Connect with us

Latest News

MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability

Published

on

MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability
MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerabilityReading Time: 3 minutes

Attackers could exploit the SQL Injection flaw to compromise the game’s database and steal user data.

The CyberNews.com Investigation team discovered a critical vulnerability in Street Mobster, a browser-based massively multiplayer online game created by Bulgarian development company BigMage Studios.

Street Mobster is a free to play, browser-based online game in the mafia empire genre where players manage a fictional criminal enterprise. The game boasts a 1.9+ million player base and stores a user record database that can be accessed by threat actors by committing an SQL Injection (SQLi) attack on the game’s website.

Other games created by BigMage Studios are also potentially vulnerable to the same type of attack, which means that there is a possibility that even more users might be at risk.

The records that can be compromised by exploiting the SQLi vulnerability in Street Mobster potentially include the players’ usernames, email addresses, and passwords, as well as other game-related data that is stored on the database.

Fortunately, after we reported the vulnerability to BigMage Studios, CERT Bulgaria, and the Bulgarian data protection authority, the issue has been fixed by the developers and the user database is no longer accessible to potential attackers.

What is SQL Injection?

First found back in 1998, SQLi is deemed by the Open Web Application Security Project (OWASP) as the number one web application security risk.

Even though this vulnerability is relatively easy to fix, researchers found that 8% of websites and web applications are still vulnerable to SQLi attacks in 2020. Which, from a security perspective, is inexcusable. So much so, in fact, that UK internet service provider TalkTalk was hit with a record £400,000 fine over succumbing to a cyberattack that involved SQLi.

The vulnerability works by injecting an unexpected payload (a piece of code) into the input box on the website or in its URL address. Instead of reading the text as part of the URL, the website’s server reads the attacker’s payload as code and then proceeds to execute the attacker’s command or output data that would otherwise be inaccessible to unauthorized parties. Attackers can exploit SQLi even further by uploading pieces of code or even malware to the vulnerable server.

The fact that Street Mobster is susceptible to SQLi attacks clearly shows the disappointing and dangerous neglect of basic security practices on the part of the developers at BigMage Studios.

 

How we found this vulnerability

Our security team identified an SQL Injection vulnerability on the Street Mobster website and were able to confirm the vulnerability by performing a simple command injection test on the website URL. The CyberNews team did not extract any data from the vulnerable Street Mobster database.

What’s the impact of the vulnerability?

The data in the vulnerable Street Mobster database can be used in a variety of ways against the players whose information was exposed:

By injecting malicious payloads on Street Mobster’s server, attackers can potentially gain access to said server, where they can install malware on the game’s website and cause harm to the visitors – from using the players’ devices to mine cryptocurrency to redirecting them to other malicious websites, installing malware, and more.

The 1.9 million user credentials stored on the database can net the attackers user email addresses and passwords, which they can potentially use for credential stuffing attacks to hack the players’ accounts on other gaming platforms like Steam or other online services.

Because Street Mobster is a free-to-play game that incorporates microtransactions, bad actors could also make a lot of money from selling hacked player accounts on gray market websites.

What to do if you’ve been affected?

If you have a Street Mobster account, make sure to change your password immediately and make it as complex as possible. If you’ve been using your Street Mobster password on any other websites or services, change that password as well. This will prevent potential attackers from accessing your accounts on these websites in case they try to reuse your password for credential stuffing attacks.

However, it’s ultimately up to BigMage Studios to completely secure your Street Mobster account against attacks like SQLi.

Disclosure and lack of communication from BigMage Studios

Following our vulnerability disclosure guidelines, we notified the BigMage Studios about the leak on August 31, 2020. However, we received no reply. Our follow-up emails were left unanswered as well.

We then reached out to CERT Bulgaria on September 11 in order to help secure the website. CERT contacted the BigMage Studios and informed the company about the misconfiguration.

Throughout the disclosure process, BigMage Studios stayed radio silent and refused to get in touch with CyberNews.com. Due to this reason, we also notified the Bulgarian data protection agency about the incident on October 9 in the hopes that the agency would be able to pressure the company into fixing the issue.

Eventually, however, BigMage Studios appear to have fixed the SLQi vulnerability on streetmobster.com, without informing either CyberNews.com or CERT Bulgaria about that fact.

 

Source


Source: Latest News on European Gaming Media Network
This is a Syndicated News piece. Photo credits or photo sources can be found on the source article: MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability

George Miller (Gyorgy Molnar) started his career in content marketing and has started working as an Editor/Content Manager for our company in 2016. George has acquired many experiences when it comes to interviews and newsworthy content becoming Head of Content in 2017. He is responsible for the news being shared on multiple websites that are part of the European Gaming Media Network.

Latest News

Atlaslive Shortlisted in Three Categories at the European iGaming Awards 2026

Published

on

Atlaslive has been shortlisted for three categories at the European iGaming Awards 2026: Best Customer Service Award, Best Sportsbetting Innovation, and Best iGaming Platform Supplier.

The European iGaming Awards is held annually during ICE Barcelona and brings together companies shaping the future of sportsbook and casino technology. The 2026 ceremony will take place on 19 January 2026 in Barcelona, recognising providers whose work has gained strong industry attention during the year.

Atlaslive’s shortlisting reflects a year of steady product improvement, new sportsbook features, and strengthened service operations. The company has focused on creating tools that support operator growth while keeping platform setup flexible and transparent.

“The shortlist recognizes the work our people do every day. Most improvements never make it into headlines, but together they shape the experience our partners and their players have every day. Being named in three categories tells us that this everyday work matters.”

—Anastasiia Poltavets, CMO, Atlaslive

About the European iGaming Awards

Organized by Datateam Business Media, the European iGaming Awards highlight companies that bring reliable products, thoughtful features, and stable services to the sector. Finalists are selected by a panel of industry professionals, with winners announced during the awards ceremony held alongside ICE Barcelona.

About Atlaslive

Atlaslive is a global B2B iGaming platform provider offering sportsbook and casino technology built for high-load environments. The company focuses on product quality, platform stability, and open communication with operators worldwide.

This document is provided to you for your information and discussion only. This document was based on public sources of information and was created by the Atlaslive team for marketing usage. It is not a solicitation or an offer to buy or sell any gambling-related product. Nothing in this document constitutes legal or business development advice. This document has been prepared from sources Atlaslive believes to be reliable, but we do not guarantee its accuracy or completeness and do not accept liability for any loss arising from its use. Atlaslive reserves the right to remedy any errors that may be present in this document.

About Atlaslive

Atlaslive, formerly known as Atlas-IAC, underwent a rebranding campaign in May 2024. It is a B2B software development company that specializes in creating a multifunctional and automated platform to optimize the workflow of sports betting and casino operators. Key components of the Atlaslive Platform include Sportsbook, Casino, Risk Management and Anti-Fraud Tools, CRM, Bonus Engine, Business Analytics, Payment Systems, and Retail Module. Follow the company on LinkedIn to stay updated with the latest news in iGaming technology.

Continue Reading

Latest News

How RocketWisdom Turned From An Internal Activity Into a Marketing Case

Published

on

Reading Time: 4 minutes

When looking for ways to unite a community through genuine engagement, The Book of RocketWisdom shows what can happen when a brand chooses to honour its players. Originally created as a small tribute — a quiet gesture of gratitude toward the RocketPlay community — the project captures over 100 real strategies, insights and gameplay habits shared by players themselves.

What began as an intimate, non-public initiative has now taken on a life of its own. The book has been downloaded thousands of times and continues to appear in streams, media features and YouTube discussions — a rare case where authentic player voices grew into a meaningful, high-impact content project. Discover how a small, community-led initiative unexpectedly developed into a successful marketing case.

How the Project Started

RocketWisdom began very differently from what it is today. Initially, the project was not designed as a campaign or public initiative. It originated as a small, personal effort within the RocketPlay team — intended solely as a meaningful gesture to the existing community. The team wanted to better understand how players think about the game, how they make intuitive choices during play, and which personal strategies they rely on.

To explore this, RocketPlay didn’t turn to numbers — it turned to people. The team listened to real player voices, collecting their stories, habits and small rituals that shape how they play.

Based on the quality of insights gathered, the decision was made to convert this material into a document that would preserve the authentic voice of the community. That format eventually became The Book of RocketWisdom. Designed as a collection of 100 real strategies based on player stories, it was produced as a warm, personal project. The Book was something intended to remain exclusive to the community, not to be used as a tool for communication or promotion.

An Unexpected Turn

The turning point came from where no one expected it. While the book was still in its final layout, the contractor working on the design felt it was too special to stay unseen — and quietly shared it with a few streamers.

The reaction was immediate. During the final layout stage, the book designers — genuinely moved by the material — shared the book with a small group of streamers, believing it deserved to live beyond a private archive and reach the very players it celebrated.

On air, streamers opened it with surprise, asking, “What is this, and who made it?”
The RocketPlay team watched in real time as curiosity turned into enthusiasm. Within minutes, chat rooms lit up, inboxes began to fill, and it became clear that a tribute intended for a closed community was suddenly becoming a public discovery.

Streamers began flipping through the pages live, reacting to the strategies, laughing, debating them with viewers — all in real time. They still had no idea who created the book. But after a quick search of the title, they found an earlier mention of the project in industry media — one of RocketPlay’s previous publications — and realised the book belonged to RocketPlay.

That moment changed everything.
As soon as the connection was made, the viewer’s interest surged. The RocketPlay inbox filled up almost instantly — emails, DMs, comments, messages from every channel asking the same thing: “Where can I get this book?”

For a project that had never been announced publicly, the volume was overwhelming in the best possible way. It felt like the community had discovered a gift meant for them — and wanted to be part of it immediately.

What started as a quiet internal project had suddenly become something the community was actively asking for — and the momentum was too strong to ignore. The decision to open RocketWisdom to everyone was made almost instantly, driven by the simple thought: if players want it, they should have it.

Within days, the team assembled a dedicated landing page, prepared the book for public release, and shifted the project from an internal archive to open access.

Release and Reaction

The impact of that decision was visible immediately. Website traffic spiked on the launch day. At the time of writing this case, the book has already been downloaded more than 10,000 times. The number continues to rise, which suggests a strong level of sustained interest rather than a short-term campaign effect.

Following release, the project gained momentum naturally. Without formal promotion, RocketWisdom appeared in thematic media reports, industry articles, printed gaming publications and YouTube content. Several streamers integrated the book into their broadcasts, selecting individual strategies and testing them live for their audiences. Those who first showed the book were later contacted, and RocketPlay established partnerships with them, providing personalised bonuses to support their content.

At this stage, the project has featured in approximately 80 streams and has been referenced across more than 50 industry publications. It has also been covered in 3 major interviews and discussed by creators with high viewer reach.

What stands out about RocketWisdom is that it never started as marketing. It began as a warm, community-focused project — and only later turned into a high-performing communication case because players recognised themselves in it. Its success came from resonance, not planning.

For RocketPlay, the project became a reminder of who truly shapes the brand. And for the players, it became a gesture of appreciation that grew far beyond its initial intention. RocketWisdom continues to expand organically, showing that the strongest stories in iGaming still come from people.

The Book of RocketWisdom remains available for free download on the RocketPlay website. It contains 100 real strategies shared by actual players, and can be used by anyone wishing to explore them in practice.

The post How RocketWisdom Turned From An Internal Activity Into a Marketing Case appeared first on European Gaming Industry News.

Continue Reading

Latest News

Kaizen Foundation partners with Ashoka to empower future social entrepreneurs

Published

on

Reading Time: 2 minutes

Kaizen Foundation, the Social Purpose Foundation funded exclusively by Kaizen Gaming, is partnering with Ashoka, one of the world’s leading organisations dedicated to social entrepreneurship, to support the next generation of social innovators and changemakers. Through this collaboration, the Kaizen Foundation will contribute to Ashoka’s global work and fund two outstanding new Ashoka Fellows – one in Portugal and one in Romania.

For more than 40 years, Ashoka has built and nurtured the largest network of social entrepreneurs in the world, with each Fellow committed to driving innovation and creating meaningful, long-term change. Addressing challenges such as poverty, access to healthcare and the development of inclusive public services, Ashoka fosters changemaking ecosystems through partnerships across education, civil society and business. Its youth initiatives promote empathy, co-creation and problem-solving as core skills to achieve system-level change.

Recent Fellows in Romania include Dorica Dan, who revolutionizes the field of care for rare disease patients, influencing national legislation to improve diagnosis and access to therapies. In Portugal, Celmira Macedo tackles barriers to education and health literacy and supports students with special needs, reaching over 100,000 people in 76 Portuguese cities.

Once identified and selected for Ashoka’s Global Fellowship, the two new entrepreneurs will be fully funded by the Kaizen Foundation and will join a vibrant global community of Fellows across 95 countries. In addition to supporting Ashoka’s backbone operations, the Kaizen Foundation will also support the Ashoka Fellowship offering for all current Fellows – a programme designed to sustain and strengthen the global, national and regional infrastructure that helps Fellows thrive, scale their impact and collaborate across borders.

Panos Konstantopoulos, President of the Kaizen Foundation, noted: “Real impact begins with people – those who dare to imagine better futures and work tirelessly to build them. Ashoka has created one of the strongest communities of changemakers worldwide. Supporting new Fellows in Portugal and Romania allows us to stand behind individuals who are addressing critical social challenges with courage and creativity. We’re honoured to help strengthen the communities they serve.”

David Bonbright, Member of the Global Leadership Group at Ashoka, commented: “We are delighted to welcome the Kaizen Foundation into Ashoka’s global community of partners. Their strong focus on innovation, technology and long-term social impact makes them a natural ally in our effort to build a world where everyone can be a changemaker. With their support, we will be able to identify and back outstanding entrepreneurs in Portugal and Romania, while also strengthening the support system that enables all our Fellows to collaborate, learn from one another and scale their impact.”

The post Kaizen Foundation partners with Ashoka to empower future social entrepreneurs appeared first on European Gaming Industry News.

Continue Reading

Trending

EEGaming.org is part of HIPTHER, parent brand of various prominent news outlets and international conferences. These platforms and events span a wide range of industries, including Entertainment, Technology, Gaming and Gambling, Blockchain, Artificial Intelligence, Fintech, Quantum Technology, Legal Cannabis, Health and Lifestyle, VR/AR, eSports, and several others. This indicates that EEGaming.org is part of a larger network that focuses on a diverse array of sectors, particularly those related to cutting-edge technology and modern lifestyle trends.

Contact us: [email protected]

Editorial / PR Submissions: [email protected]

Copyright © 2015 - 2025 HIPTHER. All Rights Reserved. Registered in Romania under Proshirt SRL, Company number: 2134306, EU VAT ID: RO21343605. Office address: Blvd. 1 Decembrie 1918 nr.5, Targu Mures, Romania

We are constantly showing banners about important news regarding events and product launches. Please turn AdBlock off in order to see these areas.