Connect with us

Latest News

MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability

Published

on

MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability
MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerabilityReading Time: 3 minutes

Attackers could exploit the SQL Injection flaw to compromise the game’s database and steal user data.

The CyberNews.com Investigation team discovered a critical vulnerability in Street Mobster, a browser-based massively multiplayer online game created by Bulgarian development company BigMage Studios.

Street Mobster is a free to play, browser-based online game in the mafia empire genre where players manage a fictional criminal enterprise. The game boasts a 1.9+ million player base and stores a user record database that can be accessed by threat actors by committing an SQL Injection (SQLi) attack on the game’s website.

Other games created by BigMage Studios are also potentially vulnerable to the same type of attack, which means that there is a possibility that even more users might be at risk.

The records that can be compromised by exploiting the SQLi vulnerability in Street Mobster potentially include the players’ usernames, email addresses, and passwords, as well as other game-related data that is stored on the database.

Fortunately, after we reported the vulnerability to BigMage Studios, CERT Bulgaria, and the Bulgarian data protection authority, the issue has been fixed by the developers and the user database is no longer accessible to potential attackers.

What is SQL Injection?

First found back in 1998, SQLi is deemed by the Open Web Application Security Project (OWASP) as the number one web application security risk.

Even though this vulnerability is relatively easy to fix, researchers found that 8% of websites and web applications are still vulnerable to SQLi attacks in 2020. Which, from a security perspective, is inexcusable. So much so, in fact, that UK internet service provider TalkTalk was hit with a record £400,000 fine over succumbing to a cyberattack that involved SQLi.

The vulnerability works by injecting an unexpected payload (a piece of code) into the input box on the website or in its URL address. Instead of reading the text as part of the URL, the website’s server reads the attacker’s payload as code and then proceeds to execute the attacker’s command or output data that would otherwise be inaccessible to unauthorized parties. Attackers can exploit SQLi even further by uploading pieces of code or even malware to the vulnerable server.

The fact that Street Mobster is susceptible to SQLi attacks clearly shows the disappointing and dangerous neglect of basic security practices on the part of the developers at BigMage Studios.

 

How we found this vulnerability

Our security team identified an SQL Injection vulnerability on the Street Mobster website and were able to confirm the vulnerability by performing a simple command injection test on the website URL. The CyberNews team did not extract any data from the vulnerable Street Mobster database.

What’s the impact of the vulnerability?

The data in the vulnerable Street Mobster database can be used in a variety of ways against the players whose information was exposed:

By injecting malicious payloads on Street Mobster’s server, attackers can potentially gain access to said server, where they can install malware on the game’s website and cause harm to the visitors – from using the players’ devices to mine cryptocurrency to redirecting them to other malicious websites, installing malware, and more.

The 1.9 million user credentials stored on the database can net the attackers user email addresses and passwords, which they can potentially use for credential stuffing attacks to hack the players’ accounts on other gaming platforms like Steam or other online services.

Because Street Mobster is a free-to-play game that incorporates microtransactions, bad actors could also make a lot of money from selling hacked player accounts on gray market websites.

What to do if you’ve been affected?

If you have a Street Mobster account, make sure to change your password immediately and make it as complex as possible. If you’ve been using your Street Mobster password on any other websites or services, change that password as well. This will prevent potential attackers from accessing your accounts on these websites in case they try to reuse your password for credential stuffing attacks.

However, it’s ultimately up to BigMage Studios to completely secure your Street Mobster account against attacks like SQLi.

Disclosure and lack of communication from BigMage Studios

Following our vulnerability disclosure guidelines, we notified the BigMage Studios about the leak on August 31, 2020. However, we received no reply. Our follow-up emails were left unanswered as well.

We then reached out to CERT Bulgaria on September 11 in order to help secure the website. CERT contacted the BigMage Studios and informed the company about the misconfiguration.

Throughout the disclosure process, BigMage Studios stayed radio silent and refused to get in touch with CyberNews.com. Due to this reason, we also notified the Bulgarian data protection agency about the incident on October 9 in the hopes that the agency would be able to pressure the company into fixing the issue.

Eventually, however, BigMage Studios appear to have fixed the SLQi vulnerability on streetmobster.com, without informing either CyberNews.com or CERT Bulgaria about that fact.

 

Source


Source: Latest News on European Gaming Media Network
This is a Syndicated News piece. Photo credits or photo sources can be found on the source article: MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability

George Miller (Gyorgy Molnar) started his career in content marketing and has started working as an Editor/Content Manager for our company in 2016. George has acquired many experiences when it comes to interviews and newsworthy content becoming Head of Content in 2017. He is responsible for the news being shared on multiple websites that are part of the European Gaming Media Network.

Latest News

N1 Partners Takes Action at Affiliate World Asia 2025 with a New Award and Key Event Collaborations

Published

on

N1 Partners wrapped up a dynamic week at Affiliate World Asia 2025 in Bangkok, strengthening relationships with industry leaders, taking part in key networking events, engaging with iGaming media, and celebrating a major milestone — winning “The Best Gambling/Betting Affiliate Program” at the Affiliate Space Awards 2025 by Conversion Club.

Across the conference, side events, and business  meetings, the team aligned strategies for 2026, discussed performance trends, explored new collaboration formats, and presented upcoming product updates. These conversations shaped a more focused partnership roadmap for the year ahead.

A defining moment of AWA week was N1 Partners’ success  at the Affiliate Space Awards 2025 by Conversion Club. N1 Parthers was named “Best Gambling/Betting Affiliate Program”. Determined by peer voting and expert evaluation, the award reflects the affiliate program’s proven results, reliability, and consistently strong performance recognized across the industry.

“We’re incredibly grateful for this recognition,” says Alexa Bond, Head of Affiliates at N1 Partners. “What truly makes this program the best is the product depth across our brands, a hands-on affiliate managers team that is always present, and partner conditions designed with care – all that meets affiliates where they are. Winning this award isn’t just about N1 Partners, but every affiliate who grows with us. This is our common win.”

The team also joined the Affiliate Drinks Meetup Bangkok 2025, where the relaxed  setting encouraged direct, meaningful discussions on performance, GEO strategies, and long-term cooperation.

Throughout the week, N1 Partners was present at Fridman Palace, a curated business space where industry leaders gathered for strategic meetings. As the sponsor of the smoking lounge, the company hosted partners in a comfortable, premium environment designed for meaningful conversations and high-level deal-making.

With the Bangkok chapter concluded, the focus now shifts to Barcelona 2026, where N1 Partners will host the grand finale of the N1 Puzzle Promo during iGB/ICE Europe week. The celebration will feature exclusive prizes, a high-energy entertainment program, and the reveal of the Robinson R22 Beta II helicopter winner — setting the stage for one of the most anticipated events of the upcoming iGaming year.

N1 Partners extends its thanks to everyone who connected with the team in Bangkok, shared insights, and contributed to the energy of this week.

Next stop: Barcelona.

Be number one with N1!

Continue Reading

Latest News

Realize Music: Sing Launches on Meta Quest With Broad Catalog From Universal, Warner, Sony and Beggars, Delivered by Tuned Global’s Music Technology

Published

on

Groundbreaking singing game for wellness and creativity expands beyond VR with a PC Gaming release planned for 2026, with the support of Tuned Global’s backend music platform enabling scalable catalogue delivery and lyric integration.

 Realize Music, in collaboration with leading music and media technology platform Tuned Global, announces the launch of Realize Music: Sing, now available on the Meta Quest Store. Co-founded by veteran publisher Mike Wilson, best known as the co-founder of Devolver Digital and Gathering of Developers, the company is positioning Sing as Wilson’s final major venture in the gaming industry; a project that bridges music, wellness, and play across both VR and traditional platforms. Known for championing creativity and emotional depth in gaming, Wilson’s work has consistently challenged the boundaries of what interactive experiences can express.

To support this vision, Realize Music recently selected Tuned Global to power the music backend that enables Sing’s extensive licensed catalogue across platforms.

Launching first on Meta Quest, with plans to expand to additional platforms later in 2026, Sing marks one of the largest music collaborations ever seen in gaming. At release, the app features over one million of the most iconic popular songs officially licensed from Universal Music Group, Warner Music Group, Sony Music Entertainment and Beggars Group, covering an unparalleled range of genres and decades, with new songs to be added regularly. It transforms singing into a hands-on, interactive experience where players can explore, express, and unwind through sound.

Announcing the launch on Meta Quest, Realize Music: Sing also marks the start of its next phase. A Steam PC gaming version and additional platforms are planned for 2026, expanding Sing beyond virtual reality and into new spaces for interactive music and wellness.

“We’ve always believed that games can help people feel better, not just entertained,” said Meta Quest, Realize Music: Sing Co-Founder, Mike Wilson. “Sing is about rediscovering joy without judgment or pressure, through the simple act of raising your own voice and watching the world respond. It’s the kind of project I’ve always hoped to finish my career on, and I hope it inspires other creators to focus their energies on beneficial media.”

“Realize Music: Sing is a breakthrough moment for music-driven wellbeing,” said Con Raso, CEO of Tuned Global. “We’re proud to support the Realize Music team with innovative music technology that empowers their vision and brings it to life in such an exciting way. From licensed catalogue delivery to lyrics and reporting, Sing shows what becomes possible when creativity, wellness, and responsible music innovation come together.”

Players can preview songs for free, purchase individual tracks or albums à la carte, or subscribe for unlimited access. Subscriptions launch at an introductory price of $9.99 per month for the first two months, before moving to $14.99 per month or $119.99 per year.

Realize Music: Sing is available now on the Meta Quest Store.

The post Realize Music: Sing Launches on Meta Quest With Broad Catalog From Universal, Warner, Sony and Beggars, Delivered by Tuned Global’s Music Technology appeared first on Gaming and Gambling Industry Newsroom.

Continue Reading

Latest News

Hub88 strikes Playzia deal to deliver branded content and proprietary mechanics

Published

on

Popular TV-based IPs such as Love Island: Love in a Spin and the other iconic themes made available via aggregator’s platform

Hub88 has boosted its award-winning aggregation platform by entering a strategic agreement with online casino content provider Playzia.

Playzia’s popular games, including Love Island: Love in a Spin – released under licence from ITV Studios – as well as Tale of the Red Dragon, Crazy Chilli Party, The Great Fishing Adventure, Billionaire Wolf and Sweet Candy Fortune, are now available to Hub88’s licensed global operator network.

The agreement brings Playzia’s titles to Hub88’s platform, spanning slots, instant win content and crash and table games, with a focus on regulated market compliance across multiple jurisdictions.

Additionally, Playzia’s proprietary Cubicways mechanic offers players dynamic rotating reel configurations that reveal new progression paths and gameplay environments, a trademarked feature in titles such as Knights 2: The Dragon Cubicways.

The deal further reinforces Hub88’s commitment to offering diverse gaming content from studios that successfully blend entertainment and iGaming, while sharing their regulated-first approach.

Ollie Castleman, Managing Director at Hub88, said: “Playzia has built an impressive portfolio that balances innovation with broad player appeal. Their Cubicways mechanic brings something different to the market, while their branded titles create compelling experiences that attract new player segments.

“As operators look to differentiate their content offering and engage new demographics, partnerships like this become increasingly important.”

Joe Caetano, Commercial Director at Playzia, said: “We’re thrilled to partner with Hub88, a platform that shares our commitment to seamless integration and delivering engaging gaming experiences.

“This collaboration enables us to reach new regulated markets and connect with operators looking for vibrant, high-quality content that resonates with diverse player audiences.”

The post Hub88 strikes Playzia deal to deliver branded content and proprietary mechanics appeared first on Gaming and Gambling Industry Newsroom.

Continue Reading

Trending

EEGaming.org is part of HIPTHER, parent brand of various prominent news outlets and international conferences. These platforms and events span a wide range of industries, including Entertainment, Technology, Gaming and Gambling, Blockchain, Artificial Intelligence, Fintech, Quantum Technology, Legal Cannabis, Health and Lifestyle, VR/AR, eSports, and several others. This indicates that EEGaming.org is part of a larger network that focuses on a diverse array of sectors, particularly those related to cutting-edge technology and modern lifestyle trends.

Contact us: [email protected]

Editorial / PR Submissions: [email protected]

Copyright © 2015 - 2025 HIPTHER. All Rights Reserved. Registered in Romania under Proshirt SRL, Company number: 2134306, EU VAT ID: RO21343605. Office address: Blvd. 1 Decembrie 1918 nr.5, Targu Mures, Romania

We are constantly showing banners about important news regarding events and product launches. Please turn AdBlock off in order to see these areas.