Latest News
Popular Gambling App Exposed Millions of Users in Massive Data Leak
Led by Noam Rotem and Ran Locar, vpnMentor’s research team discovered a data breach on casino gambling app Clubillion.
The breach originated in a technical database built on an Elasticsearch engine and was recording the daily activities of millions of Clubillion players around the world.
Aside from leaking activity on the app, the breached database also exposed private user information.
With this information publicly available, Clubillion’s users were vulnerable to fraud and various online attacks with potentially devastating results.
Company Profile
Clubillion is a free online casino game available for iOS and Android, offering players 30+ free slot games. While each app is listed under a different developer – Ouroboros on iOS and T7 Games on Android – these are most likely owned by the same company.
Both versions of Clubillion were released in 2019 and became instant hits. Each is now ranked the #1 ‘social slots’ casino app on Google Play and the App Store, with a 4.8 star on both.
Timeline of Discovery and Owner Reaction
Sometimes, the extent of a data breach and the owner of the database are obvious, and the issue quickly resolved. But rare are these times. Most often, we need days of investigation before we understand what’s at stake or who’s leaking the data.
Understanding a breach and its potential impact takes careful attention and time. We work hard to publish accurate and trustworthy reports, ensuring everybody who reads them understands their seriousness.
Some affected parties deny the facts, disregarding our research, or playing down its impact. So, we need to be thorough and make sure everything we find is correct and accurate.
In this case, the database was built on Elasticsearch and hosted on Amazon Web Services (AWS), with Clubillion’s name on its apps, and links to assets owned by the company.
Once Clubillion was confirmed as the owner of the database, we reached out to the developers. While awaiting a reply, we also contacted AWS with details of the leak. It was closed a few days later.
- Date discovered: 19th March 2020
- Date vendors contacted: 23rd March 2020
- Date of contact with AWS: 31st March 2020
- Date of Action: Approx. 5th April 2020
Example of Entries in the Database
Clubillion’s exposed database contained technical logs for millions of Clubillion users around the world, on both iOS and Android devices. Every time an individual player took any action on the app, a record was logged. Examples of records include:
- “enter game”
- “win”
- “lose”
- “update account”
- “create account”
During our investigation of the database, new entries continued to appear continuously. We estimated an average of approximately 200 million records per day – and sometimes, considerably more.
In total, this amounted to over 50GB of exposed records in the database every single day.
Within many of these records, were various forms of user Personally Identifiable Information (PII) data, including:
- IP addresses
- Email addresses
- Winnings
- Private messages
This data breach was truly global, with millions of records originating from Clubillion’s daily users all over the world. The following list is just a sample of countries affected, along with the average number of daily users from each country:
- USA – 10,000+
- UK – 2,475+
- France – 1,650+
- Israel – 408+
- Germany – 1,582+
- Spain – 1,026+
- Italy – 2,407+
- Netherlands – 622+
- Australia – 6,251+
- Canada – 7,792+
- Brazil – 3,859+
- Sweden – 191+
- Russia – 547+
Other countries affected included Uzbekistan, India, Poland, Romania, Vietnam, Lebanon, Indonesia, Philippines, Pakistan, Thailand, Austria, Hungry, and Latvia.
As you can see, on a single day, 10,000s of individual Clubillion players were exposed. Each one of these players could be targeted by malicious hackers for fraud and cyberattacks – along with millions more whose records were also contained in the database.
Data Breach Impact
Studies have shown that free gambling and gaming apps are especially prone to attacks and hacking from cybercriminals. They are routinely targeted for theft of private data and embedding malicious software on users’ devices.
Despite their popularity, gambling and casino apps often lack transparency, and it can be impossible to know what steps they’re taking to prevent cybercriminals successfully targeting their users.
One study of 23,000 free gambling apps found that: 3,200 posed a ‘moderate risk’ to users; 379 had known security vulnerabilities; 52 contained malicious software.
Any of these issues could be exploited to target app users in a wide range of frauds and cyberattacks, and Clubillion is no different.
With the exposed user PII and knowledge of their activity on the app, hackers could create elaborate schemes to defraud users. For example, some entries also included transaction errors for attempted card payments on Clubillion.
With the information in these transaction errors, hackers could target users with phishing campaigns, with the following aims:
- Trick them into providing their credit card details
- Trick them into providing additional PII to be used against them in further fraud
- Clicking a link that embeds malware, spyware, or ransomware onto their device.
If cybercriminals used Clubillion to embed malware or similar onto a user’s phone, they could potentially hack other apps, access files stored on the device, make calls, and send texts from the hacked device. They could even access a user’s phone contacts and steal the PII data of their friends and family.
Worse still, as people across the globe now find themselves under quarantine or self-isolation, as a result of the Coronavirus pandemic, the impact of a leak like this is potentially even more significant.
Clubillion stands to gain many new users, along with regular users playing more frequently. Hackers will be aware of this and looking for opportunities to exploit any vulnerabilities in the data security of such a massively popular app.
Had criminal hackers discovered Clubillion’s database, they could have targeted millions of people around the world, with devastating results.
Impact on Clubillion and it’s Developers
The most immediate risk for Clubillion is the loss of players. Data security is a growing concern for everyone these days, and this leak could turn many players off the app. Clubillion is not unique, and players have plenty of other choices for free gambling apps.
With fewer players, Clubillion will lose advertising revenue and reduced profits.
As many of Clubillion’s players reside within the EU, the app is under the jurisdiction of GDPR. The rules of GDPR also apply to apps, and Clubillion will need to take specific actions to ensure the regulatory body in charge doesn’t reprimand it.
Finally, Clubillion could also potentially be removed from Google Play and the App Store. Both Apple and Google are clamping down on apps that pose a risk to their users, removing apps embedded with malware, and taking data leaks much more seriously.
Each of these outcomes has a different likelihood of happening, but they would all negatively impact Clubillion’s revenue and business.
Advice from the Experts
Clubillion’s developers could have easily avoided this leak if they had taken some basic security measures to protect the database. These include, but are not limited to:
- Securing their servers.
- Implementing proper access rules.
- Never leaving a system that doesn’t require authentication open to the internet.
Any company can replicate the same steps, no matter its size.
For a more in-depth guide on how to protect your business, check out our guide to securing your website and online database from hackers.
For Clubillion Users
If you play on Clubillion and are concerned about how this breach might impact you, contact the app’s developers directly to find out what steps it’s taking to protect your data.
To learn about data vulnerabilities in general, read our complete guide to online privacy.
It shows you the many ways cybercriminals target internet users, and the steps you can take to stay safe.
How and Why We Discovered the Breach
The vpnMentor research team discovered the breach in Clubillion’s database as part of a huge web mapping project. Our researchers use port scanning to examine particular IP blocks and test different systems for weaknesses or vulnerabilities. They examine each weakness for any data being leaked.
Our team was able to access this database because it was completely unsecured and unencrypted.
Whenever we find a data breach, we use expert techniques to verify the owner of the database, usually a commercial company.
As ethical hackers, we’re obliged to inform a company when we discover flaws in their online security. We reached out to Clubillion’s developers, not only to let them know about the vulnerability but also to suggest ways in which they could make their system secure.
These ethics also mean we carry a responsibility to the public. Clubillion users must be aware of a data breach that exposes so much of their sensitive data.
The purpose of this web mapping project is to help make the internet safer for all users.
Source: Latest News on European Gaming Media Network
This is a Syndicated News piece. Photo credits or photo sources can be found on the source article: Popular Gambling App Exposed Millions of Users in Massive Data Leak
Latest News
EGT at ICE Barcelona 2025: Get ready to be stunned
EGT is prepared to make a long-lasting impression on visitors at ICE 2025, which will be held in Barcelona for the first time. The Bulgarian manufacturer of gaming equipment will showcase its compelling selection of bestsellers and high-potential new developments at one of the largest stands at the exhibition 3F30.
Among the novelties that will arouse the greatest interest will be 2 brand-new slot cabinets – 32-32 St and 32-32 Up. These models will certainly not go unnoticed by the event guests.
On display will be the newest addition to the company’s jackpot family – the 4-level Asian-themed Zhao Cai Shuang Yu. It will reveal the astonishing world of its 2 games, Prosperity Strike and Rising Coins.
The attendees will also be able to see and test the latest multigames from the Supreme Selection slot series. The Mega Supreme Fruits, Supreme Red, and Supreme Buy Bonus Prize Selection will present a lot of new slot titles, offering a perfect mix of fascinating themes, attractive bonus features, and great entertainment.
EGT will show its newest ETG developments as well. Among them will be the 32 T terminal, which will make its debut during the show. It will complement the company’s rich portfolio of ETG products, which are the preferred choice in numerous gaming venues around the world.
Expanding its offering, EGT will present the Supreme Series of game mixes, currently including the Supreme Roulette Union and Supreme Green Union multigames. Focusing exclusively on roulette, the Supreme Roulette Union blends the excitement of classic roulette gameplay with innovative jackpot systems and versatile features. Supreme Green Union combines popular games from the company’s portfolio with roulette, Keno, Baccarat, and Blackjack, offering players a unique and engaging experience.
Numerous new AWP and VLT products, created specifically for different markets, will also be at the visitors’ disposal, as well as the casino management system Spider, which will show its latest modules.
EGT Digital will also present its vast array of iGaming solutions, including instant and casino games, jackpots, and its in-house developed “all-in-one” betting platform X-Nave.
Nadia Popova, Chief Revenue Officer and VP Sales & Marketing at EGT, commented: “ICE is a very important event for us, which gives us the opportunity to meet with industry professionals from all over the world. We will welcome our current and potential new customers and partners at our stand to present them all new products from our portfolio, divided into zones, covering all gaming verticals. I believe in the positive potential of changes. That is why I think that the relocation of the show to Barcelona will open new business horizons and bring many opportunities for building fruitful partnerships, for which we as a company are ready. “
The post EGT at ICE Barcelona 2025: Get ready to be stunned appeared first on European Gaming Industry News.
Latest News
Vibra Group Completes the Acquisition of TSA
Go-to LatAm content and platform developer purchases longstanding Brazil-based tech development partner to accelerate growth plans
Vibra Group, the ‘go-to’ content and platform developer for the LatAm region, has acquired TSA, a Brazil-based technology company and one of its longest standing development partners.
The acquisition will further strengthen the award-winning company and accelerate its growth plans with 55 specialist platform development experts based in Northern Brazil.
TSA and Vibra Group have been long-term partners with TSA contributing significantly to Vibra’s technological growth. TSA, which operates under the ServiceNet brand name, also has existing contracts with several Brazilian lotteries including Loteria do Tocantins, Loteria do Maranhao, Loteria de Sergipe and Loteria da Paraíba.
The integration of TSA’s expert teams will immediately enhance Vibra’s platform development roadmap with additional resources dedicated to the Vibra Solutions business unit and will consolidate the Vibra Group’s structure across the LatAm region. The LatAm based team is focused on game studios, Remote Gaming Server (RGS), and Electronic Gaming Machines (EGM). The Brazil-based team specialising in Player Account Management (PAM) and sportsbook solutions.
Vibra’s product strategy is to service every client need delivering a complete solution on three core areas: sportsbook and casino platform with multiple levels of customization and flexibility; content aggregation platform including proprietary titles and third party games from the main brands in the industry; and a state-of-the-art EGM platform allowing operators to distribute products and content through VLT / retail terminals. The group’s 3 business divisions: Vibra Gaming, Vibra Solutions and Vibra VLT / Retail.
Ramiro Atucha, CEO, Vibra Group, said: “We’re delighted to close the acquisition of TSA and welcome the team to the Vibra family. TSA are one of our closest and most trusted partners with whom we’ve closely collaborated across several significant projects as well as ongoing development work, therefore joining forces makes perfect strategic sense.
“Our expansion and first M&A deal follows significant customer demand and growth across the LatAm region in the last 12 to 18 months so the timing is ideal. We’re very excited to have the TSA team join us as we continue our journey.”
Werter Luna, CEO, TSA, said: “We’re thrilled with the outcome of joining Ramiro and the Vibra team after having worked together for so long. The synergies were very clear and both companies know we are stronger together. The future is very bright and we’re ready to go on the ambitious plans we have to significantly grow our business.”
Founded five years ago by a management team of highly experienced industry experts with decades of land-based and online experience, Vibra has emerged as one of the most exciting and innovative content studios and software developers in the industry and rapidly grown to become the LatAm market’s ‘go-to’ partner for local and international operators.
The post Vibra Group Completes the Acquisition of TSA appeared first on European Gaming Industry News.
Latest News
GIANTX begins its 2025 LEC journey with fresh faces
The global esports organization GIANTX is ready to kick off its journey in the League of Legends EMEA Championship (LEC), Europe’s premier esports competition. With a revamped roster and a clear goal of qualifying for the 2025 Worlds in China, the team begins its campaign this Saturday with a challenging schedule.
Led by renowned coach André Guilhoto, the roster features Lot (toplaner), Closer (jungler), Jackies (midlaner), Noah (AD carry), and Jun (support). Jackies, the 2024 Rookie of the Year, returns as the only player from last year’s roster. Lot, a standout in the LFL, joins as a promising top laner. Closer, a three-time Worlds participant and North American champion, brings leadership and experience. Meanwhile, Noah and Jun, from Fnatic, aim to establish themselves as one of the best bot lanes in the LEC.
GIANTX continues to rely on advanced data analytics and statistics in building its roster. “We believe in this roster. It’s a mix of hungry, talented players and experienced individuals. This team has the potential to be a strong contender in the LEC,” said David Alonso, GIANTX’s head of esports.
The journey begins on January 18 against SK Gaming (7:30 PM), followed by Rogue (Sunday, 6:45 PM) and Karmine Corp (Monday, 9:00 PM). In the second week, GIANTX will face Movistar KOI, Team Heretics, and G2 Esports, closing the regular phase against Fnatic, BDS, and Vitality. With a demanding schedule ahead, GIANTX is set to prove it is ready to compete at the highest level.
The post GIANTX begins its 2025 LEC journey with fresh faces appeared first on European Gaming Industry News.
-
Latest News2 months ago
India’s top gamers Jonathan & TechnoGamerz to face off in eFootball showdown at DreamHack India 2024
-
Latest News2 months ago
The 2024 PUBG MOBILE Global Championship (PMGC) Grand Finals Arrive in London!
-
Latest News4 weeks ago
GamCare releases Annual Report following record breaking year of support on the National Gambling Helpline
-
Latest News2 months ago
Mortal cements his name as face of Indian gaming, wins ‘Content Creator of the Year’ at global Esports Awards 2024
-
Latest News1 month ago
Abios powers upcoming gaming media platform Apollo with in-play statistics for League of Legends
-
Latest News3 months ago
DreamHack India 2024: A complete guide to the esports tournaments with INR 45+ lakh prize pool on the line
-
Latest News2 months ago
Mythpat, GamerFleet, Piyush Joshi Gaming: India’s popular Minecraft Players Gear Up for the Ultimate Battle in Creators Rumble
-
Latest News2 months ago
MelBet Appoints Bollywood Actress Sherlyn Chopra as its New Brand Ambassador
You must be logged in to post a comment Login