Latest News
MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability

Reading Time: 3 minutes
Attackers could exploit the SQL Injection flaw to compromise the game’s database and steal user data.
The CyberNews.com Investigation team discovered a critical vulnerability in Street Mobster, a browser-based massively multiplayer online game created by Bulgarian development company BigMage Studios.
Street Mobster is a free to play, browser-based online game in the mafia empire genre where players manage a fictional criminal enterprise. The game boasts a 1.9+ million player base and stores a user record database that can be accessed by threat actors by committing an SQL Injection (SQLi) attack on the game’s website.
Other games created by BigMage Studios are also potentially vulnerable to the same type of attack, which means that there is a possibility that even more users might be at risk.
The records that can be compromised by exploiting the SQLi vulnerability in Street Mobster potentially include the players’ usernames, email addresses, and passwords, as well as other game-related data that is stored on the database.
Fortunately, after we reported the vulnerability to BigMage Studios, CERT Bulgaria, and the Bulgarian data protection authority, the issue has been fixed by the developers and the user database is no longer accessible to potential attackers.
What is SQL Injection?
First found back in 1998, SQLi is deemed by the Open Web Application Security Project (OWASP) as the number one web application security risk.
Even though this vulnerability is relatively easy to fix, researchers found that 8% of websites and web applications are still vulnerable to SQLi attacks in 2020. Which, from a security perspective, is inexcusable. So much so, in fact, that UK internet service provider TalkTalk was hit with a record £400,000 fine over succumbing to a cyberattack that involved SQLi.
The vulnerability works by injecting an unexpected payload (a piece of code) into the input box on the website or in its URL address. Instead of reading the text as part of the URL, the website’s server reads the attacker’s payload as code and then proceeds to execute the attacker’s command or output data that would otherwise be inaccessible to unauthorized parties. Attackers can exploit SQLi even further by uploading pieces of code or even malware to the vulnerable server.
The fact that Street Mobster is susceptible to SQLi attacks clearly shows the disappointing and dangerous neglect of basic security practices on the part of the developers at BigMage Studios.
How we found this vulnerability
Our security team identified an SQL Injection vulnerability on the Street Mobster website and were able to confirm the vulnerability by performing a simple command injection test on the website URL. The CyberNews team did not extract any data from the vulnerable Street Mobster database.
What’s the impact of the vulnerability?
The data in the vulnerable Street Mobster database can be used in a variety of ways against the players whose information was exposed:
By injecting malicious payloads on Street Mobster’s server, attackers can potentially gain access to said server, where they can install malware on the game’s website and cause harm to the visitors – from using the players’ devices to mine cryptocurrency to redirecting them to other malicious websites, installing malware, and more.
The 1.9 million user credentials stored on the database can net the attackers user email addresses and passwords, which they can potentially use for credential stuffing attacks to hack the players’ accounts on other gaming platforms like Steam or other online services.
Because Street Mobster is a free-to-play game that incorporates microtransactions, bad actors could also make a lot of money from selling hacked player accounts on gray market websites.
What to do if you’ve been affected?
If you have a Street Mobster account, make sure to change your password immediately and make it as complex as possible. If you’ve been using your Street Mobster password on any other websites or services, change that password as well. This will prevent potential attackers from accessing your accounts on these websites in case they try to reuse your password for credential stuffing attacks.
However, it’s ultimately up to BigMage Studios to completely secure your Street Mobster account against attacks like SQLi.
Disclosure and lack of communication from BigMage Studios
Following our vulnerability disclosure guidelines, we notified the BigMage Studios about the leak on August 31, 2020. However, we received no reply. Our follow-up emails were left unanswered as well.
We then reached out to CERT Bulgaria on September 11 in order to help secure the website. CERT contacted the BigMage Studios and informed the company about the misconfiguration.
Throughout the disclosure process, BigMage Studios stayed radio silent and refused to get in touch with CyberNews.com. Due to this reason, we also notified the Bulgarian data protection agency about the incident on October 9 in the hopes that the agency would be able to pressure the company into fixing the issue.
Eventually, however, BigMage Studios appear to have fixed the SLQi vulnerability on streetmobster.com, without informing either CyberNews.com or CERT Bulgaria about that fact.
Source: Latest News on European Gaming Media Network
This is a Syndicated News piece. Photo credits or photo sources can be found on the source article: MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability
Latest News
Allwyn commits to highest level of 2025 Gift Responsibly Campaign
Reading Time: 2 minutes
– National Lottery ‘Add some play to Christmas’ campaign supported by enhanced protection measures –
– In a UK National Lottery first, Allwyn becomes a Level 3 Gift Responsibly supporter –
National Lottery operator Allwyn has unveiled its multi-channel ‘Add some play to Christmas’ campaign, which puts National Lottery Scratchcards at the heart – positioning them as a fun way to come together, no matter the occasion or the group.
As part of that, Allwyn has once again signed up to the National Council on Problem Gambling’s (NCPG) 2025 Gift Responsibly Campaign – this year as a Level 3 sponsor, the highest possible level and a UK National Lottery first.
Founded in the early 2000s, the Gift Responsibly Campaign works to raise public awareness about the risks of youth gambling. Through partnerships with lotteries and other organisations, the campaign educates communities about the risks of buying lottery products for children.
As part of its commitments as a Level 3 supporter, Allwyn will carry a ’18+ Gift Responsibly’ mark across its National Lottery gifting-related festive advertising – to re-iterate the need for people to be 18 or older to buy, gift, receive and play.
The company has also created three brand new bespoke creative assets promoting responsible play that it will use:
- across its @TNLUK and @AllwynUK social media channels
- on in-store National Lottery media screens
- as part of a digital campaign
Allwyn already carries out extensive training with its 43,500 retail partners to prevent underage and excessive play, as well as running a rigorous ‘Operation Guardian’ programme for mystery shopping and knowledge checks with National Lottery retailers to ensure compliance.
The company’s advanced NCPG participation will also see it prompting its tens of thousands of retail partners to remind their customers to gift National Lottery products responsibly this festive season, through direct communications and trade advertising.
Jordana Jackson, Head of Participant Protection at Allwyn, commented: “Since becoming National Lottery operator early last year, we’ve made great progress on our participant protection plans. We’re proud to once again be supporting the NCPG’s Gift Responsibly Campaign and, for the first time in the UK National Lottery’s history, commit to Level 3 sponsorship – the highest level of support possible. This commitment includes a range of activity to remind everyone that, while National Lottery Scratchcards can add festive fun and help raise over £30m a week for Good Causes, they’re strictly for adults.”
The post Allwyn commits to highest level of 2025 Gift Responsibly Campaign appeared first on European Gaming Industry News.
Latest News
LeoVegas Group signs partnership deal with Valletta FC and boosts local footprint in Malta
Reading Time: 2 minutes
LeoVegas Group has entered into a two-year partnership agreement with Malta Premier League club Valletta Football Club. As Exclusive Online Gaming Partner, the LeoVegas Group corporate brand will feature on the men’s squad’s match kits, at training grounds, and prominently across the club’s digital channels. The partnership will enhance the Group’s brand visibility and commitment to the local community, while further strengthening its position as an employer of choice in igaming.
LeoVegas Group and Valletta Football Club, one of the most successful clubs in Malta’s history, today announced a new partnership that will see LeoVegas Group’s corporate brand become the club’s Exclusive Online Gaming Partner during the 2025/2026 and 2026/2027 seasons. The agreement includes match kit sleeve branding for the men’s squad, visibility across all club facilities, including the Rabat Football Ground and Dangli Football Ground and the matchday fanzone, as well as branding on the squad’s training bags. The club’s digital channels, which have tens of thousands passionate followers on social media such as Instagram and Facebook, will regularly feature the LeoVegas Group logo in their content.
As partners, LeoVegas Group and Valletta Football Club will also collaborate to create exciting branded experiences across the Maltese capital for both fans and employees. Group employees can look forward to exclusive matchday opportunities and VIP experiences. The partnership enables LeoVegas Group to further strengthen corporate brand awareness across the Maltese islands and continue positioning the Group as an employer of choice for talent seeking careers in the growing igaming industry.
Additionally, the partnership includes branding on the youth team’s kit. This shirt sponsorship opportunity will be donated by LeoVegas Group to a local non-governmental organization (NGO), which will be selected through a popular vote by club members during a club meeting.
Stefan Nelson, LeoVegas Group CFO and Malta Managing Director, said “We are very proud to partner with Valletta FC, one of the most successful and popular clubs in Malta. Our Group has considered itself a partly Maltese company almost since its inception, and we are thrilled to collaborate with the capital’s club to create exciting opportunities for fans, employees, and future talent alike. When two strong lions join forces, great things can happen!”.
Claudio Grech, Valletta Football Club President, said “This partnership brings together two brands that share Malta’s global reputation for excellence in gaming, entertainment, and sport. LeoVegas Group has become a world leader in mobile gaming while Valletta FC stands as Malta’s largest football club. Both of us thrive on delivering excitement and engagement — whether through live football or immersive digital experiences. We also share a forward-looking vision that embraces technology and online communities to connect with our audiences. As LeoVegas Group continues to expand internationally, Valletta FC is equally determined to evolve into a regional football powerhouse, making this collaboration a natural and powerful alignment of ambition, innovation, and Maltese pride”.
The post LeoVegas Group signs partnership deal with Valletta FC and boosts local footprint in Malta appeared first on European Gaming Industry News.
Latest News
Gamblers Connect Named Finalist in Three Categories at the International Gaming Awards 2026
Reading Time: < 1 minute
Gamblers Connect has been officially shortlisted in three categories at the International Gaming Awards 2026, one of the most respected global recognitions within the gaming and iGaming sectors.
This announcement marks an important milestone for the company, reflecting its continued growth, consistent industry presence and long-term commitment to responsible and high-quality affiliate operations.
Gamblers Connect has been shortlisted in three distinct categories: Affiliate (Company) of the Year, recognising its public-facing affiliate excellence; the Great Place to Work Award (Operator), highlighting the strength of its internal culture; and the Safer Gambling Award, which reflects the company’s commitment to responsibility standards across its operations.
The 19th annual International Gaming Awards will be held on 18th January during ICE Barcelona. It is regarded as one of the leading global recognitions for excellence across the gaming industry. Each year, the IGA highlights companies that show innovation, quality, responsibility and meaningful contribution to the sector.
Gjorgje Ristikj, Founder of Gamblers Connect, said: “Being shortlisted across three very different categories shows our strength on multiple levels. It recognises our public-facing work, the culture behind it and the responsibility standards that guide everything we do.”
The post Gamblers Connect Named Finalist in Three Categories at the International Gaming Awards 2026 appeared first on European Gaming Industry News.
-
Latest News3 months ago
Duels for Friends in Trophy Hunter. Invite your friends and create a shared space for fun and competition.
-
Latest News2 months ago
Announcement: 25th September 2025
-
Latest News3 months ago
Flamez – A Fiery New Online Casino Contender from Ganadu
-
Latest News2 months ago
GR8 Tech’s Bet It Drives Wraps Season 1 with Stephen Crystal—From Las Vegas Legends to Global Gaming Leadership
-
Latest News2 months ago
AI-Powered Gamification Arrives on Vegangster Platform via Smartico
-
Latest News2 months ago
The Countdown is On: Less Than 3 Months to Go Until The Games of The Future 2025 Kicks Off in Abu Dhabi
-
Latest News2 weeks ago
JioBLAST Launches All Stars vs India powered by Campa Energy: A New Era of Creator-Driven Esports Entertainment
-
Latest News2 months ago
Adidas Arena Set to Welcome the 2026 Six Invitational




You must be logged in to post a comment Login