Planet Ice Data Breach (2023): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The Planet Ice Data Breach (2023) (reported January 14, 2023) exposed Dates of birth, Email addresses, Genders and IP addresses belonging to roughly 240K people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Organisations that handle everyday bookings and family events have become routine targets in a threat landscape where stolen personal records are traded, reused for fraud, and combined with other leaks. Consumer services that store contact details, account credentials and information about children sit in that path: the data is valuable enough to attract attackers, yet the systems involved are often treated as ordinary business tools rather than high-risk stores of identity information.
In January 2023, the UK-based ice skating rink booking service Planet Ice was reported to have suffered a data breach affecting around 240,000 people. Public reporting described exposure of names, contact details, dates of birth, genders, IP addresses and passwords stored as MD5 hashes, including records linked to children attending parties. The scale and the mix of adult and child data make the incident relevant to anyone who used the service or booked events through it.
What happened
According to reporting dated 14 January 2023, Planet Ice experienced a data breach that exposed personal data belonging to approximately 240,000 people. The disclosed material included email addresses, physical addresses, phone numbers, names, genders, dates of birth, IP addresses and passwords stored as MD5 hashes. Reporting also stated that the data included the names, genders and dates of birth of children having parties.
Public detail does not describe the precise intrusion method, the duration of unauthorised access, or whether the data was obtained from a live system, a backup or another store. No specific threat actor is attributed in the available facts. What is established is the reported timing, the approximate number of people affected, and the categories of data named as exposed.
How a breach like this happens
Incidents of this type commonly begin with an attacker gaining a foothold through stolen or weak credentials, an unpatched application, a misconfigured database, or a compromised third-party component used for bookings or payments. Once inside, the attacker may copy customer databases, account tables or export files that already contain the fields a service needs to run reservations and marketing.
Credential data is frequently taken because it can be reused elsewhere. When passwords are stored with outdated hashing methods such as MD5, offline cracking is often feasible if the hashes are not further protected with strong, unique salts and modern algorithms. Contact and identity fields are then packaged for sale or leak-site publication. None of this requires a named group; the pattern is widespread across consumer booking platforms and similar services. Exact mechanics for any single case remain undisclosed unless investigators or the organisation publish them.
About Planet Ice
Planet Ice is a UK-based ice skating rink and booking service. Organisations in this sector typically manage rink sessions, lessons, parties and related customer accounts. To operate, they commonly hold names, email and postal addresses, phone numbers, dates of birth for age-restricted or party bookings, and login credentials for online accounts. They may also log technical details such as IP addresses in the course of website or app use.
A breach at such a service is consequential because the customer base includes families and children as well as adult skaters. Party bookings in particular can concentrate children’s names and birth dates alongside adult contact information, creating a denser identity profile than a simple mailing list. For the organisation, loss of that trust and the regulatory and operational follow-on are material even when the technical root cause is not fully public.
What was likely exposed
Reporting named the following categories as exposed: dates of birth, email addresses, genders, IP addresses, names, passwords, phone numbers and physical addresses. Passwords were described as stored as MD5 hashes. The same reporting stated that the data included the names, genders and dates of birth of children having parties.
Beyond those named fields, the exact full contents of every record are not independently itemised in the facts provided here. Organisations of this kind typically also hold booking histories, account preferences or payment-related references; whether any of those appeared in this incident is unconfirmed. Readers should treat only the listed types as reported and regard other possibilities as unverified.
Why it matters
For affected people, the combination of name, address, phone, email and date of birth supports phishing, account takeover attempts and identity fraud. MD5 password hashes, if cracked, can expose reused passwords on other sites. IP addresses add a technical trace that can sometimes be linked to location or account activity. When children’s names, genders and dates of birth are included, the risk extends to misuse of minors’ details in social engineering or long-term identity abuse, even if no financial data is mentioned.
For the organisation, the incident creates obligations around notification, customer support and security remediation, and it can damage confidence in a service that families use for routine leisure. The real-world impact is practical rather than abstract: unwanted contact, credential stuffing against other accounts, and the lasting difficulty of retracting personal data once it has left the original system.
What to do if you're exposed
If you used Planet Ice or booked parties there, treat the named data types as potentially compromised. Change any password you used on the service, and change it on every other account where you reused the same or a similar password. Prefer a unique password and multi-factor authentication where available. Watch email and phone messages for phishing that references skating, bookings or party details. Consider credit or identity monitoring if your address and date of birth were involved, and be cautious about sharing further personal information in response to unexpected contact.
Parents and guardians should review what children’s details may have been supplied for parties and limit any further unnecessary sharing. As a further check, you can run a free exposure scan of your email address to see whether it has appeared in known breach data sets and to decide what else to secure next.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Hathway Data Breach (2023)InflateVids Data Breach (2023)KitchenPal Data Breach (2023)Facebook Marketplace Data Breach (2023)Latest breaches
Read GalaxyWarden’s full analysis of the Planet Ice Data Breach (2023) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.