/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

How hackers stole 8.1M user records by breaching two gambling payment processors, Moneybookers and Neteller, in 2009 and 2010

How Hackers Breached Two Gambling Payment Providers To Harvest ‘Millions’ Of Records  —  In 2009 and 2010 two separate attacks hit widely-used online gambling payments processors Moneybookers and Neteller. Thanks: @iblametom

Forbes Thomas Fox-Brewster

Context & Ripple Effects

This Forbes retrospective lands inside a corpus where payment intermediaries keep showing up as the soft spot in the financial stack: PayPal disclosed a December 2022 credential-stuffing attack touching ~35K users, Amazon admitted money was siphoned from ~100 seller accounts over six months, and a phishing-and-malware crew pulled more than $15M out of Eastern European banks. The Moneybookers and Neteller breaches are an early, large data point in that same pattern — attackers going after the processor rather than the bank or the merchant.

What makes the 2009–2010 thefts still relevant is where the records go next. Stolen username-password pairs don't stay still: they accumulate into the tradeable stockpiles seen when hackers began distributing Collections #2-5, some 25 billion credential records, and they circulate through markets like the one Troy Hunt exposed when the Carding Mafia card-trading forum itself was hacked, unmasking ~300K of its users. An 8.1M-record gambling-payments trove is exactly the kind of inventory that feeds that pipeline.

First-order effects

  • Users of Moneybookers and Neteller whose records were among the 8.1 million stolen faced direct account-takeover and fraud exposure on payment accounts linked to their gambling activity.
  • Both processors carried the reputational cost of the attacks resurfacing publicly years after the fact, long past the window when customers could be individually warned.

Second-order effects

  • Harvested email-and-password pairs from breaches like these feed the credential-stuffing playbook PayPal later fell victim to, where reused logins gave hackers access to addresses and social security numbers.
  • Stolen records become resale inventory, and the corpus shows that secondary market scaling from small forum trades into gigabyte-scale public dumps — every processor breach quietly restocks it.

Third-order effects

  • Because payment processors sit between banks, merchants, and end users, a single intermediary breach propagates far beyond its own customer base wherever credentials were reused — making intermediaries de facto single points of failure in consumer finance.
  • If the pattern holds, the industry's center of gravity shifts from defending individual accounts to securing and disclosing failures at the processing layer, since that is where millions of records change hands in one incident.

The trend: Attackers increasingly bypass banks and merchants to strike payment processors directly, turning each intermediary breach into raw material for the broader credential-trading economy.