Latest News
Popular Gambling App Exposed Millions of Users in Massive Data Leak


Led by Noam Rotem and Ran Locar, vpnMentor’s research team discovered a data breach on casino gambling app Clubillion.
The breach originated in a technical database built on an Elasticsearch engine and was recording the daily activities of millions of Clubillion players around the world.
Aside from leaking activity on the app, the breached database also exposed private user information.
With this information publicly available, Clubillion’s users were vulnerable to fraud and various online attacks with potentially devastating results.
Company Profile
Clubillion is a free online casino game available for iOS and Android, offering players 30+ free slot games. While each app is listed under a different developer – Ouroboros on iOS and T7 Games on Android – these are most likely owned by the same company.
Both versions of Clubillion were released in 2019 and became instant hits. Each is now ranked the #1 ‘social slots’ casino app on Google Play and the App Store, with a 4.8 star on both.
Timeline of Discovery and Owner Reaction
Sometimes, the extent of a data breach and the owner of the database are obvious, and the issue quickly resolved. But rare are these times. Most often, we need days of investigation before we understand what’s at stake or who’s leaking the data.
Understanding a breach and its potential impact takes careful attention and time. We work hard to publish accurate and trustworthy reports, ensuring everybody who reads them understands their seriousness.
Some affected parties deny the facts, disregarding our research, or playing down its impact. So, we need to be thorough and make sure everything we find is correct and accurate.
In this case, the database was built on Elasticsearch and hosted on Amazon Web Services (AWS), with Clubillion’s name on its apps, and links to assets owned by the company.
Once Clubillion was confirmed as the owner of the database, we reached out to the developers. While awaiting a reply, we also contacted AWS with details of the leak. It was closed a few days later.
- Date discovered: 19th March 2020
- Date vendors contacted: 23rd March 2020
- Date of contact with AWS: 31st March 2020
- Date of Action: Approx. 5th April 2020
Example of Entries in the Database
Clubillion’s exposed database contained technical logs for millions of Clubillion users around the world, on both iOS and Android devices. Every time an individual player took any action on the app, a record was logged. Examples of records include:
- “enter game”
- “win”
- “lose”
- “update account”
- “create account”
During our investigation of the database, new entries continued to appear continuously. We estimated an average of approximately 200 million records per day – and sometimes, considerably more.
In total, this amounted to over 50GB of exposed records in the database every single day.
Within many of these records, were various forms of user Personally Identifiable Information (PII) data, including:
- IP addresses
- Email addresses
- Winnings
- Private messages
This data breach was truly global, with millions of records originating from Clubillion’s daily users all over the world. The following list is just a sample of countries affected, along with the average number of daily users from each country:
- USA – 10,000+
- UK – 2,475+
- France – 1,650+
- Israel – 408+
- Germany – 1,582+
- Spain – 1,026+
- Italy – 2,407+
- Netherlands – 622+
- Australia – 6,251+
- Canada – 7,792+
- Brazil – 3,859+
- Sweden – 191+
- Russia – 547+
Other countries affected included Uzbekistan, India, Poland, Romania, Vietnam, Lebanon, Indonesia, Philippines, Pakistan, Thailand, Austria, Hungry, and Latvia.
As you can see, on a single day, 10,000s of individual Clubillion players were exposed. Each one of these players could be targeted by malicious hackers for fraud and cyberattacks – along with millions more whose records were also contained in the database.
Data Breach Impact
Studies have shown that free gambling and gaming apps are especially prone to attacks and hacking from cybercriminals. They are routinely targeted for theft of private data and embedding malicious software on users’ devices.
Despite their popularity, gambling and casino apps often lack transparency, and it can be impossible to know what steps they’re taking to prevent cybercriminals successfully targeting their users.
One study of 23,000 free gambling apps found that: 3,200 posed a ‘moderate risk’ to users; 379 had known security vulnerabilities; 52 contained malicious software.
Any of these issues could be exploited to target app users in a wide range of frauds and cyberattacks, and Clubillion is no different.
With the exposed user PII and knowledge of their activity on the app, hackers could create elaborate schemes to defraud users. For example, some entries also included transaction errors for attempted card payments on Clubillion.
With the information in these transaction errors, hackers could target users with phishing campaigns, with the following aims:
- Trick them into providing their credit card details
- Trick them into providing additional PII to be used against them in further fraud
- Clicking a link that embeds malware, spyware, or ransomware onto their device.
If cybercriminals used Clubillion to embed malware or similar onto a user’s phone, they could potentially hack other apps, access files stored on the device, make calls, and send texts from the hacked device. They could even access a user’s phone contacts and steal the PII data of their friends and family.
Worse still, as people across the globe now find themselves under quarantine or self-isolation, as a result of the Coronavirus pandemic, the impact of a leak like this is potentially even more significant.
Clubillion stands to gain many new users, along with regular users playing more frequently. Hackers will be aware of this and looking for opportunities to exploit any vulnerabilities in the data security of such a massively popular app.
Had criminal hackers discovered Clubillion’s database, they could have targeted millions of people around the world, with devastating results.
Impact on Clubillion and it’s Developers
The most immediate risk for Clubillion is the loss of players. Data security is a growing concern for everyone these days, and this leak could turn many players off the app. Clubillion is not unique, and players have plenty of other choices for free gambling apps.
With fewer players, Clubillion will lose advertising revenue and reduced profits.
As many of Clubillion’s players reside within the EU, the app is under the jurisdiction of GDPR. The rules of GDPR also apply to apps, and Clubillion will need to take specific actions to ensure the regulatory body in charge doesn’t reprimand it.
Finally, Clubillion could also potentially be removed from Google Play and the App Store. Both Apple and Google are clamping down on apps that pose a risk to their users, removing apps embedded with malware, and taking data leaks much more seriously.
Each of these outcomes has a different likelihood of happening, but they would all negatively impact Clubillion’s revenue and business.
Advice from the Experts
Clubillion’s developers could have easily avoided this leak if they had taken some basic security measures to protect the database. These include, but are not limited to:
- Securing their servers.
- Implementing proper access rules.
- Never leaving a system that doesn’t require authentication open to the internet.
Any company can replicate the same steps, no matter its size.
For a more in-depth guide on how to protect your business, check out our guide to securing your website and online database from hackers.
For Clubillion Users
If you play on Clubillion and are concerned about how this breach might impact you, contact the app’s developers directly to find out what steps it’s taking to protect your data.
To learn about data vulnerabilities in general, read our complete guide to online privacy.
It shows you the many ways cybercriminals target internet users, and the steps you can take to stay safe.
How and Why We Discovered the Breach
The vpnMentor research team discovered the breach in Clubillion’s database as part of a huge web mapping project. Our researchers use port scanning to examine particular IP blocks and test different systems for weaknesses or vulnerabilities. They examine each weakness for any data being leaked.
Our team was able to access this database because it was completely unsecured and unencrypted.
Whenever we find a data breach, we use expert techniques to verify the owner of the database, usually a commercial company.
As ethical hackers, we’re obliged to inform a company when we discover flaws in their online security. We reached out to Clubillion’s developers, not only to let them know about the vulnerability but also to suggest ways in which they could make their system secure.
These ethics also mean we carry a responsibility to the public. Clubillion users must be aware of a data breach that exposes so much of their sensitive data.
The purpose of this web mapping project is to help make the internet safer for all users.
Source: Latest News on European Gaming Media Network
This is a Syndicated News piece. Photo credits or photo sources can be found on the source article: Popular Gambling App Exposed Millions of Users in Massive Data Leak

Latest News
Former Sky Bet strategist Andrew Mook joins Midnite as Head of Brand Marketing
Fast-growing UK sportsbook and casino Midnite has continued to strengthen its leadership team with the appointment of Andrew Mook as Head of Brand Marketing.
Mook joins Midnite having most recently been Head of Marketing Strategy & Planning at Flutter. Prior to that, he was Head of Creative Strategy at Sky Bet.
It is the latest high-profile hire for Midnite, after the appointment in April of Mook’s former Sky Bet colleague Zach Amin as Vice-President of Sportsbook.
Mook has been tasked with raising awareness of Midnite’s next-gen product among UK bettors and establishing a brand strategy and identity as the company aims to build on recent marketing activities including sponsorship of the 2025 World Snooker Championship and launching its first TV advertising campaign.
He said: “Midnite is the most exciting name in UK betting right now. There’s a genuine ambition here to shake things up and do things differently. The opportunity to help shape the brand at this stage of its growth is incredibly rare, and I’m thrilled to be on board.”
Midnite’s sportsbook was launched in 2018 by Nick Wright and Daniel Qu, who previously created daily fantasy sports platform Dribble in partnership with Sky Bet.
The brand is focused on disrupting the UK betting market, prioritising the player experience with a slick website and app and a brand platform designed to speak to a new generation of players.
Wright said: “Andrew brings a wealth of experience from some of the biggest names in the industry, but what really stood out was his passion for building bold, creative brands. As we continue to grow, having someone like Andrew to lead our brand marketing efforts is a huge asset.”
The post Former Sky Bet strategist Andrew Mook joins Midnite as Head of Brand Marketing appeared first on European Gaming Industry News.
Latest News
BETER Names Adam Conway as General Manager of Esports Business Division
Seasoned esports professional joins fast-betting content provider, bringing over 20 years of trading and product experience to elevate its offering
BETER, an award-winning provider of fast-betting content, data, and live streaming for esports and sports, has appointed former SIS senior executive Adam Conway as its new General Manager of Esports Business Division, significantly strengthening the company’s position in the market.
Conway is a highly accomplished manager in the betting industry, with more than 20 years of experience in overseeing and launching successful product portfolios.
Adam joins BETER following a ten-year tenure at SIS, where he held various positions—from Head of Trading to Global Head of Esports and Competitive Gaming. Before SIS, he held roles at several companies, including Head of Trading at betting powerhouse Ladbrokes.
As Esports General Manager at BETER, Adam will be responsible for strengthening the provider’s leadership in the fast-betting domain, as well as developing and expanding the number of in-house events for the company’s flagship ESportsBattle tournaments, which currently feature disciplines such as eFootball, eBasketball, and eHockey.
Conway will spearhead the development of new disciplines—eCricket and eTennis are set to launch soon—and focus on enhancing relationships with existing clients while establishing new partnerships.
Adam will lead a team of over 200 specialists and 500 professional athletes, delivering more than 500,000 esports events annually across four countries. He will also work closely with key industry bodies, including the Esports Integrity Commission (ESIC) and the International Betting Integrity Association (IBIA).
Gal Ehrlich, CEO at BETER, said: “Adam’s background in esports is unmatched, and we are thrilled to have him on board as we continue to enhance our esports offering, especially our flagship ESportsBattle tournaments.
“We’re already the go-to provider for fast-betting content, data, and live streaming in esports and sports. With Adam as our Esports General Manager, we’re confident we’ll strengthen that leadership and further distance ourselves from the competition.
“We’re excited to welcome Adam and look forward to the significant value his expertise will bring to our partners worldwide.”
Adam Conway, Esports General Manager at BETER, added: “It’s an honour to join BETER and contribute my extensive experience in trading and product development to such a pioneering company.
“BETER is the undisputed market leader, and I’m excited to help ensure it remains at the forefront—delivering exceptional products to operator partners and bettors alike.”
The post BETER Names Adam Conway as General Manager of Esports Business Division appeared first on European Gaming Industry News.
Latest News
Hit the red line and massive payouts in Vegas Velocity from Rival
Speed down The Strip towards the game’s 10,000x max payout, boosted by Expanding Turbo Wilds and an Overdrive Respin feature
Experience the neon lights and pulsing rhythm of the City of Sin in Vegas Velocity from Rival. This is a slot where players shift into gear and hit the gas as they race towards big wins.
Vegas Velocity sees players strap in for a thrill ride like no other, lighting up the reels with Expanding Turbo Wild symbols and an Overdrive Re-spin feature.
This is one of the studio’s most visually striking games to date, capturing the electrifying glow of the Las Vegas strip, which flashes past as players speed towards the game’s 10,000x max win potential.
The action hits the red line when Expanding Turbo Wild Symbols drop onto the reels. They can land on reels two, three or four and light up the reel (literally), substituting for all symbols to boost wins.
There’s also the Overdrive Re-spin Feature for added adrenaline-fuelled action. When a Wild Car symbol is part of a win, it expands to fill the whole reel.
It then Locks into place for a free Overdrive Respin. Any additional Wild Cars that form a win during the respin award another Overdrive Respin.
This occurs until there are no more Respins in play, and the feature then U-turns back to the base game.
Vegas Velocity is set across five reels and three rows with ten paylines active in the base game. This is a highly volatile slot with a score of 5/5.
Operators can choose from a range of RTPs including 92.62%, 94.64% and 96.00%, which is the game’s default Return to Player setting.
Ryan Maclean, Head of Games at Rival, said: “Vegas Velocity offers players a fast-paced thrill ride where the adrenaline builds with each spin as they speed towards massive wins.
“The game captures the electrifying excitement of The Strip and where neon lights pulse to the beat of the city.
“By keeping the pedal to the metal, players can trigger high-octane bonuses such as Expanding Turbo Wilds and Overdrive Respin, which help them shift up a gear and hit the game’s biggest payouts.
“This is a strong addition to our growing game portfolio, and we look forward to seeing players buckle up, hit the gas, and light up the reels in what is one of our most explosive slots yet.”
The post Hit the red line and massive payouts in Vegas Velocity from Rival appeared first on European Gaming Industry News.
-
Latest News1 month ago
Exclusive Q&A With Bar Konson, Chief Business Development Officer at NuxGame
-
Latest News1 month ago
SARA TENDULKAR JOINS JETSYNTHESYS’ GLOBAL E-CRICKET PREMIER LEAGUE AS MUMBAI FRANCHISE OWNER FOR SEASON 2
-
Latest News3 weeks ago
Week 17/2025 slot games releases
-
Latest News3 weeks ago
Fortuna Partners with 2025 UEFA Under-21 EURO
-
Latest News4 weeks ago
Esports World Cup Foundation Confirms Full Game Lineup, Schedule, and Club Championship Rules for EWC 2025
-
Latest News5 days ago
ELA Games Receives Key Nomination at EGR Marketing & Innovation Awards
-
Latest News1 month ago
DreamPlay consolidates its status as a global player in the iGaming industry and opens an office and campus in Cyprus
-
Latest News4 weeks ago
ACR POKER’S NEXT HIGH STAKES ADVENTURE TAKES PLAYERS TO MONTENEGRO FOR PRESTIGIOUS SUPER HIGH ROLLER SERIES
You must be logged in to post a comment Login