Connect with us

Latest News

MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability

Published

on

MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability
MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerabilityReading Time: 3 minutes

Attackers could exploit the SQL Injection flaw to compromise the game’s database and steal user data.

The CyberNews.com Investigation team discovered a critical vulnerability in Street Mobster, a browser-based massively multiplayer online game created by Bulgarian development company BigMage Studios.

Street Mobster is a free to play, browser-based online game in the mafia empire genre where players manage a fictional criminal enterprise. The game boasts a 1.9+ million player base and stores a user record database that can be accessed by threat actors by committing an SQL Injection (SQLi) attack on the game’s website.

Other games created by BigMage Studios are also potentially vulnerable to the same type of attack, which means that there is a possibility that even more users might be at risk.

The records that can be compromised by exploiting the SQLi vulnerability in Street Mobster potentially include the players’ usernames, email addresses, and passwords, as well as other game-related data that is stored on the database.

Fortunately, after we reported the vulnerability to BigMage Studios, CERT Bulgaria, and the Bulgarian data protection authority, the issue has been fixed by the developers and the user database is no longer accessible to potential attackers.

What is SQL Injection?

First found back in 1998, SQLi is deemed by the Open Web Application Security Project (OWASP) as the number one web application security risk.

Even though this vulnerability is relatively easy to fix, researchers found that 8% of websites and web applications are still vulnerable to SQLi attacks in 2020. Which, from a security perspective, is inexcusable. So much so, in fact, that UK internet service provider TalkTalk was hit with a record £400,000 fine over succumbing to a cyberattack that involved SQLi.

The vulnerability works by injecting an unexpected payload (a piece of code) into the input box on the website or in its URL address. Instead of reading the text as part of the URL, the website’s server reads the attacker’s payload as code and then proceeds to execute the attacker’s command or output data that would otherwise be inaccessible to unauthorized parties. Attackers can exploit SQLi even further by uploading pieces of code or even malware to the vulnerable server.

The fact that Street Mobster is susceptible to SQLi attacks clearly shows the disappointing and dangerous neglect of basic security practices on the part of the developers at BigMage Studios.

 

How we found this vulnerability

Our security team identified an SQL Injection vulnerability on the Street Mobster website and were able to confirm the vulnerability by performing a simple command injection test on the website URL. The CyberNews team did not extract any data from the vulnerable Street Mobster database.

What’s the impact of the vulnerability?

The data in the vulnerable Street Mobster database can be used in a variety of ways against the players whose information was exposed:

By injecting malicious payloads on Street Mobster’s server, attackers can potentially gain access to said server, where they can install malware on the game’s website and cause harm to the visitors – from using the players’ devices to mine cryptocurrency to redirecting them to other malicious websites, installing malware, and more.

The 1.9 million user credentials stored on the database can net the attackers user email addresses and passwords, which they can potentially use for credential stuffing attacks to hack the players’ accounts on other gaming platforms like Steam or other online services.

Because Street Mobster is a free-to-play game that incorporates microtransactions, bad actors could also make a lot of money from selling hacked player accounts on gray market websites.

What to do if you’ve been affected?

If you have a Street Mobster account, make sure to change your password immediately and make it as complex as possible. If you’ve been using your Street Mobster password on any other websites or services, change that password as well. This will prevent potential attackers from accessing your accounts on these websites in case they try to reuse your password for credential stuffing attacks.

However, it’s ultimately up to BigMage Studios to completely secure your Street Mobster account against attacks like SQLi.

Disclosure and lack of communication from BigMage Studios

Following our vulnerability disclosure guidelines, we notified the BigMage Studios about the leak on August 31, 2020. However, we received no reply. Our follow-up emails were left unanswered as well.

We then reached out to CERT Bulgaria on September 11 in order to help secure the website. CERT contacted the BigMage Studios and informed the company about the misconfiguration.

Throughout the disclosure process, BigMage Studios stayed radio silent and refused to get in touch with CyberNews.com. Due to this reason, we also notified the Bulgarian data protection agency about the incident on October 9 in the hopes that the agency would be able to pressure the company into fixing the issue.

Eventually, however, BigMage Studios appear to have fixed the SLQi vulnerability on streetmobster.com, without informing either CyberNews.com or CERT Bulgaria about that fact.

 

Source


Source: Latest News on European Gaming Media Network
This is a Syndicated News piece. Photo credits or photo sources can be found on the source article: MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability

George Miller (Gyorgy Molnar) started his career in content marketing and has started working as an Editor/Content Manager for our company in 2016. George has acquired many experiences when it comes to interviews and newsworthy content becoming Head of Content in 2017. He is responsible for the news being shared on multiple websites that are part of the European Gaming Media Network.

Latest News

Legends Collide and the Stage Ignites at Red Bull League of its Own 2025, Munich

Published

on

Reading Time: 2 minutes

Everything you need to know ahead of Saturday 29 November, when Red Bull’s one-of-a-kind League of Legends tournament ‘Red Bull League of Its Own’ is set to make its grand return.

Taking place in the iconic SAP Garden in Munich, reigning champions and esport titans T1, along with some of Europe’s most celebrated teams – G2 Esports, Karmine Corp, NNO Old and Los Ratones, will go head-to-head in an unmissable end-of-year showdown.

Red Bull League of Its Own 2025 is set to light up Munich’s SAP Garden, turning the state-of-the-art arena into an electrifying esports stage in the heart of Olympic Park. 11,500 fans will fill the stands, with countless more watching online, as international icons and Europe’s elite face-off in this year’s ultimate League of Legends clash. Red Bull League of Its Own is all about pushing the action to the limit, delivering high-energy matchups, unexpected twists, and the possibility of mixed rosters that keep every game fresh. All matchups will be played in a Ultimate Fearless best-of-1 format, keeping every game high-stakes and unpredictable.

The 2024 Red Bull League of Its Own delivered an unforgettable spectacle in Paris’ Accor Arena as T1 swapped roles, Los Ratones stunned after causing an upset, and Rekkles made a triumphant reunion on stage. This year’s edition aims to raise the bar even higher, promising elevated competition and moments that will captivate the global League community once again.

Returning as the official Monitor Partner for 2025, AGON by AOC will once again deliver high-performance gaming monitors to ensure contestants get the ultimate gaming experience. Razer makes its debut as the official Chair Partner of Red Bull League of Its Own, bringing the Razer Iskur V2 – an ergonomic chair built for comfort, durability, and focus – to keep players at their best throughout every match. MSI also joins as the official Gaming PC and Laptop Partner, while KFC comes on board for the first time as an event partner.

With record viewership last year, Red Bull League of Its Own 2025 promises unforgettable clashes, daring strategies, and moments fans will talk about long after the final match.

See below for full event details, timings, and where to watch.

Schedule:

  • -15:00 CET – Opening Ceremony
  • -15:15 CET – G2 Esports vs NNO Old
  • -16:00 CET – Los Ratones vs Karmine Corp
  • -17:00 CET – G2 Esports vc Karmine Corp
  • -18:00 CET – T1 vs Match 3 Winner
  • -19:00 CET – T1 vs NNO Old
  • -20:00 CET – T1 vs Los Ratones

Talent:

  • -Eefje “Sjokz” Depoortere – Host
  • -Keltoum “Giniro” Baddaje – Host
  • -Robert “Dagda” Price – Caster
  • -Aaron “Medic” Chamberlain – Caster
  • -Joe “Munchables” Fenny – Caster
  • -Daniel “Aux” Harrison – Caster
  • -Jona “JustJohnny” Schmitt – MC
  • -René “MasterPlay” Geigenberger – MC

On-Site Streamers:

  • -Caedrel
  • -Kameto
  • -NNO Old (NoWay, Tolkin, Agurin, Karni, and Broeli)
  • -Ilha das Lendas (Baiano, Tay, Brucer, and Pedro Bosco)

Where To Watch:

  • -Fans can tune in to Red Bull Gaming’s YouTube and Twitch channels at 3 PM (UTC+1).
  • -YouTube: youtube.com/live/mNV9ZU_YunA
  • -Twitch: twitch.tv/redbull

 

The post Legends Collide and the Stage Ignites at Red Bull League of its Own 2025, Munich appeared first on European Gaming Industry News.

Continue Reading

Latest News

1xBet Becomes the First Official Betting Partner of MIBR’s VALORANT Team

Published

on

Reading Time: 2 minutes

1xBet has signed a partnership with the VALORANT roster of esports powerhouse MIBR, becoming the first-ever official betting partner in the Riot Games ecosystem.

Under this partnership, 1xBet and MIBR will focus on creating a new, immersive fan experience, strengthening the team’s global fanbase, and boosting overall engagement with VALORANT.

MIBR’s VALORANT roster currently includes players from the United States and Brazil. Over the past few years, the team has been a regular competitor in VCT Americas, and in 2025 they qualified for VALORANT Masters Toronto — the only Latin American team to do so. Later that year, MIBR also earned a spot at VALORANT Champions 2025, finishing in the Top 5 worldwide.

Beyond their esports success, MIBR continues to expand its media presence through collaborations with leading Brazilian influencers such as Sacy, producing original entertainment content, and hosting watch parties during major tournaments — all helping the organization remain one of the most talked-about and fan-favorite names on the regional scene.

Among the team’s stars is Erick ‘Aspas’ Santos, widely regarded as a VALORANT legend in Latin America. In 2025, he set the VCT Americas record for the most kills in a BO3 series and became the first player in VALORANT Champions history to surpass 1,000 kills across tournaments (2022–2024). Outside of competition, Aspas is a three-time Prêmio eSports Brasil “Athlete of the Year” winner and a massive fan favorite — during VCT Americas 2024 Kickoff, he became the most-mentioned player on Twitch chats, with over 11,300 mentions.

1xBet is one of the most recognized brands in esports betting, regularly supporting major global tournaments and sponsoring top-tier teams around the world.

Simon Westbury, Strategic Advisor at 1xBet: “This is a historic step for 1xBet — becoming the first official betting partner of an esports team within the Riot Games ecosystem. MIBR features some of the most talented and visible players in Latin America, and together we aim to strengthen VALORANT’s presence across the LATAM region, elevate its appeal internationally, and deliver a unique fan experience for audiences around the globe.”

Raphael Castanheira, MIBR’s Director of Marketing and Partnerships:  “Being the first organization in the entire Riot ecosystem to obtain approval for a betting sponsorship is a direct result of how MIBR operates today, as an organized company with robust governance, clear processes, and protected by policies that put competitive integrity at the forefront. ”

 

The post 1xBet Becomes the First Official Betting Partner of MIBR’s VALORANT Team appeared first on European Gaming Industry News.

Continue Reading

Latest News

ComeOn Group climbs to 21st place in the EGR Global Power 50 following a year of strategic growth

Published

on

Reading Time: < 1 minute

Leading iGaming operator ComeOn Group has secured the 21st position in the 2025 EGR Power 50 rankings, reflecting a year defined by expansion, product innovation, and strengthened regulatory presence across Europe.

In 2025, the Group broadened its footprint in the regulated European markets with the launch of its casino-first brand Casinostuen in Denmark. The Group also advanced its activities in the Netherlands through the operation of Evoke’s 888 brand within the regulated Dutch market.

ComeOn Group continues to benefit from its strategic focus on locally regulated jurisdictions, which is powered by its own technology platform including an in-house sportsbook platform, proprietary games studio SpinOn, and unique, innovative jackpot products have been key contributors to differentiation and growing market share in core territories.

Juergen Reutter, Chief Executive Officer, said: “Our proprietary technology is powering our products and services, giving us a strong competitive edge in highly dynamic and regulated markets. This foundation allows us to innovate faster, deliver differentiated experiences, and scale with confidence.

At the same time, artificial intelligence is transforming how competitive we can operate. We’ve equipped our teams with the tools and governance to experiment boldly and apply AI where it creates the most value. At ComeOn Group, we want to learn faster than our competition, because speed, agility, and innovation are essential to staying ahead in this industry.”

The Group closed the period with strong financial performance, demonstrating consistent growth across all key indicators for the 12 months ending 30 June 2025. Combined with the company’s increased market reach and accelerated innovation initiatives, ComeOn Group enters the coming year with robust momentum and a strengthened market position.

 

The post ComeOn Group climbs to 21st place in the EGR Global Power 50 following a year of strategic growth appeared first on European Gaming Industry News.

Continue Reading

Trending

EEGaming.org is part of HIPTHER, parent brand of various prominent news outlets and international conferences. These platforms and events span a wide range of industries, including Entertainment, Technology, Gaming and Gambling, Blockchain, Artificial Intelligence, Fintech, Quantum Technology, Legal Cannabis, Health and Lifestyle, VR/AR, eSports, and several others. This indicates that EEGaming.org is part of a larger network that focuses on a diverse array of sectors, particularly those related to cutting-edge technology and modern lifestyle trends.

Contact us: [email protected]

Editorial / PR Submissions: [email protected]

Copyright © 2015 - 2025 HIPTHER. All Rights Reserved. Registered in Romania under Proshirt SRL, Company number: 2134306, EU VAT ID: RO21343605. Office address: Blvd. 1 Decembrie 1918 nr.5, Targu Mures, Romania

We are constantly showing banners about important news regarding events and product launches. Please turn AdBlock off in order to see these areas.