Data breach
1Win
- Records
- 96,544,764
- Breach date
- 1 January 2024Estimated
- Added
- 13 January 2025
What was exposed
5 types of data · 4 more reported · 1 puts you at serious risk
- Email addresses96,510,809
- IP addresses96,205,309
- Phone numbers76,482,492
- Usernames1,754,450
- Passport numbers36,967
- PasswordsReported, not counted
- NamesReported, not counted
- Dates of birthReported, not counted
- Account balancesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
A massive data theft at the online betting platform 1win exposed records tied to roughly 96 million accounts, Which indexes the incident at 96,544,764 rows. The stolen data began circulating on hacking forums in early November 2024, and reporting by CyberInsider traced the leak to a hacker using the alias "fe0dor," who uploaded a large archive of 1win database records to the Exploit.in forum. The same report says a Telegram channel allegedly managed by the company's CEO confirmed that part of the database had been exposed.
Breach Timeline
November 2, 2024: Mozilla Monitor records this as the date of the 1win breach.
November 7, 2024: Reports of the leaked data surfaced in media outlets and Telegram channels, according to CyberInsider, which also reported that a user on the BreachForums site released the database for free download.
February 3, 2025: Mozilla Monitor lists the date the breach was verified and added to its database.
What Information Was Compromised?
Our analysis found the following data types in this breach: IP addresses, email addresses, phone numbers, nicknames, and passport data.
Reporting on the leaked archive additionally described usernames, full names, dates of birth, geographic locations, account balances, and password hashes, per CyberInsider and Mozilla Monitor.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The exposure of email addresses and phone numbers alongside location data gives scammers material for convincing phishing messages that appear to come from a betting platform the victim actually used. If password hashes are cracked, attackers may try the resulting passwords on other sites where victims reused credentials. For the individuals whose passport data appears in the indexed records, the risks are more serious, since identity documents can support fraud and impersonation. Anyone who registered on 1win before the leak surfaced should treat unexpected betting-related emails or messages with caution, as German reporting by heise online noted.
What Is 1Win Doing in Response?
According to CyberInsider, a 1win Telegram channel allegedly managed by the company's CEO confirmed the breach shortly after initial reports, acknowledging that part of the database had been exposed and affected roughly 100 million users. The company also said the attackers had attempted extortion: the initial demand was reportedly $1 million, which escalated to $15 million during negotiations. When 1win refused, the attackers began releasing portions of the database. The company reportedly did not pay.
What Should You Do If You Were Affected?
If you had a 1win account, change your password there and anywhere else you used the same one. Turn on multi-factor authentication wherever the service offers it. Watch for phishing emails or messages that reference betting, your account, or your personal details, and avoid clicking links in them. Monitor your accounts for unauthorized logins or transactions. If your passport or identity document data was involved, consider monitoring for signs of identity fraud, such as accounts opened in your name.
