Latest News
MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability

Reading Time: 3 minutes
Attackers could exploit the SQL Injection flaw to compromise the game’s database and steal user data.
The CyberNews.com Investigation team discovered a critical vulnerability in Street Mobster, a browser-based massively multiplayer online game created by Bulgarian development company BigMage Studios.
Street Mobster is a free to play, browser-based online game in the mafia empire genre where players manage a fictional criminal enterprise. The game boasts a 1.9+ million player base and stores a user record database that can be accessed by threat actors by committing an SQL Injection (SQLi) attack on the game’s website.
Other games created by BigMage Studios are also potentially vulnerable to the same type of attack, which means that there is a possibility that even more users might be at risk.
The records that can be compromised by exploiting the SQLi vulnerability in Street Mobster potentially include the players’ usernames, email addresses, and passwords, as well as other game-related data that is stored on the database.
Fortunately, after we reported the vulnerability to BigMage Studios, CERT Bulgaria, and the Bulgarian data protection authority, the issue has been fixed by the developers and the user database is no longer accessible to potential attackers.
What is SQL Injection?
First found back in 1998, SQLi is deemed by the Open Web Application Security Project (OWASP) as the number one web application security risk.
Even though this vulnerability is relatively easy to fix, researchers found that 8% of websites and web applications are still vulnerable to SQLi attacks in 2020. Which, from a security perspective, is inexcusable. So much so, in fact, that UK internet service provider TalkTalk was hit with a record £400,000 fine over succumbing to a cyberattack that involved SQLi.
The vulnerability works by injecting an unexpected payload (a piece of code) into the input box on the website or in its URL address. Instead of reading the text as part of the URL, the website’s server reads the attacker’s payload as code and then proceeds to execute the attacker’s command or output data that would otherwise be inaccessible to unauthorized parties. Attackers can exploit SQLi even further by uploading pieces of code or even malware to the vulnerable server.
The fact that Street Mobster is susceptible to SQLi attacks clearly shows the disappointing and dangerous neglect of basic security practices on the part of the developers at BigMage Studios.
How we found this vulnerability
Our security team identified an SQL Injection vulnerability on the Street Mobster website and were able to confirm the vulnerability by performing a simple command injection test on the website URL. The CyberNews team did not extract any data from the vulnerable Street Mobster database.
What’s the impact of the vulnerability?
The data in the vulnerable Street Mobster database can be used in a variety of ways against the players whose information was exposed:
By injecting malicious payloads on Street Mobster’s server, attackers can potentially gain access to said server, where they can install malware on the game’s website and cause harm to the visitors – from using the players’ devices to mine cryptocurrency to redirecting them to other malicious websites, installing malware, and more.
The 1.9 million user credentials stored on the database can net the attackers user email addresses and passwords, which they can potentially use for credential stuffing attacks to hack the players’ accounts on other gaming platforms like Steam or other online services.
Because Street Mobster is a free-to-play game that incorporates microtransactions, bad actors could also make a lot of money from selling hacked player accounts on gray market websites.
What to do if you’ve been affected?
If you have a Street Mobster account, make sure to change your password immediately and make it as complex as possible. If you’ve been using your Street Mobster password on any other websites or services, change that password as well. This will prevent potential attackers from accessing your accounts on these websites in case they try to reuse your password for credential stuffing attacks.
However, it’s ultimately up to BigMage Studios to completely secure your Street Mobster account against attacks like SQLi.
Disclosure and lack of communication from BigMage Studios
Following our vulnerability disclosure guidelines, we notified the BigMage Studios about the leak on August 31, 2020. However, we received no reply. Our follow-up emails were left unanswered as well.
We then reached out to CERT Bulgaria on September 11 in order to help secure the website. CERT contacted the BigMage Studios and informed the company about the misconfiguration.
Throughout the disclosure process, BigMage Studios stayed radio silent and refused to get in touch with CyberNews.com. Due to this reason, we also notified the Bulgarian data protection agency about the incident on October 9 in the hopes that the agency would be able to pressure the company into fixing the issue.
Eventually, however, BigMage Studios appear to have fixed the SLQi vulnerability on streetmobster.com, without informing either CyberNews.com or CERT Bulgaria about that fact.
Source: Latest News on European Gaming Media Network
This is a Syndicated News piece. Photo credits or photo sources can be found on the source article: MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability
Latest News
Casino Guru Awards 2026 introduce four new categories celebrating leadership, responsibility, and culture in iGaming
Reading Time: 2 minutes
Casino Guru proudly unveils four new award categories for the upcoming Casino Guru Awards 2026, further expanding its mission to recognize individuals and organizations shaping a fairer, safer, and more forward-thinking iGaming industry.
Following three years of continued growth and rising influence, the Casino Guru Awards remain the only industry awards focused primarily on fairness, transparency, integrity, and responsible innovation. The 2026 ceremony, scheduled for May 25, 2026, at The Xara Lodge in Malta, in partnership with NEXT.io during NEXT Valletta, will spotlight outstanding achievements from across the global iGaming landscape.
This year’s newly introduced categories reflect Casino Guru’s commitment to acknowledging emerging talent, ethical leadership, and positive workplace culture.
New Award Categories for 2026
Woman Leader of the Year
This category celebrates an exceptional female leader whose vision, resilience, and strategic influence have helped transform her company and the industry as a whole.
Judges will look for measurable achievements in 2024–2025, including business growth, crisis management, innovation in user experience, safety, transparency, and responsible gambling.
The award is open to women driving meaningful impact while championing diversity, mentorship, and collaborative progress within iGaming.
Rising Star in Responsible Gambling
Designed to recognize organizations making remarkable early strides in safer gambling initiatives, this category highlights innovation and genuine commitment from companies of all sizes.
Whether through impactful tools, awareness campaigns, or fresh approaches to player protection, nominees must demonstrate provable results that contribute to higher standards of responsibility and safety across the industry.
Young Changemaker Award
Honoring an individual under 30, the Young Changemaker Award shines a spotlight on rising professionals whose ethical innovation, creativity, and forward-thinking actions have made a visible impact in 2025.
Judges will consider originality, leadership ability, and tangible contributions that set a new benchmark for integrity and progress in iGaming.
Industry Culture Shaper
Recognizing that true industry progress starts within organizations, this award honors companies that cultivate positive, transparent, and supportive workplace cultures.
Nominees will be assessed based on measurable outcomes such as employee satisfaction, retention, and productivity, alongside initiatives that support wellbeing, mental health, professional development, and ethical HR practices.
Additional weight will be given to organizations whose efforts inspire better standards beyond their walls through partnerships, advocacy, or shared knowledge.
A broader vision for industry progress
“The addition of these categories marks an important evolution for the Casino Guru Awards,” said Daniela Sliva, PR & Creative Project Director at Casino Guru and leader of the Awards project.
“By spotlighting leadership, emerging talent, responsible innovation, and culture, we are amplifying the people and values that will define the future of iGaming. These awards aim to inspire positive change at every level, from individual contributors to global operators.”
The new categories will stand alongside Casino Guru’s established awards, including The Fairest Bonus Policy, The Most Transparent Casino, The Best Implementation of Responsible Gambling Tools, and others that reflect Casino Guru’s core values.
The post Casino Guru Awards 2026 introduce four new categories celebrating leadership, responsibility, and culture in iGaming appeared first on European Gaming Industry News.
Latest News
CT Interactive Expands in Romania with New Game Launch on Maxbet.ro
Reading Time: < 1 minute
CT Interactive is further expanding its presence in the regulated Romanian market through the launch of new gaming content on Maxbet.ro. This collaboration introduces a selection of top-performing titles designed to boost player engagement and enhance the overall gaming experience across the region.
As part of the collaboration, Maxbet.ro will feature two exclusive titles available only to its players — Kyoto Magic and Fruits & Sweets Buy Bonus.
Martin Ivanov, Chief Operating Officer at CT Interactive, said: “Our collaboration with Maxbet.ro reflects our commitment to developing high-quality content that meets the demands of the modern Romanian player. Titles like Fruits & Sweets Buy Bonus and Kyoto Magic showcase the best of our portfolio – dynamic gameplay, strategic depth, attractive bonus features and excellent math models.”
“We are confident that our exclusive titles will enhance the gaming experience for Maxbet’s players, offering them a richer, more immersive, and engaging journey,” added Bogdan Smeu, Regional Manager for Romania at CT Interactive.
In addition to the exclusive titles, Maxbet.ro will now feature a selection of CT Interactive’s most popular games, including 20 Mega Star, Lucky Clover 10, The Shining Globe, Zet Fruits and Doctor Winstein Buy Bonus.
The launch of this new content underscores CT Interactive’s commitment to the Romanian market, delivering premium gaming experiences that enhance player engagement and contribute to the long-term success of its partners.
The post CT Interactive Expands in Romania with New Game Launch on Maxbet.ro appeared first on European Gaming Industry News.
Latest News
CT Gaming Shortlisted in Three Categories at BEGE Awards 2025
Reading Time: < 1 minute
CT Gaming has announced that the company has been shortlisted in three major categories at the BEGE Awards 2025, reaffirming its strong market presence and commitment to delivering innovative gaming solutions.
This year, CT Gaming is a finalist in the following categories:
• Slot Product of the Year – Next 32
• Jackpot System of the Year – Diamond Tree Deluxe
• Casino Management System of the Year – Rhino CMS
These nominations recognise the company’s continuous ability to combine modern technological advances with proven performance, creating products that deliver exceptional value to both operators and players.
NEXT 32 is the most innovative slot cabinet in CT Gaming’s portfolio, impressive with its advanced technical features, ergonomic design and enhanced player interaction.
The upgraded Diamond Tree Deluxe jackpot system stands out with improved visuals, smoother gameplay and the exciting ability for players to win any jackpot tier directly from the base game. Its flexibility allows operators to configure parameters according to their venue needs, offering a customized jackpot experience.
Rhino, CT Gaming’s powerful casino management system, continues to evolve with new modules and features that streamline operations, support informed decision-making and enhance player interaction. Its comprehensive and scalable platform is designed to suit gaming venues of any size.
“We are honored to receive recognition in three categories this year. It reflects our team’s dedication to innovation and delivering products that support the success of our partners,” said Biser Bozhanov, CEO at CT Gaming.
The post CT Gaming Shortlisted in Three Categories at BEGE Awards 2025 appeared first on European Gaming Industry News.
-
Latest News3 months ago
Duels for Friends in Trophy Hunter. Invite your friends and create a shared space for fun and competition.
-
Latest News2 months ago
Announcement: 25th September 2025
-
Latest News3 months ago
Flamez – A Fiery New Online Casino Contender from Ganadu
-
Latest News2 months ago
GR8 Tech’s Bet It Drives Wraps Season 1 with Stephen Crystal—From Las Vegas Legends to Global Gaming Leadership
-
Latest News2 months ago
AI-Powered Gamification Arrives on Vegangster Platform via Smartico
-
Latest News2 months ago
The Countdown is On: Less Than 3 Months to Go Until The Games of The Future 2025 Kicks Off in Abu Dhabi
-
Latest News2 weeks ago
JioBLAST Launches All Stars vs India powered by Campa Energy: A New Era of Creator-Driven Esports Entertainment
-
Latest News2 months ago
Adidas Arena Set to Welcome the 2026 Six Invitational




You must be logged in to post a comment Login