Latest News
Popular Gambling App Exposed Millions of Users in Massive Data Leak


Led by Noam Rotem and Ran Locar, vpnMentor’s research team discovered a data breach on casino gambling app Clubillion.
The breach originated in a technical database built on an Elasticsearch engine and was recording the daily activities of millions of Clubillion players around the world.
Aside from leaking activity on the app, the breached database also exposed private user information.
With this information publicly available, Clubillion’s users were vulnerable to fraud and various online attacks with potentially devastating results.
Company Profile
Clubillion is a free online casino game available for iOS and Android, offering players 30+ free slot games. While each app is listed under a different developer – Ouroboros on iOS and T7 Games on Android – these are most likely owned by the same company.
Both versions of Clubillion were released in 2019 and became instant hits. Each is now ranked the #1 ‘social slots’ casino app on Google Play and the App Store, with a 4.8 star on both.
Timeline of Discovery and Owner Reaction
Sometimes, the extent of a data breach and the owner of the database are obvious, and the issue quickly resolved. But rare are these times. Most often, we need days of investigation before we understand what’s at stake or who’s leaking the data.
Understanding a breach and its potential impact takes careful attention and time. We work hard to publish accurate and trustworthy reports, ensuring everybody who reads them understands their seriousness.
Some affected parties deny the facts, disregarding our research, or playing down its impact. So, we need to be thorough and make sure everything we find is correct and accurate.
In this case, the database was built on Elasticsearch and hosted on Amazon Web Services (AWS), with Clubillion’s name on its apps, and links to assets owned by the company.
Once Clubillion was confirmed as the owner of the database, we reached out to the developers. While awaiting a reply, we also contacted AWS with details of the leak. It was closed a few days later.
- Date discovered: 19th March 2020
- Date vendors contacted: 23rd March 2020
- Date of contact with AWS: 31st March 2020
- Date of Action: Approx. 5th April 2020
Example of Entries in the Database
Clubillion’s exposed database contained technical logs for millions of Clubillion users around the world, on both iOS and Android devices. Every time an individual player took any action on the app, a record was logged. Examples of records include:
- “enter game”
- “win”
- “lose”
- “update account”
- “create account”
During our investigation of the database, new entries continued to appear continuously. We estimated an average of approximately 200 million records per day – and sometimes, considerably more.
In total, this amounted to over 50GB of exposed records in the database every single day.
Within many of these records, were various forms of user Personally Identifiable Information (PII) data, including:
- IP addresses
- Email addresses
- Winnings
- Private messages
This data breach was truly global, with millions of records originating from Clubillion’s daily users all over the world. The following list is just a sample of countries affected, along with the average number of daily users from each country:
- USA – 10,000+
- UK – 2,475+
- France – 1,650+
- Israel – 408+
- Germany – 1,582+
- Spain – 1,026+
- Italy – 2,407+
- Netherlands – 622+
- Australia – 6,251+
- Canada – 7,792+
- Brazil – 3,859+
- Sweden – 191+
- Russia – 547+
Other countries affected included Uzbekistan, India, Poland, Romania, Vietnam, Lebanon, Indonesia, Philippines, Pakistan, Thailand, Austria, Hungry, and Latvia.
As you can see, on a single day, 10,000s of individual Clubillion players were exposed. Each one of these players could be targeted by malicious hackers for fraud and cyberattacks – along with millions more whose records were also contained in the database.
Data Breach Impact
Studies have shown that free gambling and gaming apps are especially prone to attacks and hacking from cybercriminals. They are routinely targeted for theft of private data and embedding malicious software on users’ devices.
Despite their popularity, gambling and casino apps often lack transparency, and it can be impossible to know what steps they’re taking to prevent cybercriminals successfully targeting their users.
One study of 23,000 free gambling apps found that: 3,200 posed a ‘moderate risk’ to users; 379 had known security vulnerabilities; 52 contained malicious software.
Any of these issues could be exploited to target app users in a wide range of frauds and cyberattacks, and Clubillion is no different.
With the exposed user PII and knowledge of their activity on the app, hackers could create elaborate schemes to defraud users. For example, some entries also included transaction errors for attempted card payments on Clubillion.
With the information in these transaction errors, hackers could target users with phishing campaigns, with the following aims:
- Trick them into providing their credit card details
- Trick them into providing additional PII to be used against them in further fraud
- Clicking a link that embeds malware, spyware, or ransomware onto their device.
If cybercriminals used Clubillion to embed malware or similar onto a user’s phone, they could potentially hack other apps, access files stored on the device, make calls, and send texts from the hacked device. They could even access a user’s phone contacts and steal the PII data of their friends and family.
Worse still, as people across the globe now find themselves under quarantine or self-isolation, as a result of the Coronavirus pandemic, the impact of a leak like this is potentially even more significant.
Clubillion stands to gain many new users, along with regular users playing more frequently. Hackers will be aware of this and looking for opportunities to exploit any vulnerabilities in the data security of such a massively popular app.
Had criminal hackers discovered Clubillion’s database, they could have targeted millions of people around the world, with devastating results.
Impact on Clubillion and it’s Developers
The most immediate risk for Clubillion is the loss of players. Data security is a growing concern for everyone these days, and this leak could turn many players off the app. Clubillion is not unique, and players have plenty of other choices for free gambling apps.
With fewer players, Clubillion will lose advertising revenue and reduced profits.
As many of Clubillion’s players reside within the EU, the app is under the jurisdiction of GDPR. The rules of GDPR also apply to apps, and Clubillion will need to take specific actions to ensure the regulatory body in charge doesn’t reprimand it.
Finally, Clubillion could also potentially be removed from Google Play and the App Store. Both Apple and Google are clamping down on apps that pose a risk to their users, removing apps embedded with malware, and taking data leaks much more seriously.
Each of these outcomes has a different likelihood of happening, but they would all negatively impact Clubillion’s revenue and business.
Advice from the Experts
Clubillion’s developers could have easily avoided this leak if they had taken some basic security measures to protect the database. These include, but are not limited to:
- Securing their servers.
- Implementing proper access rules.
- Never leaving a system that doesn’t require authentication open to the internet.
Any company can replicate the same steps, no matter its size.
For a more in-depth guide on how to protect your business, check out our guide to securing your website and online database from hackers.
For Clubillion Users
If you play on Clubillion and are concerned about how this breach might impact you, contact the app’s developers directly to find out what steps it’s taking to protect your data.
To learn about data vulnerabilities in general, read our complete guide to online privacy.
It shows you the many ways cybercriminals target internet users, and the steps you can take to stay safe.
How and Why We Discovered the Breach
The vpnMentor research team discovered the breach in Clubillion’s database as part of a huge web mapping project. Our researchers use port scanning to examine particular IP blocks and test different systems for weaknesses or vulnerabilities. They examine each weakness for any data being leaked.
Our team was able to access this database because it was completely unsecured and unencrypted.
Whenever we find a data breach, we use expert techniques to verify the owner of the database, usually a commercial company.
As ethical hackers, we’re obliged to inform a company when we discover flaws in their online security. We reached out to Clubillion’s developers, not only to let them know about the vulnerability but also to suggest ways in which they could make their system secure.
These ethics also mean we carry a responsibility to the public. Clubillion users must be aware of a data breach that exposes so much of their sensitive data.
The purpose of this web mapping project is to help make the internet safer for all users.
Source: Latest News on European Gaming Media Network
This is a Syndicated News piece. Photo credits or photo sources can be found on the source article: Popular Gambling App Exposed Millions of Users in Massive Data Leak

Latest News
Playson casts its lucky charm in 4 Pots Riches: Hold and Win
New Super Pots Bonus Game among thrilling features in highly anticipated sequel
Playson, the accomplished digital entertainment supplier, welcomes the return of its lucky leprechaun in the charming new release, 4 Pots Riches: Hold and Win, with the mischievous figure on hand to elevate wins with a host of enriched features.
The highlight is the Super Pot Bonus Game, which is triggered by the Super Clover Bonus Symbol. It begins with an expanded 5×5 grid, which offers more space for Bonus symbols and Pot Features. This special mode includes one or more Pot Features and gives players the chance to win the Super Jackpot of 10,000x by filling all 25 cells.
During the Hold and Win Bonus Game, players can activate one or more of the following three Pot Features:
Multi Feature – Violet Clover Bonus applies up to three multipliers (x2, x3, x5) to enhance payouts.
Collect Feature – Blue Clover Bonus gathers all visible symbol values and adds them to its own.
Mystery Feature – Red Clover Bonus reveals Mini, Minor, or Major Jackpots, or high-value prizes up to 75x.
In all Bonus Games, players can aim to land 15 Bonus symbols to win the Grand Jackpot (3,000x). The Golden Pot may also appear and transform into an additional Clover Bonus symbol to boost feature potential.
The random appearance of Mini, Minor or Grand Jackpots during bonus play can also trigger one of three corresponding in-game jackpots, whilst the Grand Jackpot stands at 3,000x in the Bonus Game and 10,000x in the Super Pot Bonus.
Through its folklore adventure, Playson underlines its ability to introduce captivating new iterations to its beloved 3 Pots family, blending stimulating audiovisual effects with mechanics that have proven a global success with players.
Tamas Kusztos, CCO at Playson, said: “4 Pots Riches: Hold and Win brings fresh Irish charm to one of our most popular game series, combining player-favourite mechanics with exciting new features like the Super Pot Bonus Game.
“With its vibrant theme and generous modifiers, this release showcases our commitment to evolving gameplay while maintaining the core entertainment that our players love.”
The post Playson casts its lucky charm in 4 Pots Riches: Hold and Win appeared first on European Gaming Industry News.
Latest News
Bally’s Corporation Joins Nottingham Forest as New Front of Shirt Partner
Bally’s Corporation has become the new front of shirt partner of Nottingham Forest.
The Bally’s Corporation logo will feature on the men’s first team shirts and across the City Ground during the 2025/26 season. It’s an exciting time for a new partner to join forces with the Club, which is set to compete in its fourth consecutive Premier League campaign having also qualified for European competition for the first time in 30 years.
The sponsorship deal follows Bally’s continued expansion in the UK market, including its acquisition of Aspers Casino in Newcastle and its recent multi-year partnership to operate the Monopoly licence across multiple markets that already include the UK, Spain, Canada and the US. The partnership with Nottingham Forest marks another strategic milestone in Bally’s’ international growth, complementing its expanding portfolio of destinations and brands, which in the UK also includes Virgin Games, Jackpotjoy and Double Bubble Bingo sites, where players can enjoy a broad range of online slots, casino, bingo and free games as well as sports betting.
Nottingham Forest owner Evangelos Marinakis said: “I would like to welcome Bally’s Corporation to the Forest family. We are on a special journey – we are determined to keep achieving incredible things and strengthening our global partnerships is an important part of this. As our Club continues to thrive both on and off the pitch, we’re looking forward to working with Bally’s on a number of exciting initiatives, helping us to engage with our growing fanbase within Nottinghamshire and around the world.”
Robeson Reeves, Chief Executive of Bally’s Corporation, said: “Bally’s has always been dedicated to delivering exceptional entertainment, from our renowned resort destinations to our popular gaming platforms. Partnering with Nottingham Forest, an iconic club with a proud history and passionate fanbase, is a natural fit for us. We’re excited to bring our global brand to the Premier League stage, introduce new audiences to the club, and collaborate on initiatives that make a meaningful impact both locally and internationally. On behalf of everyone at Bally’s, we wish the Reds every success for the season ahead.”
The post Bally’s Corporation Joins Nottingham Forest as New Front of Shirt Partner appeared first on European Gaming Industry News.
Latest News
Amusnet Sparks Excitement Among Italian Operators and Players with Royal Coins Saga Event
Amusnet has strengthened its presence in the Italian iGaming market with the successful completion of the Royal Coins Saga tournament, held throughout July. Organised in collaboration with over 20 operator partners and featuring a €20,000 prize pool, the campaign attracted strong player participation and delivered significant results across all participating platforms.
Powered by Amusnet’s recently launched Tournament Tool, the campaign delivered a dynamic, competitive experience that enhanced the player engagement. The tool allows full customisation of event rules, duration, ranking criteria and prize structure, supported by a real-time leaderboard and intuitive setup. With flexible mechanics and varied reward types, it empowers operators to run impactful, tailored campaigns. Its strong performance in Italy reaffirmed its value as a trusted engagement solution, praised for its simplicity and measurable results.
The tournament showcased eight of Amusnet’s most popular titles in the Italian market, including Shining Crown, Royal Secrets, Extra Crown, 20 Extra Crown, Coin Gobbler, 20 Golden Coins, 40 Golden Coins and 100 Golden Coins. These titles continue to resonate with local audiences, combining engaging gameplay with proven appeal that helps operators deliver an enhanced entertainment experience.
Branded with the slogan “Gioca, Conquista, Regna” (Play, Conquer, Rule), the campaign received extensive visibility across participating operator platforms.
Polina Nedyalkova, Director at Amusnet Italy, said: “Italy remains a key focus market for us as we continue to expand our footprint and enrich our offering. Campaigns like Royal Coins Saga are an essential part of our commitment to delivering experiences that bring value to both players and partners.”
The post Amusnet Sparks Excitement Among Italian Operators and Players with Royal Coins Saga Event appeared first on European Gaming Industry News.
-
Latest News2 months ago
LEGENDS by Fire & Ice: July 1st at The BOX Soho
-
Latest News2 months ago
New Resort & Casino Selects IvedaAI for Intelligent Video Surveillance Ahead of Grand Opening
-
Latest News3 months ago
S8UL acquires North America’s leading Mobile Legends: Bang Bang roster ahead of Esports World Cup 2025
-
Latest News2 months ago
HIPTHER Movement Launched: Fitness Community & Summer Run-Off Challenge Powered by GameOn
-
Latest News1 month ago
Brand-new projects debuting at iGB L!VE: Casino&You and Win&You Partners!
-
Latest News3 months ago
StarLadder to Host 2025 CS2 Major in Budapest’s 20,000-Seat MVM Dome
-
Latest News3 months ago
Fueling the Fast Lane: Play’n GO Music and MoneyGram Haas F1 Team Drop Esteban Ocon’s High-Octane Playlist: ‘Ocon’s Drive’
-
Latest News3 months ago
AA Gaming Announce the Rajasthan State Esports Championship (RSEC) with Youth Affairs & Sports Department, Govt. Of Rajasthan
You must be logged in to post a comment Login