Connect with us

Powered

728x90 banner available here

Latest News

Popular Gambling App Exposed Millions of Users in Massive Data Leak

Published

on

Popular Gambling App Exposed Millions of Users in Massive Data Leak
Popular Gambling App Exposed Millions of Users in Massive Data LeakReading Time: 5 minutes

 

Led by Noam Rotem and Ran Locar, vpnMentor’s research team discovered a data breach on casino gambling app Clubillion.

The breach originated in a technical database built on an Elasticsearch engine and was recording the daily activities of millions of Clubillion players around the world.

Aside from leaking activity on the app, the breached database also exposed private user information.

With this information publicly available, Clubillion’s users were vulnerable to fraud and various online attacks with potentially devastating results.

Company Profile

Clubillion is a free online casino game available for iOS and Android, offering players 30+ free slot games. While each app is listed under a different developer – Ouroboros on iOS and T7 Games on Android – these are most likely owned by the same company.

Both versions of Clubillion were released in 2019 and became instant hits. Each is now ranked the #1 ‘social slots’ casino app on Google Play and the App Store, with a 4.8 star on both.

Timeline of Discovery and Owner Reaction

Sometimes, the extent of a data breach and the owner of the database are obvious, and the issue quickly resolved. But rare are these times. Most often, we need days of investigation before we understand what’s at stake or who’s leaking the data.

Understanding a breach and its potential impact takes careful attention and time. We work hard to publish accurate and trustworthy reports, ensuring everybody who reads them understands their seriousness.

Some affected parties deny the facts, disregarding our research, or playing down its impact. So, we need to be thorough and make sure everything we find is correct and accurate.

In this case, the database was built on Elasticsearch and hosted on Amazon Web Services (AWS), with Clubillion’s name on its apps, and links to assets owned by the company.

Once Clubillion was confirmed as the owner of the database, we reached out to the developers. While awaiting a reply, we also contacted AWS with details of the leak. It was closed a few days later.

  • Date discovered: 19th March 2020
  • Date vendors contacted: 23rd March 2020
  • Date of contact with AWS: 31st March 2020
  • Date of Action: Approx. 5th April 2020

Example of Entries in the Database

Clubillion’s exposed database contained technical logs for millions of Clubillion users around the world, on both iOS and Android devices. Every time an individual player took any action on the app, a record was logged. Examples of records include:

  • “enter game”
  • “win”
  • “lose”
  • “update account”
  • “create account”

During our investigation of the database, new entries continued to appear continuously. We estimated an average of approximately 200 million records per day – and sometimes, considerably more.

In total, this amounted to over 50GB of exposed records in the database every single day.

Within many of these records, were various forms of user Personally Identifiable Information (PII) data, including:

  • IP addresses
  • Email addresses
  • Winnings
  • Private messages

This data breach was truly global, with millions of records originating from Clubillion’s daily users all over the world. The following list is just a sample of countries affected, along with the average number of daily users from each country:

  • USA – 10,000+
  • UK – 2,475+
  • France – 1,650+
  • Israel – 408+
  • Germany – 1,582+
  • Spain – 1,026+
  • Italy – 2,407+
  • Netherlands – 622+
  • Australia – 6,251+
  • Canada – 7,792+
  • Brazil – 3,859+
  • Sweden – 191+
  • Russia – 547+

Other countries affected included Uzbekistan, India, Poland, Romania, Vietnam, Lebanon, Indonesia, Philippines, Pakistan, Thailand, Austria, Hungry, and Latvia.

As you can see, on a single day, 10,000s of individual Clubillion players were exposed. Each one of these players could be targeted by malicious hackers for fraud and cyberattacks – along with millions more whose records were also contained in the database.

Data Breach Impact

Studies have shown that free gambling and gaming apps are especially prone to attacks and hacking from cybercriminals. They are routinely targeted for theft of private data and embedding malicious software on users’ devices.

Despite their popularity, gambling and casino apps often lack transparency, and it can be impossible to know what steps they’re taking to prevent cybercriminals successfully targeting their users.

One study of 23,000 free gambling apps found that: 3,200 posed a ‘moderate risk’ to users; 379 had known security vulnerabilities; 52 contained malicious software.

Any of these issues could be exploited to target app users in a wide range of frauds and cyberattacks, and Clubillion is no different.

With the exposed user PII and knowledge of their activity on the app, hackers could create elaborate schemes to defraud users. For example, some entries also included transaction errors for attempted card payments on Clubillion.

With the information in these transaction errors, hackers could target users with phishing campaigns, with the following aims:

  1. Trick them into providing their credit card details
  2. Trick them into providing additional PII to be used against them in further fraud
  3. Clicking a link that embeds malware, spyware, or ransomware onto their device.

If cybercriminals used Clubillion to embed malware or similar onto a user’s phone, they could potentially hack other apps, access files stored on the device, make calls, and send texts from the hacked device. They could even access a user’s phone contacts and steal the PII data of their friends and family.

Worse still, as people across the globe now find themselves under quarantine or self-isolation, as a result of the Coronavirus pandemic, the impact of a leak like this is potentially even more significant.

Clubillion stands to gain many new users, along with regular users playing more frequently. Hackers will be aware of this and looking for opportunities to exploit any vulnerabilities in the data security of such a massively popular app.

Had criminal hackers discovered Clubillion’s database, they could have targeted millions of people around the world, with devastating results.

Impact on Clubillion and it’s Developers

The most immediate risk for Clubillion is the loss of players. Data security is a growing concern for everyone these days, and this leak could turn many players off the app. Clubillion is not unique, and players have plenty of other choices for free gambling apps.

With fewer players, Clubillion will lose advertising revenue and reduced profits.

As many of Clubillion’s players reside within the EU, the app is under the jurisdiction of GDPR. The rules of GDPR also apply to apps, and Clubillion will need to take specific actions to ensure the regulatory body in charge doesn’t reprimand it.

Finally, Clubillion could also potentially be removed from Google Play and the App Store. Both Apple and Google are clamping down on apps that pose a risk to their users, removing apps embedded with malware, and taking data leaks much more seriously.

Each of these outcomes has a different likelihood of happening, but they would all negatively impact Clubillion’s revenue and business.

Advice from the Experts

Clubillion’s developers could have easily avoided this leak if they had taken some basic security measures to protect the database. These include, but are not limited to:

  1. Securing their servers.
  2. Implementing proper access rules.
  3. Never leaving a system that doesn’t require authentication open to the internet.

Any company can replicate the same steps, no matter its size.

For a more in-depth guide on how to protect your business, check out our guide to securing your website and online database from hackers.

For Clubillion Users

If you play on Clubillion and are concerned about how this breach might impact you, contact the app’s developers directly to find out what steps it’s taking to protect your data.

To learn about data vulnerabilities in general, read our complete guide to online privacy.

It shows you the many ways cybercriminals target internet users, and the steps you can take to stay safe.

How and Why We Discovered the Breach

The vpnMentor research team discovered the breach in Clubillion’s database as part of a huge web mapping project. Our researchers use port scanning to examine particular IP blocks and test different systems for weaknesses or vulnerabilities. They examine each weakness for any data being leaked.

Our team was able to access this database because it was completely unsecured and unencrypted. 

Whenever we find a data breach, we use expert techniques to verify the owner of the database, usually a commercial company.

As ethical hackers, we’re obliged to inform a company when we discover flaws in their online security. We reached out to Clubillion’s developers, not only to let them know about the vulnerability but also to suggest ways in which they could make their system secure.

These ethics also mean we carry a responsibility to the public. Clubillion users must be aware of a data breach that exposes so much of their sensitive data.

The purpose of this web mapping project is to help make the internet safer for all users.

 

Source


Source: Latest News on European Gaming Media Network
This is a Syndicated News piece. Photo credits or photo sources can be found on the source article: Popular Gambling App Exposed Millions of Users in Massive Data Leak

George Miller (Gyorgy Molnar) started his career in content marketing and has started working as an Editor/Content Manager for our company in 2016. George has acquired many experiences when it comes to interviews and newsworthy content becoming Head of Content in 2017. He is responsible for the news being shared on multiple websites that are part of the European Gaming Media Network.

Latest News

Boomerang Partners launches Golden Boomerang League, a new seasonal tournament for affiliate teams

Published

on

Reading Time: 2 minutes

Boomerang Partners, an affiliate iGaming & Betting Marketing Agency, announces the launch of a new seasonal league for affiliate teams from around the world, the Golden Boomerang League. Set to kick off in September 2025, this unique event offers an unparalleled platform for both current and new Boomerang’s affiliate partners to showcase their expertise and rise to the top.

What is the Golden Boomerang League

The Golden Boomerang League is a unique seasonal tournament, open to all registered Boomerang’s affiliate partners, regardless of experience. Participants will be assigned special tasks and will have the opportunity to increase their traffic, revenue, and expertise through tournament support and increased visibility. Successful completion of tasks will bring affiliates closer to the prizes, the main of which will be automatic access to the third season of the Golden Boomerang Awards (GBA) in 2026. The Golden Boomerang League, therefore, is where legends are made.

The Golden Boomerang Awards: The pinnacle of motivation

The Golden Boomerang Awards is a prestigious annual tournament for affiliate teams from Boomerang Partners. Not everyone is allowed to participate. If you win the Golden Boomerang League, you will be among the favorites without a nomination or without making it into the top 30.

The best participants of GBA 2026 will be recognized at the industry level and will be invited to attend the exclusive awards ceremony, held at a top location. This is your chance to join the circle of legends, engage in elite networking, and be part of the most vibrant show in the industry. Recall that the Golden Boomerang Awards 2025 ceremony was held at the legendary San Siro Stadium in Milan with the participation of AC Milan Legend Andrea Pirlo.

Stay tuned

The Golden Boomerang League is your opportunity to prove yourself, gain recognition, and join the ranks of affiliate legends. More details will be coming soon — keep an eye on the Boomerang website and social media channels: LinkedIn, Instagram, Telegram.

About Boomerang

Boomerang Partners is a rapidly growing global brand offering a wide range of services. Boomerang is the Official Regional Partner of AC Milan. In 2024, it launched the inaugural Golden Boomerang Awards — a global tournament for affiliate teams. More than 400 affiliate teams participated in the second season of the tournament in 2025. Boomerang launched six new products in 2024, contributing to a nearly 1.5-fold increase in product users.

Boomerang’s portfolio contains 17+ brands offering affiliate and entertainment services across 40+ markets in compliance with local regulations. These products provide personalized bonuses and 24/7 multilingual support.

The post Boomerang Partners launches Golden Boomerang League, a new seasonal tournament for affiliate teams appeared first on European Gaming Industry News.

Continue Reading

Latest News

SuperGaming Raises $15 Million in Series B Funding

Published

on

Reading Time: 4 minutes

SuperGaming, one of India’s leading game development studios, today announced the successful completion of its $15 million (approx INR 131 Crore) Series B funding round.
The round attracted a powerful mix of top-tier strategic investors, including a16z SpeedrunBandai Namco 021 Fund, GFR Fund, IVC Japan, Neowiz (Korea),  LOUD.GG (Brazil), Barings and Steadview Capital. The round also saw strong participation from Web3 ecosystem pioneers like Polygon Ventures, Sandeep Nailwal, Decentralised.co, 4th Revolution Capital, 32-Bit Ventures, King River Capital, Ryze Labs, Ed3n Ventures, Gabby Dizon, Santiago R Santos, Emfarsis, Cristian Manea and Visceral Capital. Returning backers, including lead investor SkyCatcher,  AET Japan, and BACE Capital reaffirm their long-term belief in SuperGaming’s vision and execution.
This $15 million Series B funding follows SuperGaming’s $5.5 million Series A round in October 2021 and includes both the latest funding commitments and prior investments from returning backers, reflecting their long-term belief in SuperGaming’s vision and execution.
Investor Confidence Drives Strategic Expansion
The Series B round’s oversubscription and strong participation from existing investors underscore market confidence in SuperGaming’s technology-first approach and vision across evolving gaming paradigms,  including Web3.
These investments reflect the growing confidence in SuperGaming’s vision and execution, particularly as India emerges as a vital hub for cost effective game development, creative IP, and gaming infrastructure. SuperGaming has gained international recognition for Indus Battle Royale – winner of Google Play’s “Best Made in India” award for 2024, alongside its other highly successful titles.
“Our investment in SuperGaming pairs Bandai Namco’s global IP expertise with the team’s deep understanding of India’s gaming ecosystem, opening the door to growth in India and beyond. We also view SuperPlatform, an infrastructure that accelerates the creation of large scale, community-driven multiplayer games, as an additional strength that enriches the experiences SuperGaming already brings to players.” said Natsuhiro Maruyama, Investor at Bandai Namco 021 Fund.
“In a market crowded with demos and pitch decks, SuperGaming has done what few others can, they have shipped. Launching a game, especially one as ambitious as Indus, is no small feat. It shows execution, resilience, and deep player understanding in a hyperlocal market like India. We’re backing SuperGaming not just for what they’re building, but because they’re already delivering and that’s what makes all the difference.” said Ed Fries, General Partner at 1UpFund, Co-Creator Microsoft Game Studios and Co-Founder Xbox.
Global Expansion and Market Leadership Through SuperPlatform
The new capital will channel Indus Battle Royale’s expansion into international markets, beginning with Latin America in partnership with LOUD.GG. Home for its highly engaged mobile gaming community and vibrant esports scene, LATAM marks the first step in SuperGaming’s broader international rollout strategy. The fund will also be used to scale the company’s game development capabilities and invest in top-tier talent, while continuing to create new original IPs and deepen its publisher partnerships.
“We led SuperGaming’s Series A round in 2021 and are now leaning into our original thesis with a recent financing round. Our thesis is straight forward, India is the fastest growing gaming market globally and from that will emerge the next global giants in gaming. Our first round was about scaling development capabilities and this round is now about scaling global and unique hyper local publishing approaches. I’m excited about the multiple product launches the team has planned for Latin America and Middle East this year.” said Sia
Kamalie, Founder & Fund Manager, Skycatcher.
The Series B funding will primarily fuel SuperPlatform’s global expansion, targeting game developers and publishers in emerging markets who lack resources to build comparable proprietary backend technology. With comprehensive features including AI assisted game development and monetization tools, advanced analytics, social systems, SuperPlatform addresses the lifecycle of modern live service games.
SuperPlatform, developed in partnership with Google Cloud, represents SuperGaming’s most strategic asset and the primary focus for the Series B capital deployment. The sophisticated, cloud-based SaaS solution is meticulously designed for building and managing global, hyperscale, real-time multiplayer games for lower end devices in emerging markets.
“I’ve always dreamed of seeing a world-class gaming studio emerge from India, and if anyone can make that a reality, I believe it’s SuperGaming. Their momentum speaks volumes about the team’s passion and drive. But what excites me is how they understand the stakes: in gaming, the experience is the product, and the global bar for quality is incredibly high. I’m thrilled to be part of this journey and can’t wait to see them take their Battle Royale game Indus to the world.” said Sandeep Nailwal, Co-Founder, Polygon Ventures.
SuperGaming also plans to accelerate the development of its proprietary technology platforms— Indus Engine and SuperPlatform, which power its games and tools for live operations, telemetry, and community engagement.
Roby John, CEO and Co-Founder of SuperGaming, said “We are at an inflection point where India’s role in gaming evolves from a consumer market to a driving force in innovation, and this investment fuels that transition. ‘Indus Battle Royale’ is just our beginning. It is a showcase of quality and scale that we can achieve. But our deeper mission is to empower the gaming ecosystem through SuperPlatform. We’re providing developers worldwide with the tech backbone to bring their most ambitious visions to life, including seamless integration of Web3.”
Array into Web3 & Player Experience:
SuperGaming has been at the forefront of gaming innovation, consistently evaluating new technologies to enhance player experiences. Our journey into Web3 began with early explorations and insights gained from titles like Tower Conquest: Metaverse Edition (TC:ME), a free-to-earn game launched on Polygon, which enabled true digital asset ownership.
SuperGaming is now strategically leading India’s foray into Web3 gaming through its partnership with B3 GameChain, a gaming-optimized Layer-3 blockchain built on Base, the Ethereum Layer-2 network incubated by Coinbase.
This integration allows the company to serve both Web2 and Web3 players simultaneously across our portfolio, including our hit title Silly Royale, which is now live on our own Layer 3 Superchain powered by B3. This commitment offers asset continuity, interoperable progression, and deeper digital ownership, all while preserving the core play experience for our millions-strong user base.

The post SuperGaming Raises $15 Million in Series B Funding appeared first on European Gaming Industry News.

Continue Reading

Latest News

2025 PUBG MOBILE Global Championship Details, Format, and Map Changes Revealed at Esports World Cup

Published

on

Reading Time: 3 minutes

 

James Yang, Senior Director of Global Esports at Level Infinite, has shared a number of exciting reveals for the future of PUBG MOBILE Esports. Among this news is the official plan for the second half of the 2025 competitive season, including further information on the format and changes coming to the prestigious PUBG MOBILE Global Championship (PMGC) at the end of the year. These changes are set to amplify the excitement at the final major competition in this year’s circuit, allowing more opportunities for teams to make it to number one.

As the final tournament of the annual PUBG MOBILE Esports circuit, the 2025 PMGC is the most anticipated event of the year, with professional teams vying for their chance to etch their name in esports history as the ultimate Champions of the PUBG MOBILE year. For this reason, the best teams across the world are invited to take their shot at victory. This year sees the introduction of the Gauntlet Stage to the tournament — an initial stage where the 16 best teams from each region are selected for an initial chance to go straight to the Grand Finals, with six slots up for grabs.

In order to qualify for the Gauntlet Stage, teams must be placed within the top two or three spots in the regional 2025 PUBG MOBILE Super League (PMSL) Fall Rankings, but this is not the only opportunity to enter the tournament. The bottom 10 ranked teams from the Gauntlet will enter the Group Stage, alongside 22 teams from across the globe. These 22 teams are made up of the top-scoring teams from every region, with the combined 32 teams facing off in two groups for a further four qualifying slots per group.

The final two slots are made up of the overall winner of the host-region invite slot and the winner of the Last Chance stage, where the teams ranked 5th-12th from the Group Stage will get one more shot at qualifying for the Grand Finals.

Many other changes were announced as PUBG MOBILE Esports seeks to close the gap between professional play and the wider player experience. Kicking this off, Rondo is replacing Sanhok in the official map rotation from the 2025 PMSL Fall Season, and with it comes a myriad of impactful changes. To begin, the Recall System makes a return to the competitive formula, allowing eliminated players to rejoin the battle should their teammates safely secure their tag. Sentry Guards and drops will also be introduced in keeping with the original Rondo experience and the Blue Zone speed will remain the same. However, the iconic map stores will not be available, meaning players will have to scavenge for gear just as they do in other maps.

With the action-heavy updates revealed, PUBG MOBILE Esports has also highlighted some of the best moments across the various tournaments to date. This involves a look at the skill of standout performances, key historical moments, and also recognising amazing examples of how gaming can connect people across the globe.

Beginning with the former, following two years of persistence, Indonesia’s GluSquad Esports made their mark on the game, qualifying for the PMSL SEA for the first time, earning widespread support for their fresh energy in the summer season. Waves were also made in Africa, as Memoitho made history becoming the first woman in PUBG MOBILE Esports to reach the Top 3 in the 2025 PUBG MOBILE Africa Cup (PMAC) Kenya Solo Competition. Then to Nepal, where Horaa Esports celebrated their qualification in the 2025 PMWC, marking their debut entry into a major global tournament.

Alongside these great stories are many heartwarming highlights from over the years, such as Team Nile’s own 11011Enemy, who defied the odds while managing mobility issues from sickle cell disease, securing MVP in a crucial match, and going on to represent Nigeria in Saudi Arabia. In a similar vein, a community of gamers with disabilities from Turkey were brought together by PUBG MOBILE, growing into a 50 person group of supportive players across the country. PUBG MOBILE is also celebrating the love and support shown by pro players’ families. Earlier this year, the father of Regnum Carya Esports’ Sylas celebrated his son’s success at the 2025 PUBG MOBILE Global Open (PMGO). Then at the 2025 PMWC, the father of POWR Esports’ Alhaje cheered on his son from the crowd as the weekend unfolded. With this, both of these proud fathers proved their place as their sons’ number one fans. Last but not least, fans will remember how football star Richarlison met his partner through their mutual love for PUBG MOBILE Esports.

With a plethora of significant updates to the tournament formula, the reintroduction of impactful features, and many more stories to be made, PUBG MOBILE Esports fans have plenty to look forward to for the rest of the year and beyond.

The post 2025 PUBG MOBILE Global Championship Details, Format, and Map Changes Revealed at Esports World Cup appeared first on European Gaming Industry News.

Continue Reading

Trending

EEGaming.org is part of HIPTHER, parent brand of various prominent news outlets and international conferences. These platforms and events span a wide range of industries, including Entertainment, Technology, Gaming and Gambling, Blockchain, Artificial Intelligence, Fintech, Quantum Technology, Legal Cannabis, Health and Lifestyle, VR/AR, eSports, and several others. This indicates that EEGaming.org is part of a larger network that focuses on a diverse array of sectors, particularly those related to cutting-edge technology and modern lifestyle trends.

Contact us: [email protected]

Editorial / PR Submissions: [email protected]

Copyright © 2015 - 2025 HIPTHER. All Rights Reserved. Registered in Romania under Proshirt SRL, Company number: 2134306, EU VAT ID: RO21343605. Office address: Blvd. 1 Decembrie 1918 nr.5, Targu Mures, Romania

We are constantly showing banners about important news regarding events and product launches. Please turn AdBlock off in order to see these areas.