It seems we can’t find what you’re looking for. Perhaps searching can help.
Security, Encryption & Data Privacy
GamblScout’s data-driven hub on iGaming security, encryption, GDPR compliance and fraud, covering breach costs, RNG audits and ICO enforcement.

Online gambling platforms sit at the intersection of three high-value data types: financial credentials, government ID documents, and behavioral betting data. That combination makes operators disproportionately attractive targets, and the record is unambiguous. The 2023 ransomware attacks on MGM Resorts and Caesars Entertainment alone produced over $100 million in direct losses and a reported ransom payment, while UK regulators have already reprimanded at least one major bookmaker over unlawful tracking. This hub collects GamblScout's algorithmic analysis of how operators handle encryption, licensing-mandated security audits, data privacy law, fraud detection and game-fairness certification.
Key takeaways
- The 2023 MGM Resorts ransomware attack cost the company more than $110 million, while Caesars Entertainment reportedly paid a negotiated ransom of roughly $15 million after a $30 million demand.
- UK-licensed remote gambling operators must pass an independent annual security audit against sections of ISO/IEC 27001 as a licence condition, not an optional certification.
- The UK ICO can fine operators up to £17.5 million or 4% of global turnover for serious data protection breaches, and has already reprimanded a major bookmaker over cookie-consent failures.
- Account takeover attempts and iGaming-specific fraud losses are both rising faster than the industry's revenue growth, according to fraud-analytics vendors tracking the sector.
- Game-fairness claims rest on separate, verifiable technical standards (GLI-19, ISO-aligned RNG testing) rather than operator marketing copy — a distinction our scoring treats as evidence, not assumption.
Table of contents
What "security" means in iGaming
In a licensed betting or casino context, "security" is not one control but four overlapping obligations that regulators, payment networks and data protection authorities each enforce separately: encrypting data in transit and at rest, verifying that games produce statistically fair outcomes, preventing account takeover and payment fraud, and lawfully processing the personal data collected during KYC and AML checks. An operator can satisfy one of these and still fail another — a site can run modern TLS on its login page while still sharing browsing data with ad-tech partners without consent, which is precisely the failure mode UK regulators have flagged in the sector. This category maps each obligation to the evidence an outside observer can actually check, rather than to marketing language about being "fully secure" or "certified."
The economic backdrop matters here too. As we cover in our analysis of the macro economics of iGaming, the sector's rapid revenue growth is exactly what makes it a rational target for organized fraud rings and ransomware operators — the attack surface scales with the money moving through it.
Encryption and technical security standards
Two technical regimes dominate operator security obligations in mature markets. The first is payment-card security: any operator processing card payments directly is contractually bound by PCI DSS, which imposes strict control requirements that overlap with, but are distinct from, gambling-licence technical standards. The second is the licence-specific security audit. Under the UK Gambling Commission's Remote Gambling and Software Technical Standards, newly licensed remote gambling operators must submit a security audit within six months of being granted a licence, irrespective of whether they are trading. More significantly for ongoing compliance, remote gambling operators must complete a third-party annual security audit against specific sections of the ISO 27001 standard and submit an audit report to the Commission. That audit scope explicitly covers how personal and financial data is collected, encrypted in transit and at rest, access-controlled, retained, and disposed of, meaning "encryption" in a regulatory sense is an auditable control, not a checkbox on a homepage badge.
This is one reason our data-scraping engine looks for evidence of licence status and audit cadence rather than trusting on-page security seals, which are frequently unlicensed or expired.
Data privacy and regulatory obligations
Gambling operators sit under general data protection law in addition to gambling-specific licensing rules, and regulators have made clear the two cannot be used to excuse each other. Under UK GDPR, the ICO can issue fines of up to £17.5 million or 4% of annual worldwide turnover, whichever is higher, for serious infringements. Enforcement against the sector is not theoretical: in September 2024, the ICO issued a reprimand against Sky Betting and Gaming for unlawfully processing people's data through advertising cookies without their consent. The regulator's concern extends beyond that single case — its 2025 initiative explicitly names gambling operators among the sites it is monitoring for tracking-tool misuse, warning that gambling addicts may be targeted with betting ads based on their browsing record when consent controls fail.
The Gambling Commission itself has weighed in on where GDPR and licensing duties intersect, stating plainly that it will not accept licensees simply stating that GDPR means they are unable to comply with an aspect of gambling regulation — for example, using data protection as a defense for weak self-exclusion or AML data sharing. Because privacy enforcement regimes vary sharply by jurisdiction, the regional breakdowns in our regional deep dives track which markets pair strict data rules with strict gambling-harm rules, and which do not.
Fraud, account takeover and breach costs
The clearest illustration of what a security failure costs a listed operator remains the September 2023 attacks on two Las Vegas casino groups. Attackers used social engineering against an IT help desk to breach MGM Resorts' network, and breached MGM's network using social engineering, stole sensitive data, and encrypted over a hundred ESXi hypervisors. In an SEC filing, MGM Resorts said costs from the ransomware hack had exceeded $110 million, including $10 million in one-time consulting cleanup fees, and confirmed hackers had stolen customers' personal information, including names, driver's license numbers and Social Security numbers. Caesars Entertainment, targeted separately around the same time, took a different path: the cybercrime group demanded a $30 million ransom from Caesars, but the company ultimately agreed to pay about half that, according to reporting on the SEC disclosure.
Those figures track with the broader picture from IBM's annual breach-cost research. Globally, the average cost of a data breach fell 9%, from $4.88 million in 2024 to $4.44 million in 2025, largely due to faster AI-assisted containment — but the average cost of a data breach for U.S. companies jumped 9% to an all-time high of $10.22 million in 2025, driven by regulatory fines and escalation costs. Organizations still take a mean of 241 days to identify and contain a breach, the lowest it has been in nine years — still eight months of exposure.
Below the level of a headline breach, day-to-day fraud is a persistent operating cost specific to betting and casino accounts. Fraud-analytics vendors tracking the vertical report that iGaming fraud surged an average 64% year-over-year between 2022 and 2024, and roughly 83% of operators say it's getting worse. Account takeover — where a fraudster uses stolen or leaked credentials to drain a legitimate player's balance — is a specific driver of that trend, and industry estimates put the scale of the wider problem at global account takeover fraud losses reaching $17 billion in 2025, up from nearly $13 billion in 2023.
| Metric | Figure | Source context |
|---|---|---|
| MGM Resorts 2023 ransomware attack, total cost | >$110 million | MGM SEC 8-K filing, reported by SecurityWeek |
| Caesars Entertainment 2023 ransom payment | ~$15 million (of a $30M demand) | Reported via CNBC, sourced to SEC filing |
| Global average data breach cost, 2025 | $4.44 million | IBM Cost of a Data Breach Report 2025 |
| US average data breach cost, 2025 | $10.22 million | IBM Cost of a Data Breach Report 2025 |
| Mean time to identify and contain a breach, 2025 | 241 days | IBM Cost of a Data Breach Report 2025 |
| Max ICO fine for serious data protection breach | £17.5M or 4% of global turnover | UK GDPR enforcement powers |
| Global account takeover fraud losses, 2025 (est.) | ~$17 billion | SEON estimate, via Mitek Systems |
Fair play, RNG and game integrity
Security also covers whether the games themselves behave as advertised. Random number generators used in licensed markets are tested against independent technical standards rather than taken on trust. GLI-19, maintained by Gaming Laboratories International, is widely used across regulated markets: GLI-19 was, on its release, the world's first global interactive gaming standard, and its RNG requirements align closely with UK technical standards even where the UKGC does not mandate GLI-19 by name. Separately, eCOGRA is a London-based agency that inspects online gambling software and systems, with a stated role centered on protecting player rights and guaranteeing fair games. These are the certifications GamblScout treats as verifiable evidence of fairness, in contrast to unverifiable "provably fair" marketing claims that some operators attach to crypto-based games without third-party audit trails — a distinction we return to in our coverage of payments and crypto gambling technology.
How GamblScout scores security
Security signals feed directly into our published scoring framework rather than sitting in a separate "trust" badge. We treat licence status, audit disclosures, RNG certificate references and ICO/regulator enforcement history as objective inputs, weighted alongside the fraud and dispute-handling signals described in our fair play and fraud detection deep dive. Sentiment extracted from player complaints about locked accounts or slow withdrawals — a common downstream symptom of poor fraud controls — is processed using the methods explained in our NLP and sentiment analysis article. The relative importance assigned to each signal is set out transparently in our scoring system and algorithmic weights article, and the underlying rationale for scoring operators algorithmically at all — rather than through paid human reviewers — is covered in our core principles article. Because attitudes toward data collection and identity verification differ by market, we also cross-reference findings against the regional and demographic patterns in our demographics research and the forward-looking risks discussed in our 2026–2030 trends coverage.
Frequently asked questions
Is encryption alone enough to call a gambling site "secure"?
No. Transport encryption (TLS) protects data in transit but says nothing about how an operator stores documents, controls internal access, detects fraud, or complies with data protection law. Regulators evaluate security through audits covering encryption, access control, retention and fraud controls together, not TLS in isolation.
How do I know an RNG is actually fair?
Look for a named independent test lab (such as GLI or eCOGRA) and a standard reference (GLI-19 or equivalent), not just a generic "certified fair" badge. Licensed operators in regulated markets are required to hold these certifications; unlicensed sites often display unverifiable seals.
Does GDPR limit what gambling operators can do for anti-money-laundering checks?
No. The UK Gambling Commission has stated it will not accept GDPR as an excuse for failing to meet AML or self-exclusion duties, since regulators consider necessary processing for these purposes to have a lawful basis independent of consent.
Why are gambling accounts a common account-takeover target?
Betting and casino accounts combine stored payment methods, withdrawable balances and completed KYC verification, letting fraudsters extract funds quickly once they take over an account — a pattern fraud-analytics firms report is growing faster than the industry's overall revenue.
Methodology note
For this category, our algorithm ingests operator licence numbers and jurisdiction, publicly disclosed audit and certification references (ISO 27001, GLI-19, eCOGRA), regulator enforcement notices from bodies such as the ICO and Gambling Commission, and sentiment patterns in player complaints related to account security or withdrawal disputes. These signals are combined with the fraud and payment-security indicators described in our related methodology articles to produce a comparative, evidence-based security score rather than a subjective trust rating.
Gambling involves risk. Only play with money you can afford to lose and use the deposit limits and self-exclusion tools available in your jurisdiction.