An Announcement with the Air of a Digital Heist
The scenario resembles the opening of a heist movie. On Saturday, February 7, 2026, at 10:16 AM, a hacker publishes an advertisement on a dark web forum, then modifies it one minute later. The offer is spectacular: an administrator access to an international sports betting infrastructure, with a particularly high level of privileges. The potential buyer would, according to the seller, retrieve complete transaction histories, financial information, the identifiers of the administrative interfaces of casinos linked to the network, API documentation, and integration details.
Even more impressive: the seller claims that this access would cover 90,000 active agent sites, mainly in Asia and beyond. The access would even allow for automatic crediting of agent and "master agent" accounts — those intermediary operators who structure underground or semi-legal betting networks in several Southeast Asian countries. The advertisement also promises over $1.5 million in potential gains with little effort, without providing any elements to verify this estimate.
It was the investigation published by ZATAZ on August 10, 2026, signed by Damien Bancal, that brought this advertisement back into the spotlight. And for good reason: August 2026 saw new "data" attributed to the same profile, again concerning casinos — often opaque or even banned in several countries.
The Pseudonym "taking0ver": A Gambling Specialist
The most informative element does not lie within the ad of February 7 itself, but in the seller's history. The pseudonym "taking0ver" is not discovering this market with this publication. Their profile reveals a long-standing activity particularly focused on prospect databases, casinos, sports betting, and financial data.
The Catalog, Year by Year
The timeline reconstructed by ZATAZ shows a methodical specialization:
April 2024 — A first wave of advertisements:
- A database linked to the site Jazz Sports (sportsbook, casino, and racebook), presented as coming from data dated March 2022, with 9,780 views.
- 205,000 contacts attributed to Wolfy Casino for 2021 (8,501 views).
- 140,000 Australian players of gambling, for the period 2018-2021 (9,350 views).
- Prospects associated with 4 King Slots, dated 2021 (2,885 views).
February-March 2025 — A sharper geographical segmentation:
- 144,000 casino player records in Malaysia (February).
- 48,000 German profiles and 87,000 Indonesian profiles, all presented as dating from 2024 (March).
January 2026 — The logic continues:
- 400,000 casino players in Azerbaijan.
- 85,000 Italian records.
These five geographical publications alone represent 764,000 announced records (144,000 + 48,000 + 87,000 + 400,000 + 85,000).
Beyond Gambling: Cryptocurrencies and Tools
The catalog does not stop at the gambling sector. On January 10, 2026, the seller published an offer titled "Crypto Data from Binance for Sale," presented as first-hand information — the authenticity and provenance of which remain impossible to establish. The day before, they highlighted a mailing solution presented as usable for life. On February 5, 2026, two days before the betting portal announcement, they also offered prospects from trade in Vietnam.
This timeline radically changes the perception of the February 7 offer. It no longer resembles an isolated publication, but fits within a coherent catalog where player databases, commercial prospects, cryptocurrency data, sending tools, and now claimed administrative access intersect.
A Warning Signal: The Profile Reported for Fraud
However, one element imposes a strong caution: the profile of "taking0ver" is the subject of a fraud report on the forum where they operate. This status does not prove that each of their ads is fraudulent, but it forbids taking their claims for granted without additional evidence.
Several scenarios thus remain in competition:
- A real compromise of the targeted infrastructure;
- Recycled data or old databases resold as new;
- An exaggerated access (for instance, partial access presented as administrator);
- An entirely fictitious offer, designed to scam potential buyers.
The available excerpts do not allow for a decision. As ZATAZ points out, the real information lies elsewhere: since at least 2024, the same pseudonym has been building a coherent showcase around player data and gambling infrastructures. In cyber intelligence, this continuity is often more informative than a single spectacular announcement: it reveals a specialization, a targeted clientele, and an economy organized around stolen or supposedly compromised data.
The Context: A Dark Web Saturated with Gambling Data
The offer from "taking0ver" fits into a broader landscape. In early August 2026, ZATAZ revealed the discovery of a hacker storage housing more than 1.7 billion unique email/password pairs linked to France — nearly 25 identifiers per French inhabitant. Almost 69% of this data would come from phishing campaigns conducted over thirteen years, with the remaining 31% linked to leaks that exposed passwords in clear text.
In this same context, ZATAZ also documented the case of another cybercriminal offering more than 70 terabytes of data covering over 25 countries, with a subscription model paid in cryptocurrencies (Bitcoin, USDT, Solana, Ether), with prices ranging from $199 per month to $2,999 for permanent access. The seller, likely based in Asia, was careful to avoid offering Russian data — a typical behavior of criminals who do not want to attract the attention of the local FSB.
The same week, ZATAZ also recorded 43 ransomware claims targeting France in one month, the attack on Stade Français by the Qilin group, the hacking of a mirror of the Coco forum with 14,500 stolen accounts, and a massive data leak from a French HR professional.
The "Master Agents" Model: Why It Is Sensitive
The announcement from "taking0ver" deserves particular attention due to the structure it claims to compromise. In many Asian countries, online sports betting platforms operate according to a hierarchical model known as "agents" and "master agents": a central operator provides the technical platform (often white-labeled), local agents recruit players and manage bets, and "master agents" supervise networks of sub-agents.
This model, widely spread in Southeast Asia, relies on tens of thousands of active agent sites — a volume consistent with the claimed 90,000 sites. Administrator access to such a network would theoretically offer control over:
- The financial transactions of the entire network;
- The balances and histories of players and agents;
- The API documentation that allows understanding the technical architecture;
- The ability to credit or debit accounts, paving the way for direct fraud.
The online betting and casino sector is particularly vulnerable: many platforms operate in legal gray areas, with very uneven levels of cybersecurity. The players themselves are often reluctant to report compromises, fearing exposure of their own gambling activity, which may be illegal in their jurisdiction.
Precedents That Show the Risk
The gambling industry has already been hit by major cyberattacks. In September 2023, MGM Resorts suffered a social engineering attack (by the Scattered Spider / ALPHV group) that paralyzed its operations for several days, with an estimated cost of over $100 million. Around the same time, Caesars Entertainment paid a ransom of nearly $15 million after a similar compromise.
These incidents illustrated attackers' ability to exploit vulnerabilities in complex and interconnected infrastructures — exactly the type of vulnerability that "taking0ver" claims to exploit on a potentially much larger scale.
Key Takeaways
Several lessons emerge from this case:
-
Specialization is a strong signal. In cyber intelligence, a seller who maintains a coherent catalog for over two years around a specific sector (gambling) is not an opportunist. They reveal the existence of a structured demand and a supply chain for player data.
-
The announced volumes must be treated with caution. 764,000 geographical records, 90,000 agent sites, $1.5 million in potential gains — these figures are declarative and unverifiable from the available excerpts alone. The fraud report reinforces the necessity to cross-check these claims with other sources.
-
The gambling data economy is thriving. Whether it is individual players, prospect databases, or administrative access, the gambling sector feeds a parallel market where personal, financial, and technical data is traded in cryptocurrencies.
-
Players are particularly exposed. Casino player data (names, contacts, betting histories, financial information) can be used for targeted phishing, blackmail, identity theft, or direct fraud. The sometimes illegal nature of gambling activity makes victims even more vulnerable, as they are less likely to report themselves.
Practical Recommendations
For both gaming platform operators and players:
- Operators: apply multi-factor authentication on all administrative accesses, segment environments to limit the impact of a compromise, monitor APIs and back-office interfaces, and conduct regular security audits.
- Players: use unique passwords for each gaming service, activate multi-factor authentication whenever available, and stay vigilant against phishing attempts exploiting stolen gambling data.
- Monitoring: watch dark web forums to detect any offer mentioning its infrastructure or data, as proposed by the ZATAZ monitoring service.
The "taking0ver" case reminds us that behind every spectacular announcement on the dark web, there is often a longer and more structured story than it seems. It is this continuity — and not just the single splash — that interests cyber intelligence analysts.
Sources: ZATAZ — For Sale: Inside the Empire of Betting · ZATAZ — A Billion French Identifiers on the Dark Web · ZATAZ — Pirate Trade: A Cybercriminal Sells Tens of Terabytes of Data · ZATAZ — Two Pirates Claim the Hacking of Cloud Professionals · ZATAZ — Cyber News of the Week from August 3 to 9, 2026 · ZATAZ — Home · BleepingComputer — Security News · Krebs on Security · The Hacker News · The Record — Recorded Future News