- Joined
- May 13, 2020
- Location
- Scotland
Sorry double post, just figuring out this multi quote thing 
Hello @Calvino,Yep pretty much!
I only ever use PayPal to deposit/withdraw. I don't have a bank account linked to my account.
My money was withdrawn to a Lloyds bank account from what I could see.
In hindsight I wish I had taken some screenshots.
I also noticed my account had been accessed via a PC. I only play on my android mobile.
Hopefully these details work in my favour...
As said mate this needs properly addressed..This has been happening for nearly a year.
Casino Complaint Thread 'Money Stolen - Videoslots Account Hacked?'
Hi there everyone I am a newbie here, but I have played on videoslots for many years .
on Thursday I was out all day and when I came home I noticed pretty much all my balance on videoslots was gone , someone had got into my account and withdrawn to a payment method I have never ever seen . They had withdrawn £294 to a monzo account . Firstly how has this been allowed to happen you are not meant to be able to withdraw to a non deposited method ???
I need that money and videoslots are basically saying its my problem, saying contact my bank bla bla, I mean why would I contact my bank it's...
- mooooz
- hacked account videoslots casino
- Replies: 47
- Forum: Other Complaints
I'm taking that later - will put it towards a new freddo - not the caramel.ones though they are ridiculously pricedI think they kindly left me 12p![]()
Appreciate your response, but why again is it a gesture of goodwill? Unless I am being stupid, this just comes across as "we are doing you a favour because we are getting blasted on CM".Hi everyone,
I want to provide a clear update regarding the recent reports of unauthorised account access.
It appears that some customer login credentials are currently circulating online and may be available for purchase. Based on our investigation so far, we have found no evidence that this data originated from, or was leaked from, Videoslots’ systems. Our current understanding is that the credentials have been obtained from an external source, for example through compromised data from another website, reused passwords, malware, phishing, or another third-party breach.
As a precaution, we strongly recommend that everyone updates their passwords — both for their email account and for other online services, including Videoslots. Passwords should ideally be unique for each website and not reused across multiple services.
We are also making further improvements to account security.
We are currently working on introducing optional two-factor authentication (2FA) that customers will be able to enable for account logins. In addition, for markets that do not already use strong identity verification methods such as BankID in Sweden, we are introducing additional verification when an account is accessed from a new device and IP address.
We also started a separate project in January to introduce KYC verification directly through supported payment providers when customers make deposits. This functionality has only recently become more widely available from payment providers, and we are introducing it across every payment method that supports it.
This will allow us to complete certain KYC checks faster and more seamlessly, but it also adds another layer of security by helping us verify that the person using a payment method is the legitimate account holder. This is particularly useful in situations involving compromised login credentials or attempted unauthorised account access.
There have also been questions about whether someone gaining access to an account can simply add a new payment method. This is not normally possible unless the customer's payment loop has first been closed and the relevant requirements have been met.
During the history of Videoslots, we are aware of approximately 10 cases where accounts appear to have been accessed using credentials obtained outside our systems or through other forms of account compromise. Five of these cases have occurred during the last two months, which is clearly an increase compared with what we have historically seen and is one of the reasons we are accelerating the additional security measures described above.
In only a limited number of these cases was someone able to withdraw funds using another payment method.
For any Videoslots customer who has suffered a financial loss as a direct result of this type of unauthorised account access, we will review the individual case and, where appropriate, cover the loss as a gesture of goodwill.
I completely understand why customers may initially believe that an incident like this means Videoslots itself has suffered a data breach. However, based on the information and investigations available to us, we currently have no evidence of a breach of customer login data from our systems.
That does not mean we should simply accept that these incidents can happen. We have a responsibility to continuously improve our security and make it as difficult as possible for fraudsters to access customer accounts, and that is exactly what we are doing.
At the same time, account security works best when customers also use strong, unique passwords and keep their email accounts secure, as access to an email account can often provide access to many other online services.
We will continue reviewing our security measures and implementing further improvements where we believe they can meaningfully protect our customers.
Every time is have added a new payment method to videslots i have had to send the verification for it before I can make any withdrawals from videoslots so it still seems strange that someone can add a new payment method then withdraw to it.Hi everyone,
I want to provide a clear update regarding the recent reports of unauthorised account access.
It appears that some customer login credentials are currently circulating online and may be available for purchase. Based on our investigation so far, we have found no evidence that this data originated from, or was leaked from, Videoslots’ systems. Our current understanding is that the credentials have been obtained from an external source, for example through compromised data from another website, reused passwords, malware, phishing, or another third-party breach.
As a precaution, we strongly recommend that everyone updates their passwords — both for their email account and for other online services, including Videoslots. Passwords should ideally be unique for each website and not reused across multiple services.
We are also making further improvements to account security.
We are currently working on introducing optional two-factor authentication (2FA) that customers will be able to enable for account logins. In addition, for markets that do not already use strong identity verification methods such as BankID in Sweden, we are introducing additional verification when an account is accessed from a new device and IP address.
We also started a separate project in January to introduce KYC verification directly through supported payment providers when customers make deposits. This functionality has only recently become more widely available from payment providers, and we are introducing it across every payment method that supports it.
This will allow us to complete certain KYC checks faster and more seamlessly, but it also adds another layer of security by helping us verify that the person using a payment method is the legitimate account holder. This is particularly useful in situations involving compromised login credentials or attempted unauthorised account access.
There have also been questions about whether someone gaining access to an account can simply add a new payment method. This is not normally possible unless the customer's payment loop has first been closed and the relevant requirements have been met.
During the history of Videoslots, we are aware of approximately 10 cases where accounts appear to have been accessed using credentials obtained outside our systems or through other forms of account compromise. Five of these cases have occurred during the last two months, which is clearly an increase compared with what we have historically seen and is one of the reasons we are accelerating the additional security measures described above.
In only a limited number of these cases was someone able to withdraw funds using another payment method.
For any Videoslots customer who has suffered a financial loss as a direct result of this type of unauthorised account access, we will review the individual case and, where appropriate, cover the loss as a gesture of goodwill.
I completely understand why customers may initially believe that an incident like this means Videoslots itself has suffered a data breach. However, based on the information and investigations available to us, we currently have no evidence of a breach of customer login data from our systems.
That does not mean we should simply accept that these incidents can happen. We have a responsibility to continuously improve our security and make it as difficult as possible for fraudsters to access customer accounts, and that is exactly what we are doing.
At the same time, account security works best when customers also use strong, unique passwords and keep their email accounts secure, as access to an email account can often provide access to many other online services.
We will continue reviewing our security measures and implementing further improvements where we believe they can meaningfully protect our customers.
Appreciate your response, but why again is it a gesture of goodwill? Unless I am being stupid, this just comes across as "we are doing you a favour because we are getting blasted on CM".
It should be standard - if someone commits fraud on my bank account, I get the money back - not through a gesture of goodwill but because their system was compromised by a 3rd party and I didn't authorise the transaction
Every time is have added a new payment method to videslots i have had to send the verification for it before I can make any withdrawals from videoslots so it still seems strange that someone can add a new payment method then withdraw to it.
I understand there may have been a breach elsewhere that may have gotten someone access to the account but still struggling to believe they can add a new method then withdraw even if the loop has been closed without verifying the method first.
Sorry missed that part.I'm told they'll be in touch soon to discuss it.![]()
Excuse my skepticism but what could they do such that you, for example, would say anything else?Appreciate your response, but why again is it a gesture of goodwill? Unless I am being stupid, this just comes across as "we are doing you a favour because we are getting blasted on CM".
Not sure why you are so defensive of them to be honest max - all im saying is that it should be simple - if the player is not at fault they funds should be returned, not a "gesture of goodwill"Excuse my skepticism but what could they do such that you, for example, would say anything else?
They could give the player a big fat gift for being inconvenienced and some would say same thing, "means nothing because it's happened after the flare up on the forums".
Well I for one disagree. As I've said before in this thread most casinos would NOT have done anything for the player; "not our fault therefor your problem" has been the typical answer we've seen in the cases like this to date and that was very much not the case here, so good on them.
And there's another reason why this matters. When a casino says "not our fault therefor your problem" there is no reason to believe a word they say. They may have done it themselves for all we know and might be doing it to many other players. But when the casino steps up, as VS did here, and offers to cover the losses in such cases you can pretty well count on the fact that they wouldn't be doing it for fun and games. Trust may have been damaged but there are very good reasons to believe that they take it seriously and, as stated, are taking responsibility.
No matter what was posted here or anywhere else the bottom line is that they're doing the right thing in an industry where that is far from typical.
If you b***h-slap the guy that does the right thing -- regardless of your reasons -- don't be surprised if there are precious few others willing to bother.
I disagree and have given my reasons why. But different strokes for different folks and that's cool.I think we are splitting hairs a little and it's down to the terminology being used.
I would say pretty much summed up - apart from the withdrawal being made to an account not used before so no closed loop systemSo:
Casinos, many of them UKGC-facing, have a streamlined process for a player to change/add payment method(s) unless there is cause for suspicion.
Elsewhere, a database of hacked e-mail addresses and passwords has been compiled from another non-casino business which presumably is a widely used one.
Scammers have used this e-mail-password combo to try their luck at other businesses including online casinos.
Against all web recommendations, some people have used the same password at other sites. In these instances, the scammers can use the e-mail addy/pw to gain access. Then they filch the balance.
As far as the casino is concerned, the right details have been used, no foul.
Casino is then somehow to blame for consumer having inadequate pw protocols in place (we've all done it, not criticizing!)
The hitherto convenient quick log-ons players appreciate then becomes an issue too when they realize the event probably would not have occurred with 2FA etc. so casino is the bad guy again, this time probably with some justification.
In most cases the casino would point out the password protocol laxity on behalf of the player and say 'tough s**t mate'.
In this case, they have acknowledged their present set-up and that the circumstances of hacked details is costing a few players funds. They restore the balances and having identified procedural improvements seek to implement them. This also nullifies the password laxity on the side of the player.
So, on balance, a quite reasonable and welcome outcome for those affected?
If you've been hacked on VS, it is most likely you've used the exact same password elsewhere, and "elsewhere" has been hacked with e-mail addresses and passwords on the dark web. If your password is unique to VS then the leak is at the casino.But how can the casino prove it is the customers password that was lacking in strength or re-use?
They surely cannot see the password to know how strong it is or if it is exposed in breaches?
(this is general casino point, not targeting VS)
