottle'

Randall Munroe’s XKCD ‘Bottle’

Download Free eBook

[su_panel border="0px solid #ddd" radius="0" text_align="center" padding-top="0px" padding-bottom="0px"]
The State of Cloud Native Security 2020
[/su_panel]

Security Boulevard Logo White

DMCA

Join the Community

  • Add your blog to Security Creators Network
  • Write for Security Boulevard
  • Bloggers Meetup and Awards
  • Ask a Question
  • Email: [email protected]

Useful Links

  • About
  • Media Kit
  • Sponsor Info
  • Copyright
  • TOS
  • DMCA Compliance Statement
  • Privacy Policy

Related Sites

  • Techstrong Group
  • Cloud Native Now
  • DevOps.com
  • Digital CxO
  • Techstrong Research
  • Techstrong TV
  • Techstrong.tv Podcast
  • DevOps Chat
  • DevOps Dozen
  • DevOps TV
Powered by Techstrong Group
Copyright © 2026 Techstrong Group Inc. All rights reserved.
×

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.