
PokerStars, the largest real money online poker site in the world, said it suffered a significant data breach as a result of the Clop ransomware group exploiting a zero-day vulnerability in the MOVEit Transfer web application.In a recent filing with the office of the Attorney General of Maine, TSG Interactive US Services Limited, the company running the poker site, said that like several other organisations, it used the MOVEit Transfer application to send and receive files securely and became a victim as a result of the Clop ransomware group exploiting a zero-day vulnerability in the application.The company said that after it was notified by Progress Software about the exploitation, it launched an internal investigation to understand whether the incident had any impact on its internal network and whether any data was accessed by the threat actors.PokerStars’ investigation revealed that threat actors infiltrated its network between May 30 and May 31 and accessed certain files that contained the sensitive personal information of its customers. The compromised information included customers’ names, Social Security numbers, addresses, and more.“Following the incident, we no longer utilize the MOVEit Transfer application,” PokerStars said.The filing also confirms that at least 110,291 individuals were affected by the data breach. While the company has no evidence of any misuse of the compromised data, the possibility of the same cannot be ruled out. TSG Interactive US Services Limited is providing all affected individuals with 24 months of complimentary identity theft protection and credit monitoring services.Last week, 1st Source Bank, a leading financial service company based in South Bend, Indiana, said it suffered a significant data breach as a result of the Clop ransomware group exploiting a zero-day vulnerability in the MOVEit Transfer web application.1st Source Bank said threat actors infiltrated its network on the 9th of July and accessed confidential information of some of its commercial and individual clients. It soon launched an internal investigation with assistance from cyber security experts to understand the nature of the compromised information.In a filing with the office of the Maine Attorney General, the financial services company said that the sensitive personal information of about 450,000 clients and employees was compromised as a result of the security incident. The compromised information included names, dates of birth, Social Security Numbers, driver’s licenses, state identification card numbers, and other government identification numbers.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543