BCLC announced on Thursday, August 1st, that a recent incident may have resulted in passwords getting leaked from other sources, potentially affecting their online platform for gambling and lottery, PlayNow.
According to BCLC, some passwords have been stolen from other companies’ sites, and this has impacted a small percentage of PlayNow accounts.
On July 24th, PlayNow said they detected an unusually high volume of user traffic on the site.
Following this discovery, they say the traffic was the result of ‘credential stuffing’.
Credential Stuffing is when criminals attempt to access accounts using email addresses and passwords previously exposed or stolen from other sources.
This works on the notion that many people use the same email and password on multiple websites.
“This is a deeply concerning incident and a cautionary tale for everyone with multiple online accounts,” says Pat Davis, BCLC President and CEO.
“Our investigation remains ongoing, and we have found no evidence that our systems have been compromised, or that player login information was stolen from our systems.”
BCLC says that as soon as they determined what took place, PlayNow notified all impacted users and is taking measures to block suspicious activity.
PlayNow is reportedly still investigating the matter.
See also:
- Province urges British Columbians to remain vigilant as wildfire risk remains high
- Unhoused people in Victoria left with only three parks for overnight sheltering
Since the breach, BCLC has informed all necessary organizations, including the Office of the Information and Privacy Commissioner of BC, the Office of the Privacy Commissioner of Canada and BC Gaming Policy and Enforcement Branch.
“Integrity and security are at the core of our business and our games,” said Davis.
“We are committed to continuing our ongoing evaluation and enhancement of PlayNow security controls to maintain the safety of our players’ information going forward.”
To mitigate additional accounts being breached, PlayNow is urging users to change their passwords on the platform as a precautionary measure.
Additionally, users are being asked to consider if they need to change passwords on other accounts of theirs.











