TuLotero KYC Breach: How Stolen IDs Fuel Gambling Phishing

PhishFort Team
PhishFort Team
• 7 min read
TuLotero KYC Breach: How Stolen IDs Fuel Gambling Phishing

In July 2026, attackers accessed TuLotero’s identity verification service and stole images of users’ Spanish national ID cards (DNI) and verification selfies, affecting about 2% of users, roughly 100,000 people. In September, a threat actor claimed to sell a much larger set of 37.4 GB and nearly 240,000 images, which is not verified. The main risk now is phishing: fake KYC portals and fake support messages that use real player data and the TuLotero brand.

Summary

  • TuLotero, a Spanish online lottery platform, confirmed unauthorized access to an isolated KYC (Know Your Customer) service between July 13 and July 15, 2026.
  • The stolen material was front and back DNI images plus identity verification selfies. TuLotero said passwords, banking data and stored payment methods were not affected.
  • Threat actor mor3nako later claimed to sell 37.4 GB and nearly 240,000 KYC images and linked the intrusion to a malware family called TerciosRAT. Both claims are unverified.
  • Stolen KYC data lets attackers send context-aware phishing: messages that know the player’s name, ID and gambling platform.
  • Gambling operators should monitor for lookalike domains, fake verification portals, fake support accounts and fake apps that use their brand after a KYC incident.

What happened in the TuLotero KYC breach?

An unauthorized party accessed an isolated service TuLotero used for identity verification, which Spanish gaming regulation and anti-money laundering (AML) rules require. The intrusion ran from July 13 to July 15, 2026. TuLotero detected it on July 14 and blocked it the following day.

TuLotero said the compromised material consisted of:

  • Images of the front of users’ DNI documents.
  • Images of the back of users’ DNI documents.
  • Identity verification selfies.

The company reported the incident to Spain’s data protection authority, the Agencia Española de Protección de Datos (AEPD), and to law enforcement on July 17. According to TuLotero information reported by the Spanish consumer organization OCU, about 2% of users were affected, roughly 100,000 people.

What is confirmed and what is only claimed?

The July intrusion into TuLotero’s KYC service is confirmed by the company. The September claims about the size of the stolen dataset and the malware used come from a threat actor and are not independently verified.

The table separates the two:

ItemStatusSource
Unauthorized access to the KYC service, July 13 to 15, 2026ConfirmedTuLotero, via OCU
DNI images (front and back) and selfies accessedConfirmedTuLotero, via OCU
About 2% of users affected (roughly 100,000 people)ConfirmedTuLotero, via OCU
Passwords and payment data not affectedCompany statementTuLotero
37.4 GB dataset with nearly 240,000 images for saleThreat actor claimmor3nako, reported September 16, 2026
Intrusion linked to TerciosRAT malwareThreat actor claimThreat intelligence reporting (Hackmanac)

Threat actors often inflate dataset size, mix data from several breaches or misstate where it came from to attract buyers. The claim still matters operationally: if part of it is genuine, a large set of identity verification images is now on the criminal market.

Why is KYC data more dangerous than a leaked password?

A password can be reset and a payment card can be replaced, but a government ID and a verification selfie cannot be rotated. That makes KYC repositories high-value targets.

A stolen DNI gives an attacker an identity document. A selfie gives visual evidence tied to that identity. Together they can make fraudulent identity verification attempts and impersonation more convincing, especially when combined with data from other breaches. The OCU warned about exactly this risk of identity impersonation.

How do attackers turn a KYC breach into a phishing campaign?

Attackers use the stolen data to make phishing believable, then collect what the breach did not give them: fresh passwords, SMS codes and banking details. The sequence usually looks like this:

  1. The attacker already knows the player’s name, DNI, photo and that they use TuLotero.
  2. A message arrives: “Your TuLotero account requires identity verification. Complete it to avoid restrictions on your account.”
  3. The link leads to a cloned gaming portal on a lookalike domain.
  4. The fake portal asks for the DNI, password, SMS verification code, banking details and a new selfie.
  5. The attacker now holds working credentials and can take over the account or reuse the identity elsewhere.

This is context-aware phishing. The message is credible because it uses real information from the victim’s relationship with the gaming brand.

How do scammers use fake apps, sign-up flows and support accounts to impersonate betting brands?

Scammers impersonate betting brands with cloned websites, fake mobile apps, fake KYC sign-up flows and fake customer support accounts on social media and messaging apps. Each channel copies a step players already expect, which is why gambling impersonation works.

  • Fake verification flows: players are used to uploading a DNI or selfie, so a fake KYC request looks like normal compliance.
  • Fake withdrawal notices: “Your withdrawal has been suspended” sounds routine to someone who moves money through a gaming account.
  • Fake support agents: players contact support about deposits, bonuses and winnings, so a fake agent on Telegram, WhatsApp or Discord can ask for one-time codes.
  • Fake apps and paid ads: copies of the operator’s app, or search ads that send players to a clone site.

PhishFort sees this pressure in its own data. iGaming and Betting accounted for 6.2% of confirmed brand impersonation cases from January to June 2026, and attack velocity in high-risk sectors such as iGaming tripled as AI site builders cut the time from domain registration to live clone to hours (PhishFort internal data).

How do gambling operators remove clone sites and fake KYC portals?

Gambling operators remove clone sites and fake KYC portals by detecting them early and filing takedown requests with the registrar, the hosting provider and, for apps and profiles, the platform. After a KYC incident, monitor these signals:

  1. Lookalike domains: new registrations that combine the brand with words like verify, KYC, login, payment or withdrawal.
  2. Fake verification portals: pages that request DNI photos, passports, selfies, proof of address, bank details or one-time passwords.
  3. Brand impersonation channels: search results, paid ads, social media accounts, Telegram channels, WhatsApp campaigns, Discord communities and malicious mobile apps.
  4. Credential harvesting pages: pages that combine brand, login, KYC and payment elements, a strong sign that stolen data is being used.
  5. Fake customer support: accounts that offer help with deposits, withdrawals, bonuses or account restrictions.

The goal is to find and remove the infrastructure used to target players, not only to close the original breach.

What should TuLotero players watch for?

Affected players should treat any unexpected identity verification request as suspicious, even when the sender knows their name. Warning signs include requests to:

  • Re-upload a DNI or send a selfie through WhatsApp.
  • Share an SMS verification code or confirm banking details.
  • Unlock an account, verify a withdrawal or pay a fee before receiving winnings.
  • Follow a link to an unfamiliar domain.

After a KYC breach, knowing your personal details is not proof that a sender is legitimate. That information may be exactly what the attacker stole.

Timeline of the TuLotero incident

  • July 13 to 15, 2026: unauthorized access to TuLotero’s identity verification service, detected July 14 and blocked July 15.
  • July 17, 2026: TuLotero reports the incident to the AEPD and law enforcement.
  • August 2026: TuLotero confirms about 2% of users were affected and that DNI images and selfies were accessed.
  • September 15 to 16, 2026: threat actor mor3nako claims a 37.4 GB dataset of nearly 240,000 images and offers it for sale (unverified).

How PhishFort helps gaming operators after a KYC incident

PhishFort Brand Protection monitors new domains, app stores, social media and paid ads for impersonation of gaming brands, and takes down fake verification portals, clone sites and fake support accounts with registrars, hosts and platforms.

Frequently asked questions

What data was stolen in the TuLotero breach?

TuLotero confirmed that attackers accessed images of the front and back of users’ DNI documents and identity verification selfies. The company said passwords, banking data and stored payment methods were held separately and were not affected.

How many TuLotero users were affected?

About 2% of users, roughly 100,000 people, according to TuLotero information reported by the OCU. A later claim of 37.4 GB and nearly 240,000 images came from a threat actor and is not verified.

Why do criminals target KYC data at gambling platforms?

Regulated gambling platforms must collect government IDs and selfies, so KYC systems hold identity data in one place. That data cannot be changed like a password and makes phishing and impersonation far more convincing.

How do online casinos remove clone and fake KYC sites?

Operators detect lookalike domains and fake portals through continuous monitoring, collect evidence and send takedown requests to the registrar, hosting provider or platform. Many use a brand protection provider to handle detection and takedown at scale.

Sources