Betfair Account Recovery System Flaws Raise Alarms

Submitted by Aaron Goldstein on

Written by :

Aaron Goldstein

Published on :

Betfair, Europe’s largest betting exchange, has reassured its customers that it is fixing issues uncovered with its account recovery system.

A major security flaw was detected by users in recent days.

From the Register:

The alarm was raised with Betfair after people found that the account reset procedure for users with less than £100 in their account was simply to provide data such as the account name and holder's date of birth, neither of which are particularly hard to find out.

No additional means of authentication would have been required for an attacker to gain access to a user's account.

The Register goes on:

Betfair's T&C states that its users are "solely responsible for the security and confidentiality of [their] account. In particular, [they] agree to keep their username, password and/or TAN strictly confidential."

However, during registration, users are not offered the option of entering a username. Instead, customers have their email addresses automatically selected as their usernames.

- Aaron Goldstein, Gambling911.com

 

 

Related Content

Spiked drink

MGM Settles Vegas Ketamine-Spiking Lawsuit Filed By Super Agent: Says He Lost $2 Million Gambling

Neither party is disclosing the sum involved as part of the confidential settlement
The Lost Book of Mummy’s Curse Slot

Where Can I Find The Lost Book of Mummy’s Curse Slot Online?

The Lost Book of Mummy’s Curse slot was set to debut April 22, 2026
Empty pockets

Slow Pay, No Pay Jazz Sports Still Sending Out Bonus Emails

Despite not paying some customers, Jazz Sports continues to email customers about 100 percent re-up bonuses
Hard Rock Bet jackpots

Hard Rock Bet Casino's Jackpot Tops $1 million in New Jersey

The site promotes $5,000 jackpots daily in the only other state it has an online casino, Michigan.