Connect with us

Latest News

Popular Gambling App Exposed Millions of Users in Massive Data Leak

Published

on

Popular Gambling App Exposed Millions of Users in Massive Data Leak
Popular Gambling App Exposed Millions of Users in Massive Data LeakReading Time: 5 minutes

 

Led by Noam Rotem and Ran Locar, vpnMentor’s research team discovered a data breach on casino gambling app Clubillion.

The breach originated in a technical database built on an Elasticsearch engine and was recording the daily activities of millions of Clubillion players around the world.

Aside from leaking activity on the app, the breached database also exposed private user information.

With this information publicly available, Clubillion’s users were vulnerable to fraud and various online attacks with potentially devastating results.

Company Profile

Clubillion is a free online casino game available for iOS and Android, offering players 30+ free slot games. While each app is listed under a different developer – Ouroboros on iOS and T7 Games on Android – these are most likely owned by the same company.

Both versions of Clubillion were released in 2019 and became instant hits. Each is now ranked the #1 ‘social slots’ casino app on Google Play and the App Store, with a 4.8 star on both.

Timeline of Discovery and Owner Reaction

Sometimes, the extent of a data breach and the owner of the database are obvious, and the issue quickly resolved. But rare are these times. Most often, we need days of investigation before we understand what’s at stake or who’s leaking the data.

Understanding a breach and its potential impact takes careful attention and time. We work hard to publish accurate and trustworthy reports, ensuring everybody who reads them understands their seriousness.

Some affected parties deny the facts, disregarding our research, or playing down its impact. So, we need to be thorough and make sure everything we find is correct and accurate.

In this case, the database was built on Elasticsearch and hosted on Amazon Web Services (AWS), with Clubillion’s name on its apps, and links to assets owned by the company.

Once Clubillion was confirmed as the owner of the database, we reached out to the developers. While awaiting a reply, we also contacted AWS with details of the leak. It was closed a few days later.

  • Date discovered: 19th March 2020
  • Date vendors contacted: 23rd March 2020
  • Date of contact with AWS: 31st March 2020
  • Date of Action: Approx. 5th April 2020

Example of Entries in the Database

Clubillion’s exposed database contained technical logs for millions of Clubillion users around the world, on both iOS and Android devices. Every time an individual player took any action on the app, a record was logged. Examples of records include:

  • “enter game”
  • “win”
  • “lose”
  • “update account”
  • “create account”

During our investigation of the database, new entries continued to appear continuously. We estimated an average of approximately 200 million records per day – and sometimes, considerably more.

In total, this amounted to over 50GB of exposed records in the database every single day.

Within many of these records, were various forms of user Personally Identifiable Information (PII) data, including:

  • IP addresses
  • Email addresses
  • Winnings
  • Private messages

This data breach was truly global, with millions of records originating from Clubillion’s daily users all over the world. The following list is just a sample of countries affected, along with the average number of daily users from each country:

  • USA – 10,000+
  • UK – 2,475+
  • France – 1,650+
  • Israel – 408+
  • Germany – 1,582+
  • Spain – 1,026+
  • Italy – 2,407+
  • Netherlands – 622+
  • Australia – 6,251+
  • Canada – 7,792+
  • Brazil – 3,859+
  • Sweden – 191+
  • Russia – 547+

Other countries affected included Uzbekistan, India, Poland, Romania, Vietnam, Lebanon, Indonesia, Philippines, Pakistan, Thailand, Austria, Hungry, and Latvia.

As you can see, on a single day, 10,000s of individual Clubillion players were exposed. Each one of these players could be targeted by malicious hackers for fraud and cyberattacks – along with millions more whose records were also contained in the database.

Data Breach Impact

Studies have shown that free gambling and gaming apps are especially prone to attacks and hacking from cybercriminals. They are routinely targeted for theft of private data and embedding malicious software on users’ devices.

Despite their popularity, gambling and casino apps often lack transparency, and it can be impossible to know what steps they’re taking to prevent cybercriminals successfully targeting their users.

One study of 23,000 free gambling apps found that: 3,200 posed a ‘moderate risk’ to users; 379 had known security vulnerabilities; 52 contained malicious software.

Any of these issues could be exploited to target app users in a wide range of frauds and cyberattacks, and Clubillion is no different.

With the exposed user PII and knowledge of their activity on the app, hackers could create elaborate schemes to defraud users. For example, some entries also included transaction errors for attempted card payments on Clubillion.

With the information in these transaction errors, hackers could target users with phishing campaigns, with the following aims:

  1. Trick them into providing their credit card details
  2. Trick them into providing additional PII to be used against them in further fraud
  3. Clicking a link that embeds malware, spyware, or ransomware onto their device.

If cybercriminals used Clubillion to embed malware or similar onto a user’s phone, they could potentially hack other apps, access files stored on the device, make calls, and send texts from the hacked device. They could even access a user’s phone contacts and steal the PII data of their friends and family.

Worse still, as people across the globe now find themselves under quarantine or self-isolation, as a result of the Coronavirus pandemic, the impact of a leak like this is potentially even more significant.

Clubillion stands to gain many new users, along with regular users playing more frequently. Hackers will be aware of this and looking for opportunities to exploit any vulnerabilities in the data security of such a massively popular app.

Had criminal hackers discovered Clubillion’s database, they could have targeted millions of people around the world, with devastating results.

Impact on Clubillion and it’s Developers

The most immediate risk for Clubillion is the loss of players. Data security is a growing concern for everyone these days, and this leak could turn many players off the app. Clubillion is not unique, and players have plenty of other choices for free gambling apps.

With fewer players, Clubillion will lose advertising revenue and reduced profits.

As many of Clubillion’s players reside within the EU, the app is under the jurisdiction of GDPR. The rules of GDPR also apply to apps, and Clubillion will need to take specific actions to ensure the regulatory body in charge doesn’t reprimand it.

Finally, Clubillion could also potentially be removed from Google Play and the App Store. Both Apple and Google are clamping down on apps that pose a risk to their users, removing apps embedded with malware, and taking data leaks much more seriously.

Each of these outcomes has a different likelihood of happening, but they would all negatively impact Clubillion’s revenue and business.

Advice from the Experts

Clubillion’s developers could have easily avoided this leak if they had taken some basic security measures to protect the database. These include, but are not limited to:

  1. Securing their servers.
  2. Implementing proper access rules.
  3. Never leaving a system that doesn’t require authentication open to the internet.

Any company can replicate the same steps, no matter its size.

For a more in-depth guide on how to protect your business, check out our guide to securing your website and online database from hackers.

For Clubillion Users

If you play on Clubillion and are concerned about how this breach might impact you, contact the app’s developers directly to find out what steps it’s taking to protect your data.

To learn about data vulnerabilities in general, read our complete guide to online privacy.

It shows you the many ways cybercriminals target internet users, and the steps you can take to stay safe.

How and Why We Discovered the Breach

The vpnMentor research team discovered the breach in Clubillion’s database as part of a huge web mapping project. Our researchers use port scanning to examine particular IP blocks and test different systems for weaknesses or vulnerabilities. They examine each weakness for any data being leaked.

Our team was able to access this database because it was completely unsecured and unencrypted. 

Whenever we find a data breach, we use expert techniques to verify the owner of the database, usually a commercial company.

As ethical hackers, we’re obliged to inform a company when we discover flaws in their online security. We reached out to Clubillion’s developers, not only to let them know about the vulnerability but also to suggest ways in which they could make their system secure.

These ethics also mean we carry a responsibility to the public. Clubillion users must be aware of a data breach that exposes so much of their sensitive data.

The purpose of this web mapping project is to help make the internet safer for all users.

 

Source


Source: Latest News on European Gaming Media Network
This is a Syndicated News piece. Photo credits or photo sources can be found on the source article: Popular Gambling App Exposed Millions of Users in Massive Data Leak

George Miller (Gyorgy Molnar) started his career in content marketing and has started working as an Editor/Content Manager for our company in 2016. George has acquired many experiences when it comes to interviews and newsworthy content becoming Head of Content in 2017. He is responsible for the news being shared on multiple websites that are part of the European Gaming Media Network.

Latest News

Play’n GO games now live with Ivy Casino in the UK

Published

on

Swedish gaming giant’s industry signals commitment to the UK regulated market by launching it leading portfolio of games with Ivy Casino 

Play’n GO, the world’s leading casino entertainment provider, has today announced that its industry leading portfolio of games is now live with Ivy Casino in the UK. 

Ivy Casino’s players in the United Kingdom can now access global smash hits from Play’n GO, including Book of Dead, Legacy of Dead, and Rise of Olympus 100 among many others. 

Ivy Casino is a UK-facing online casino brand that launched in 2024 with a focus on delivering a premium, player-centric experience tailored specifically for the UK market. 

The brand operates alongside two sister sites, Rose Casino and O’Reels, which also serve UK audiences and share the same commitment to high-quality entertainment, strong user experience and robust responsible gaming standards. 

Play’n GO has been one of the leading game suppliers in the UK for many years and is steadfast in its commitment to regulated markets globally. 

Magnus Olsson, Chief Commercial Officer of Play’n GO, said:

“We are delighted to launch with Ivy Casino in the UK who, like us, are focused on all the key elements of operating within a regulated market framework. I’m sure this is just the beginning of a long and fruitful partnership.” 

Mark Good, representing Ivy Casino, said:

“This partnership with Play’n GO forms part of Ivy Casino’s ongoing strategy to enhance its content offering for UK players by collaborating with leading studios known for creative, engaging gameplay.” 

Play’n GO is a proud sponsor of the Moneygram Haas Formula 1 team, and recently launched a fashion brand, Play’n GO Shop, to sit alongside its existing Play’n GO Music brand to give fans more ways to connect with Play’n GO. 

In October, Play’n GO set a world record by launching everyone’s favourite slot character, Garga, into space reaching a height of over 35,500m as part of the launch campaign for Reactoonz 100 which instantly became one of the biggest game launches of the year for the company. 

The post Play’n GO games now live with Ivy Casino in the UK appeared first on Gaming and Gambling Industry Newsroom.

Continue Reading

Latest News

Esportes da Sorte strengthens brand presence during New Year’s Eve celebrations across four Brazilian capitals

Published

on

Esportes da Sorte, one of Brazil’s leading online betting platforms, will be the official sponsor of New Year’s Eve celebrations in four Brazilian capitals: Salvador, Recife, Natal and Maceió. The initiative reinforces the brand’s growing presence in the national cultural calendar and its strategy to connect with large-scale public celebrations beyond the digital environment.

New Year’s Eve is one of Brazil’s most significant annual moments, marked by intense domestic travel, international tourism and mass public participation. By supporting celebrations in four key destinations, Esportes da Sorte aligns its brand with tradition, culture and shared experiences that resonate deeply with local communities.

“Sponsoring New Year’s Eve celebrations in four capitals reflects our commitment to being present in moments that bring people together,” said Marcela Campos, Vice President of the Esportes Gaming Brasil Group, owner of the Esportes da Sorte brand. “Supporting these cities means valuing their cultural identity, strengthening local ecosystems and celebrating the people who keep these traditions alive year after year.”

Across all four capitals, the brand will activate its presence through immersive experiences, public-facing activations and the distribution of branded giveaways — a hallmark of Esportes da Sorte’s engagement strategy at major events. The activations are designed to enhance the festive atmosphere while reinforcing the brand’s connection with culture, entertainment and responsible enjoyment.

The New Year’s Eve sponsorships build on Esportes da Sorte’s broader cultural engagement strategy, which includes long-standing support for large-scale events such as Carnatal, in Rio Grande do Norte — a key fixture in the state’s tourism and cultural calendar. Together, these initiatives reflect the company’s commitment to expanding its footprint in cultural sponsorships nationwide.

Esportes da Sorte’s participation also mirrors a wider trend within Brazil’s regulated betting market, as operators increasingly diversify their sponsorship portfolios beyond football. Music, festivals and cultural celebrations have become strategic platforms for brands seeking broader visibility, deeper community ties and more sustainable engagement with the public.

The post Esportes da Sorte strengthens brand presence during New Year’s Eve celebrations across four Brazilian capitals appeared first on Gaming and Gambling Industry Newsroom.

Continue Reading

Latest News

Holi Primed For Emerging Markets Via New QTech Games Partnership

Published

on

Emerging-markets leader expands its live-games offering with new games from rising star supplier

 QTech Games, the leading game aggregator for all emerging markets, has announced its latest partnership with live-games provider Holi, allowing its platform clients access to another positively delineated portfolio.

Integrating content from one of the more colourful and creative digital slots providers adds yet more variety to QTech Games’ premier platform, which is taking the widest range of online games to emerging territories with established names sitting alongside the industry’s most exciting up-and-coming providers.

Holi is the absolute embodiment in the latter rising-star category, reimagining the live-gaming experience through the power of aesthetics in content which delivers a unique and simplified gambling experience, underscored by reliability. Colourful-yet-familiar “light” table games, such as roulette and baccarat, are now overcoming local obstacles to engagement in emerging markets, like handset quality limitations, restricted access to fast networks, and high data costs.

Philip Doftvik, QTech Games’ CEO, said: “We will continue to add fresh content to the platform, prioritising suppliers who provide unique, localised content – and Holi’s light, colourful live games fit the bill perfectly. Their content brings a new level of energy and engagement that we’re thrilled to share across our growing network.”

Inga Vakulcika, Chief Product Officer at Holi, added: “Holi is artfully fusing craft and technology to create more aesthetically pleasing live games that turn local players’ heads – that means captivating, colourful graphics for a top-notch gaming experience. We look forward to seeing how our unique games perform when placed in front of new audiences via QTech’s emerging-market operators.”

The post Holi Primed For Emerging Markets Via New QTech Games Partnership appeared first on Gaming and Gambling Industry Newsroom.

Continue Reading

Trending

EEGaming.org is part of HIPTHER, parent brand of various prominent news outlets and international conferences. These platforms and events span a wide range of industries, including Entertainment, Technology, Gaming and Gambling, Blockchain, Artificial Intelligence, Fintech, Quantum Technology, Legal Cannabis, Health and Lifestyle, VR/AR, eSports, and several others. This indicates that EEGaming.org is part of a larger network that focuses on a diverse array of sectors, particularly those related to cutting-edge technology and modern lifestyle trends.

Contact us: [email protected]

Editorial / PR Submissions: [email protected]

Copyright © 2015 - 2025 HIPTHER. All Rights Reserved. Registered in Romania under Proshirt SRL, Company number: 2134306, EU VAT ID: RO21343605. Office address: Blvd. 1 Decembrie 1918 nr.5, Targu Mures, Romania

We are constantly showing banners about important news regarding events and product launches. Please turn AdBlock off in order to see these areas.