
Zero Day is a new Gamblers Connect editorial product covering cyber security, fraud and operational resilience across the iGaming industry. It launches as a section inside the Gamblers Connect news vertical and as a newsletter on LinkedIn, on the premise that security in this sector is reported too late, too thinly, and almost never by people who read the regulator filings.
Why iGaming needs a security beat
Gambling is one of the most attacked industries on the internet, and one of the least covered from a security standpoint by its own trade press. The reasons are structural rather than mysterious. Operators have every commercial incentive to say as little as possible after an incident. Suppliers sit one contract away from a breach they did not cause but will be named in. Regulators publish enforcement notices that almost nobody in the commercial teams actually reads. And the security story usually surfaces in the mainstream press first, framed for a general audience, weeks after the people who needed to act had the chance to.
The result is an industry that talks about security in two registers and neither of them is useful. There is the conference panel register, where everyone agrees security is important and nobody says anything specific. And there is the vendor register, where a real risk is described accurately and then immediately resolved by the product being sold. What is largely missing is the plain version: what happened, to whom, how, what it cost, what the regulator did about it, and what a company with the same exposure should do differently on Monday.
Security in iGaming is reported as an IT problem. It is a licence problem, a payments problem, a player trust problem, and increasingly a board level problem.
What Zero Day covers
The section is organised around the risks that actually move money and licences in this industry, rather than around security as a technology category.
Incidents and breaches
Cyber incidents at operators, suppliers, aggregators and payment providers. What was accessed, what was disclosed, when, and whether the disclosure matched what regulators and players were later told. Post incident regulatory action, fines and licence conditions.
Ransomware and extortion
Attacks that take a platform offline or hold data hostage, the operational decisions that follow, and the cost of downtime in a sector where a sportsbook cannot simply pause during a major fixture.
Account takeover and credential abuse
Credential stuffing against player accounts, session hijacking, SIM swap attacks on account recovery, and the tension between friction and conversion that every operator security team lives inside.
Fraud, payments and bonus abuse
Payment fraud and chargeback abuse, multi accounting and bonus abuse at scale, affiliate fraud and traffic laundering, money mule activity, and the point where fraud stops being a commercial loss and becomes an anti money laundering failure.
Identity, KYC and synthetic media
Document forgery, injection attacks against identity verification flows, and the fast moving problem of generated faces, voices and video used against liveness checks. This is where the security beat and the responsible gambling beat overlap, because an identity system that fails cannot enforce age limits or self exclusion.
Supplier, aggregator and third party risk
The route most commonly underestimated in this industry. Game aggregators, platform providers, payment processors, CRM tools and affiliate trackers all sit inside the operator’s trust boundary, and an incident at any of them becomes the operator’s regulatory problem.
Regulation, standards and enforcement
The information security obligations attached to licences across jurisdictions, enforcement action where security or data protection failures are cited, and the standards operators are asked to evidence, from ISO 27001 and SOC 2 through to PCI DSS and jurisdiction specific technical standards.
Insider threat and physical security
Insider data theft, collusion, and the physical security questions that still matter across land based estates and at industry events where thousands of laptops and phones travel into one building.
Where to find it
The Zero Day section
Zero Day runs as a permanent section inside the Gamblers Connect news vertical. Articles are published as the story warrants rather than to a fixed schedule, because security news does not arrive on a calendar. Every piece carries the standard Gamblers Connect Verified Sources panel, so a reader can see exactly which regulator filing, corporate disclosure, court document or named source each claim rests on.
The Zero Day newsletter on LinkedIn
The newsletter version is published on LinkedIn for readers who would rather have the beat delivered than go looking for it. Each edition gathers what moved in security across the industry, with the reasoning kept short and the sourcing kept visible. Subscribing is a single click from the Gamblers Connect LinkedIn page, and the newsletter is free.
How Zero Day is written
Security reporting fails in predictable ways, so it is worth setting out the rules Zero Day operates under before the first article rather than after a complaint.
- Named sources or documents, every time. Every incident claim is anchored to a regulator publication, a company disclosure, a court or enforcement document, or a named source willing to be quoted. Zero Day does not publish breach claims sourced only to an anonymous post on a leak site.
- No unverified victim naming. A company appearing on a ransomware group’s leak page is a claim by a criminal group, not a confirmed fact. Where Zero Day reports on such a claim it will be labelled as a claim, and the company will be given the opportunity to respond before publication.
- No operational detail that helps an attacker. Zero Day explains what happened and why it mattered. It does not publish exploit detail, working attack methodology, or anything that functions as a recipe.
- Right of reply before publication, not after. Any company named in an incident story is contacted before the piece runs, with a reasonable deadline and the specific claims put to them in writing.
- No vendor coverage for sale. Security vendors cannot buy a mention, a placement, or favourable framing. Where a vendor is a Gamblers Connect commercial partner and appears in Zero Day coverage, that relationship is disclosed inline in the article.
- Corrections in public. Security stories move fast and early reporting is sometimes wrong. Corrections are published on the page with a visible notice rather than edited in silently.
Why Zero Day
A zero day is a vulnerability that is being exploited before anyone responsible for fixing it knows it exists. The name was chosen because it describes the position most of this industry is in on security more often than it would like to admit: the exposure is already live, the clock is already running, and the first anyone hears about it is when something breaks. The purpose of the section is to shorten that gap.
Coming next
The Zero Day section is live now inside the Gamblers Connect news vertical, and the LinkedIn newsletter will publish its first edition on the last Thursday of the Month. Tips, disclosures and responses to Zero Day coverage can be sent to the Gamblers Connect editorial team, and we will confirm receipt of anything sent by a named sender. Where a source needs to remain unnamed, that will be respected and stated in the article as an unnamed source with the reason given.