1win Data Breach (2024)
If you are a customer of 1win, here’s what’s now in circulation.
In November 2024, the online betting platform 1win suffered a data breach that exposed 96M users. The exposed data included email and IP addresses, phone numbers, dates of birth, country and SHA-256 password hashes.
1win customer?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
On November 2, 2024, online betting platform 1win appeared in a major breach notification after 96.2 million user records surfaced. The incident exposed sensitive personal details including email addresses, phone numbers, dates of birth, geographic locations, IP addresses, and SHA-256 password hashes. Anyone who has ever placed a bet or created an account on the site should assume their information is now circulating among threat actors.
Confirmed Breach Details
The disclosure on Have I Been Pwned states that the 1win breach occurred in 2024 and contains 96.2 million affected records. Exposed data types explicitly listed are dates of birth, email addresses, geographic locations, IP addresses, passwords stored as SHA-256 hashes, and phone numbers. The notification does not specify the initial attack vector, whether the data was exfiltrated through a ransomware operation, or if any extortion demand was made. It also does not confirm whether the company itself notified users directly.
Passwords hashed with SHA-256 remain vulnerable to offline cracking, especially for users who chose weak or common passphrases. The presence of phone numbers, dates of birth, and geographic locations further increases the risk of targeted follow-on attacks.
Why This Matters for You and Your Family
If you or anyone in your household has used 1win, your real-world identity is now easier to link across services. Threat actors routinely combine breached email addresses with phone numbers and dates of birth to impersonate victims, reset accounts on banking or government sites, or launch convincing phishing campaigns. Children or teenagers who share a family email or phone number for gaming or social accounts can quickly become collateral targets once the primary breach record is sold or posted.
Advertisement
BATECH StudioWe build it.We run it.Web apps, AI pipelines and internal tools — under your brand, not ours.Tell us what you need →
BATECH Studio and GalaxyWarden share common ownership.
The exposure of IP addresses and geographic locations lets attackers map your approximate home area, making physical stalking or localized scams more feasible. Even if you no longer use the betting site, the data retains long-term value on underground markets where it can be bundled with other leaks and resurfaced years later.
Doxxing and Identity-Chain Risks
Once an attacker possesses your email, phone number, date of birth, and password hash from the 1win breach, they can begin building an identity chain. A cracked password often re-used on other platforms leads to account takeovers. Those compromised accounts then reveal additional handles, friends lists, or linked gaming profiles. The cycle accelerates when threat actors sell or trade the enriched dataset, turning a single breach into persistent harassment or financial fraud against you and your family.
Gaming accounts belonging to children are particularly vulnerable in these chains because parents frequently reuse credentials or recovery phone numbers across betting, shopping, and gaming services. A single leak like this can cascade into doxxing that exposes home addresses, family relationships, and real-time location data derived from IP history.
What to Do
- Run a DoxxScan to map every link between your handles, emails, phone numbers, and real identity, then use the cleanup of Warden to remove what you can.
- Rotate the password used at 1win anywhere it is reused and immediately enable 2FA through an authenticator app rather than SMS.
- Enable continuous DoxxScan monitoring across 13.1B+ breach records and 100+ platforms so the next exposure of your data is caught in hours, not months.
- Cover the household with DoxxScan family coverage that extends to dependents and children's gaming accounts that often chain back to the same address or phone number.
- Let remediation specialists handle takedown requests across data brokers and leak sites for you while you focus on securing active accounts.
The 1win breach is a reminder that betting and gaming platforms remain high-value targets precisely because users often treat them with lower security standards than banking apps. A forward-looking approach means treating every credential leak as the start of an identity chain rather than an isolated event. DoxxScan by GalaxyWarden provides continuous monitoring across 13.1 billion+ breach records and more than 100 platforms, AI-powered identity-chain mapping, hands-on remediation by specialists, and full household coverage that includes children's gaming accounts at risk of cascading takeovers.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
For security and vendor-risk teams: a staff address in a leak does not mean you were breached — it usually means a third party was. We monitor a domain against 13.1B+ leaked records and tell you when one of your people appears. See what we would check →
Report details & sourcing
Related breaches
Match Group (Tinder, Hinge, OkCupid) Data Breach — January 2026
ShinyHunters claimed responsibility for stealing over 10 million Match Group user records in early 2…
149 Million Credential Mega-Exposure — January 2026
Security researchers discovered a publicly exposed 96 GB database with 149 million unique logins cov…
Under Armour 72M Customer Email Dataset Resurfaces — January 2026
72 million user emails from a prior Under Armour breach were reposted publicly in January 2026, ampl…