Privacy settings

We use a number of cookies on our website. Some are essential, while others help us improve our portal for you.

Privacy settings

Here is an overview of all the cookies we use. You can choose to accept whole categories or view more information and select only certain cookies.

Essential (6)

Essential cookies enable basic functions and are necessary for the website to function properly.

Statistics (3)

Statistics cookies collect information anonymously. This information helps us to understand how our visitors use our website.
If the statistics cookies are subsequently deselected, they will remain on the computer until the expiry date. However, they are neither updated nor evaluated.

Online Casinos in general: Hacker attack on Merkur Bets (Page 15)

Topic created on 14th Mar. 2025 | Page: 15 of 22 | Answers: 319 | Views: 25,213
andjoker
Amateur
is it enough to submit a request to protectra once and it applies to the whole Merkur Group or do I have to submit a separate request to protectra for the other two casinos (Slotmagie, crazybuzzer)? I am affected everywhere...

This post has been translated automatically

slotliebe89
Elite

andjoker wrote on 21.03.2025 at 17:02: is it enough to submit a request to protectra once and it applies to the whole Merkur Group or do I have to submit a separate request to protectra for the other two casinos (Slotmagie, crazybuzzer)?! I am affected everywhere...

As there are 3 different casinos, you can probably submit a separate application for each one. Why don't you ask Protectra?

This post has been translated automatically

slotliebe89
Elite
Just received from Merkur.

Excerpt:

However, the data was not readily accessible, but required a particularly high level of expertise along with the circumvention of various security measures. According to our current state of knowledge, no other unauthorized third parties apart from the white-hat hacker were able to access the data. The white-hat hacker has not expressed any intention to pass on or misuse the information obtained.

This post has been translated automatically

Blackhawk030
Visitor
Hi does anyone have the same problems? that you can't Deposit at Jeton thanks.

This post has been translated automatically

frapi07
Elite

slotliebe89 wrote on 22.03.2025 at 09:54: Just got it from Merkur.

Excerpt:

However, the data was not readily accessible, but required a particularly high level of expertise along with the circumvention of various security measures. As far as we are currently aware, no other unauthorized third parties apart from the white-hat hacker were able to access the data. The white-hat hacker did not express any intention to pass on or misuse the information obtained.

Nevertheless, she has seen and even analyzed the data. She is not allowed to do so, or the company must obtain the players' consent. You just want to limit the damage by writing that no damage has been done and that the hacker has no bad intentions.

This post has been translated automatically

slotliebe89
Elite
frapi07 wrote on March 22nd, 2025 at 10:06 am:

She saw the data anyway and even analyzed it. She's not allowed to, or the company has to get the players' consent. You just want to limit the damage by writing that no damage has been done and the hacker has no bad intentions.

At least you have now admitted that unauthorized third parties had access. Something that was denied in the first email.

Above all, it was apparently very easy to access the data. High security precautions, my ass.


This post has been translated automatically

Zockerbernd
Amateur
we would like to inform you that we, Jokerstar GmbH, detected a criminal cyber attack on the login interface of the Jokerstar online casino website on March 20, 2025. We would like to expressly point out that no data was leaked from Jokerstar, but that the attack may have an indirect impact on your player account or user account.
At Jokerstar GmbH, data protection and data security have the highest priority. As a responsible company that also takes the protection of its customers seriously, we see it as our duty to inform you about this incident for your own protection.
What has happened?
On 20.03.2025, a cyber attack was carried out on the password reset function of the login page for players.
Triggering this function started an automated process that sent a system-generated password reset email to the validated email address.
To use the function, an e-mail address must be entered in the input field. Based on the analysis of the entries and the rapid sequence in which email addresses were entered, we were able to determine that a script was being used. The script also entered e-mail addresses that are not registered with Jokerstar. We are therefore certain that the hacker used an e-mail address database that was available to him from external sources.
Which data and systems are affected? What consequences are to be expected?
Only the password reset function on the player login page was used. Direct access to your data via the Jokerstar systems can be ruled out.
Please note:
We would like to expressly point out that the hacker does not have direct access to your data by using this function.
Digression: From our point of view, the sole use of the password reset function does not make sense for the hacker, as the hacker would have to have access to the registered e-mail account (with GMX, WEB.de, T-Online, etc.) for the attack to be successful. It cannot be ruled out that your e-mail account or even your own system (PC, notebook, smartphone) may already be or have been compromised independently of this process.
The previous and next steps of Jokerstar GmbH:
The hacker's IP address has been blocked so that the Jokerstar games page can no longer be accessed from it.
We have temporarily deactivated the password reset function.
Jokerstar GmbH will soon file a complaint against unknown persons and has already filed a report with the Central Contact Point for Cybercrime (ZAC) at the LKA BW.
What you can do now:
As a general rule, pay particular attention to messages and emails that seem unusual to you - for example due to typos in the text or the sender's email address.
You should not respond to the password reset email and reset your password not . The hacker has not gained access to your password at Jokerstar. Theoretically, you are only at Risk if your registered, private email account is compromised at the same time.
Further information and recommendations on data security can be found on the websites of the Federal Office for Security and Information Technology and the Federal Criminal Police Office.
Yours sincerely
Jokerstar Compliance Team

This post has been translated automatically

Zockerbernd
Amateur
Now of course I wonder which email database the hacker used to start this mass password reset with the script. Actually, my email hasn't been in any dump yet

This post has been translated automatically

Druff
Amateur
I was affected by the "attack" at SlotMagie, Merkurbets and Crazybuzzer.

I am also registered with the same one at Jokerstar, and have not received an email from Jokerstar about password resets, so it speaks against your theory and seems to come from a different database.

This post has been translated automatically

Zockerbernd
Amateur

Druff wrote on 22.03.2025 at 10:57 am: I was affected by the "attack" at SlotMagie, Merkurbets and Crazybuzzer.

Am also registered with the same at Jokerstar, and have not received an email from Jokerstar about password reset, so it speaks against your theory and seems to be from a different database.

That's good information, thank you.

This post has been translated automatically

WithoutWings
Expert
And today I received another password reset mail from Jokerstars ...the second within a few days

This post has been translated automatically

Toastbrot
Experienced
Heise has also written an article about it with further information

https://www.heise.de/news/Weitere-Online-Casinos-nach-Datenpanne-offline-10325501.html


I would like to quote Wittmann's last sentence from the Heise interview in which she takes stock of the whole story:

"They didn't give a damn about the security of the players' data"

This post has been translated automatically

Pneumatic
Top Member
Yesterday I also took part in protectra with all 3 casino providers ✌🏻

This post has been translated automatically

gamble1
Icon

Pneumatic wrote on 23.03.2025 at 22:24: Yesterday I also participated in protectra with all 3 casino providers ✌🏻

Were you actually informed about the leak by all three providers separately by e-mail?

This post has been translated automatically

Pneumatic
Top Member

gamble1 wrote on March 23rd, 2025 at 11:00 pm:

Were you actually notified of the leak by all three providers separately via email?

Yes exactly, I received 3 emails from 3 different casinos ✌🏻

This post has been translated automatically

Hot Topics16th Apr. 2025 at 07:51 pm CEST

Community Forum-Moderators

Members who assist the GJ team in moderating the forum.
Profile picture of AndreAndre
Profile picture of gamble1gamble1
Profile picture of Langhans_innenLanghans_innen
Profile picture of SaphiraSaphira
GambleJoe is aimed exclusively at user whose allowed to play legally with his current location in online casinos and does not violate the current law.
It is the responsibility of the user to inform himself about the current legal situation. Gambling is prohibited for children and adolescents under the age of 18.
GambleJoe is a registered trademark with the EUIPO of GJ International Ltd.

© 2012-2025 GambleJoe.com

Forgotten your password?

Create a new password here

  • 1. Fill in the 3 fields carefully and click on the green button
  • 2. Check your email inbox for a message from GambleJoe
  • 3. Click on the confirmation link in the email and your new password will be active immediately