Planet Ice 2023 Data Breach

Planet Ice UK Ice Skating Venues & Youth Programs Breach (2023): 240K Family Records Including Children's DOB, Home Address & Passwords Exposed

Company · Ice skating venues and youth programs · Membership and event management system · UK

Planet Ice UK Ice Skating Venues & Youth Programs Breach (2023): 240K Family Records Including Children's DOB, Home Address & Passwords Exposed

Planet Ice operates ice skating rinks and youth-oriented programs across the UK. Systems include booking, membership management, and event participation, often involving minors and families.

Confirmed · ObscureIQ Intelligence
Limited DisclosureThis breach involves data relating to children. We do not confirm the presence of any individual publicly or to third parties. A parent or guardian can check exposure privately below.
Breach Risk Index i
44/100
Lower riskHigher risk
Moderate: notable exposure with meaningful misuse potential.
Data Sensitivity i
Restricted
Being associated with this breach can itself be harmful. Disclosure is limited and presence is not confirmed to unverified parties.
240KRecords
2023Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
AddressPhysical address
MinorsChildren / minors
Classification Tags
Cloud MisconfigurationChildren & FamilyChildren2023

Breach Summary

Planet Ice, a UK-based operator of about fourteen public ice-skating rinks, suffered a data breach disclosed in late January 2023. The incident affected the company's "Ice Account" booking platform and exposed records for approximately 240,000 customers. Planet Ice attributed the unauthorized access to its event-services provider, IMP-UK. Financial information was not affected because payment processing was handled separately by Worldpay.\n\nThe exposed data covered email addresses, physical addresses, phone numbers, gender, dates of birth, and passwords stored as weak MD5 hashes. The dataset also included names, dates of birth, and gender for children who had attended birthday parties at Planet Ice rinks, recorded as part of the booking system. Parents and guardians who booked these events were the primary account holders and the parties most likely to have used the platform's password.\n\nBecause the breach exposed minors' personal details combined with home addresses and parent contact information, the practical risk profile is materially more sensitive than a standard customer-list leak. The combination of a child's full name, date of birth, and home address, paired with a parent's email and phone number, creates a base for targeted contact and impersonation attempts that reference specific children and family activities. Parents whose children's details may have been exposed should rotate any reused passwords, treat any unsolicited contact referencing skating activities or party bookings with caution, and consider monitoring for unusual contact aimed at the child's name.

Full threat analysis, exploitation vectors, and principal guidance below.

10 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

240K records analyzed

About Planet Ice

Planet Ice is a U.K.-based operator of public ice-skating rinks and venue services. The company runs roughly fourteen rinks across the United Kingdom, hosting public skating sessions, ice-hockey leagues, learn-to-skate programs, children's parties, and venue events. Its customer base is heavily family-oriented, with parents and guardians booking sessions, parties, and lessons on behalf of children. The company's customer-account platform was branded "Ice Account" and was operated alongside event-management services from a related provider, IMP-UK. Payment processing was handled separately by Worldpay.

Why They Hold Your Data

Membership and youth-program organizations collect participant identity, contact details, payment records, event enrollments, membership status, and parent or guardian information across venue and program operations.

Recent Developments

Planet Ice continues to operate its rinks following the 2023 incident and has not been publicly tied to further significant breach events. The company notified the UK Information Commissioner's Office and engaged external cybersecurity advisors during incident response. Customer-facing communications were criticized at the time, with many affected users learning of the breach through press coverage or HaveIBeenPwned rather than from Planet Ice directly. There has been no public ICO enforcement action announced against Planet Ice or its event-services partner IMP-UK in the years since, although affected children's data falls within the heightened protections of UK data-protection law.

Data Points Exposed

9 verified field types
Date of Birth High
Email Address
Full Name
Gender
IP Address
Password High
Phone Number
Physical address High
Transaction History

Breach Impact

The 2023 incident produced limited direct financial cost to Planet Ice but generated meaningful reputational and operational disruption. The "Ice Account" booking platform was taken offline during containment, interrupting ticket and party bookings during peak season. Customer trust took a noticeable hit, particularly among parents whose children's data had been exposed. Planet Ice notified the Information Commissioner's Office and engaged external incident-response specialists. There is no public record of ICO enforcement action, settlement, or class-action litigation tied to the breach. The event-services partner IMP-UK, which the company stated had been the source of the unauthorized access, also drew scrutiny in the disclosure messaging.

Exploitation & Downstream Threats

• Credential stuffing against reused passwords across other platforms | • Identity verification bypass using name + date of birth combination | • SIM swap attacks where phone numbers are present | • Targeted phishing campaigns using exposed email addresses | • Doxxing risk from physical address exposure

Principal Risk Advisory

What this means for a principal

A breach involving minors: identity data on children carries long-tail identity-theft and safeguarding risk. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.

What You Should Do

  1. Treat the home address as exposed: review mail and package handling and physical-security routines, and brief household staff to verify unusual requests.
  2. Reset any reused passwords and enable MFA on email first, then financial accounts.
  3. Guard against SIM-swap and vishing: add a carrier port-out PIN and verify any 'support' calls independently.
  4. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping and footprint neutralization: cross-reference against broker-available data and suppress still-removable elements, prioritizing address and phone, since this record re-seeds broker networks.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).

Protect Yourself

Protect Yourself: Limited Disclosure

Check Exposure: Verification Required

Because this breach involves data about minors, we do not confirm whether any individual appears in it to unverified parties. A verified parent, guardian, or the individual can privately check exposure.

We confirm exposure only to the affected individual or their verified parent or guardian.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation