Latest News
MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability


Attackers could exploit the SQL Injection flaw to compromise the game’s database and steal user data.
The CyberNews.com Investigation team discovered a critical vulnerability in Street Mobster, a browser-based massively multiplayer online game created by Bulgarian development company BigMage Studios.
Street Mobster is a free to play, browser-based online game in the mafia empire genre where players manage a fictional criminal enterprise. The game boasts a 1.9+ million player base and stores a user record database that can be accessed by threat actors by committing an SQL Injection (SQLi) attack on the game’s website.
Other games created by BigMage Studios are also potentially vulnerable to the same type of attack, which means that there is a possibility that even more users might be at risk.
The records that can be compromised by exploiting the SQLi vulnerability in Street Mobster potentially include the players’ usernames, email addresses, and passwords, as well as other game-related data that is stored on the database.
Fortunately, after we reported the vulnerability to BigMage Studios, CERT Bulgaria, and the Bulgarian data protection authority, the issue has been fixed by the developers and the user database is no longer accessible to potential attackers.
What is SQL Injection?
First found back in 1998, SQLi is deemed by the Open Web Application Security Project (OWASP) as the number one web application security risk.
Even though this vulnerability is relatively easy to fix, researchers found that 8% of websites and web applications are still vulnerable to SQLi attacks in 2020. Which, from a security perspective, is inexcusable. So much so, in fact, that UK internet service provider TalkTalk was hit with a record £400,000 fine over succumbing to a cyberattack that involved SQLi.
The vulnerability works by injecting an unexpected payload (a piece of code) into the input box on the website or in its URL address. Instead of reading the text as part of the URL, the website’s server reads the attacker’s payload as code and then proceeds to execute the attacker’s command or output data that would otherwise be inaccessible to unauthorized parties. Attackers can exploit SQLi even further by uploading pieces of code or even malware to the vulnerable server.
The fact that Street Mobster is susceptible to SQLi attacks clearly shows the disappointing and dangerous neglect of basic security practices on the part of the developers at BigMage Studios.
How we found this vulnerability
Our security team identified an SQL Injection vulnerability on the Street Mobster website and were able to confirm the vulnerability by performing a simple command injection test on the website URL. The CyberNews team did not extract any data from the vulnerable Street Mobster database.
What’s the impact of the vulnerability?
The data in the vulnerable Street Mobster database can be used in a variety of ways against the players whose information was exposed:
By injecting malicious payloads on Street Mobster’s server, attackers can potentially gain access to said server, where they can install malware on the game’s website and cause harm to the visitors – from using the players’ devices to mine cryptocurrency to redirecting them to other malicious websites, installing malware, and more.
The 1.9 million user credentials stored on the database can net the attackers user email addresses and passwords, which they can potentially use for credential stuffing attacks to hack the players’ accounts on other gaming platforms like Steam or other online services.
Because Street Mobster is a free-to-play game that incorporates microtransactions, bad actors could also make a lot of money from selling hacked player accounts on gray market websites.
What to do if you’ve been affected?
If you have a Street Mobster account, make sure to change your password immediately and make it as complex as possible. If you’ve been using your Street Mobster password on any other websites or services, change that password as well. This will prevent potential attackers from accessing your accounts on these websites in case they try to reuse your password for credential stuffing attacks.
However, it’s ultimately up to BigMage Studios to completely secure your Street Mobster account against attacks like SQLi.
Disclosure and lack of communication from BigMage Studios
Following our vulnerability disclosure guidelines, we notified the BigMage Studios about the leak on August 31, 2020. However, we received no reply. Our follow-up emails were left unanswered as well.
We then reached out to CERT Bulgaria on September 11 in order to help secure the website. CERT contacted the BigMage Studios and informed the company about the misconfiguration.
Throughout the disclosure process, BigMage Studios stayed radio silent and refused to get in touch with CyberNews.com. Due to this reason, we also notified the Bulgarian data protection agency about the incident on October 9 in the hopes that the agency would be able to pressure the company into fixing the issue.
Eventually, however, BigMage Studios appear to have fixed the SLQi vulnerability on streetmobster.com, without informing either CyberNews.com or CERT Bulgaria about that fact.
Source: Latest News on European Gaming Media Network
This is a Syndicated News piece. Photo credits or photo sources can be found on the source article: MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability

Latest News
Meridianbet Expands B2B Operations into Nigeria, Entering a Regulated $2 Billion Betting Market
Meridianbet, a subsidiary of Golden Matrix Group, Inc., has officially launched its B2B operations in Nigeria, one of the largest and fastest-growing betting markets in Africa. The company’s entry into Nigeria further strengthens its 20-year presence in Africa, leveraging its proven track record in regulated markets to deliver world-class gaming products.
Through its newly licensed local entity, Masterlive Network Limited, Meridianbet has secured full regulatory approval from the Lagos State Lotteries and Gaming Authority (LSLGA), allowing it to operate in both sports betting and online casino verticals under License No: LSLGA/OP/OSB/MB041124.
The official launch of Meridianbet.ng marks a strategic expansion into a market worth over $2 billion, according to the research of Orange Business Intelligence Technology, with over 60 million Nigerians actively participate in betting, contributing to one of the fastest-growing industries on the continent.
Zoran Milosevic, CEO of Meridianbet, commented: “Our expansion into Nigeria marks a significant step in our long-term strategy to deepen our presence in Africa’s most dynamic gaming markets. With a highly engaged player base and strong industry growth, Nigeria presents a major opportunity for our B2B model. We are committed to bringing our cutting-edge technology, AI-powered betting solutions, and localized expertise to drive long-term success for our partners in the region.”
FY 2024 Revenue Growth & Investor Outlook
Golden Matrix Group has provided a preliminary full-year 2024 revenue estimate of $150 million, reflecting the company’s continued growth trajectory. The Group expects to release its audited FY 2024 financial results in the coming days, offering investors a comprehensive performance overview. The Nigerian market represents a strategic opportunity for future revenue expansion, aligning with GMGI’s global strategy to strengthen its presence in high-growth gaming markets.
Key Market Potential & Strategic Expansion
According to the Orange Business Intelligence Technology (ORBIT), Nigeria’s betting industry surpassed $2 billion back in 2020, with projections indicating up to $4.7 billion in annual revenue potential over the next decade. Football remains the primary driver of market growth, with a vast customer base engaging both online and offline. Meridianbet’s B2B model will provide advanced technology solutions, gaming content, and platform services to local operators, offering a scalable and highly adaptable system tailored to the Nigerian market.
A Strategic Milestone in Meridianbet’s African Growth
With operations in 18 markets across Europe, Africa, and Latin America, Meridianbet has built a reputation as a leading technology provider and betting operator. The company’s expansion into Nigeria follows its long-standing success in established African markets, where it has been a dominant player for over two decades.
The soft launch of Meridianbet.ng is already delivering positive early results, with strong partner satisfaction and excellent customer feedback.
AI-Powered Innovation & Market Expansion
As part of this rollout, Meridianbet is introducing its proprietary AI Sports Betting Recommender and AI Casino Recommender, delivering personalized betting experiences based on real-time data, player behavior, and predictive analytics. These innovations, already proving successful in multiple markets, will enhance customer engagement, retention, and overall user satisfaction in Nigeria’s rapidly evolving gaming landscape.
The post Meridianbet Expands B2B Operations into Nigeria, Entering a Regulated $2 Billion Betting Market appeared first on European Gaming Industry News.
Latest News
Week 11/2025 slot games releases
Here are this weeks latest slots releases compiled by European Gaming
PG Soft has launched its swashbuckling new 3-reel, 3-row video slot, Mr Treasure’s Fortune. PG Soft’s perilous high-seas expedition blends the nostalgia of classic arcade machines with modern gameplay as players search for the legendary Black Fang Pirates’ hidden fortune.
ELA Games presents its newest development, Noble Crown. This title, with its high-quality graphics, enticing animations and contribution to a balanced portfolio, is a testament to the studio’s design and development philosophy. This 5×3 slot includes iconic symbols commonly seen in classic pub games, such as crowns, diamonds and lucky sevens.
Evoplay has launched Emerald Brewer, a festive slot that captures the spirit of St. Patrick’s Day with vibrant visuals, rewarding features, and a taste of Irish luck. Played on a 5×4 reel layout, the game introduces Wild symbols, which substitute for all regular symbols except Green Pot, Coin, and Bonus symbols.
Swintt, is helping players satisfy their cravings for sugar, spice and all things nice in Candyman – a sweet new Premium release where tumbling reels and multiplier free spins pave the way to candy-coated wins of up to 5,000x. Played out across an expanded 6×5 reel matrix, Candyman does away with conventional lines in favour of a scatter mechanic were collecting eight or more matching symbols guarantees a prize regardless of where they land, with new icons falling from above to potentially create further wins.
Make Slots Great Again! Nolimit City breaks the norm once more in its latest release Home of the Brave. A slot that isn’t afraid to take a jab! No agendas here, just a whole lot of chaotic fun, spicy mechanics and unpredictable gameplay. Unlike typical slots, which are composed of a couple of rows and reels, Home of the Brave includes a Conveyor Belt positioned above the top row and 2 Hot Sauce Reels on either side of the reel area.
Thunderkick has released The Golden Pot & Pints, the latest introduction to its diverse festive-themed portfolio centred around the iconic Irish holiday, St. Patrick’s Day. Set in an Irish tavern, four lucky leprechauns reside on the reels of this 7×7 cluster pays slot, accompanied by tankards, top hats, and shamrocks.
Amusnet has unveiled the latest addition to its Live Casino portfolio, Extra Crown Deluxe Live. The company’s first-ever live slot game seamlessly blends tradition and innovation into an exciting mix of standard slot games and live-streamed action available 24/7.
Million Games is thrilled to announce the launch of Vault Rush, the latest high-volatility online slot developed in collaboration with YUGO Workshop under the Million Stars partner program. This 5×3 reel slot pays homage to the golden era of classic slots, featuring familiar symbols like 7s, Bars, bells, and fruits.
Play’n GO introduces Trinity Impact, a vibrant new slot that combines adventure, magic, and teamwork in a quest to save the mystical realm of Lumina. Immerse yourself in the enchanting world of Trinity Impact, where players join three friends on a heroic journey to protect Lumina, a land of magical wonders and ancient Crystal relics.
Push Gaming has launched the sequel to its 2024 Arctic-themed hit with the release of Big Bite Push Ways. The title will debut the provider’s new mechanic, Push Ways. This mechanic features nudging Hot Zones, which splits any symbol within the overlay into two. This increases the number of available ways to 262,144 and drives engagement.
Amusnet has released a new game for those who enjoy classic slot games with a dice twist. The latest addition to the company’s Online Casino, 100 Golden Coins Dice Edition, comes to life in March to provide a fun gaming experience to all dice lovers. This 5-reel, 100-fixed-payline game combines the classic slot game and dice symbols in entertaining gameplay.
Players can expect a fresh and juicy take on the classic slot experience in the latest title from ICONIC21. Iconic Fruits: Hold and Win sees classic appeal meet modern excitement across a three-by-three gameboard with five paylines active. A feeling of nostalgia will be felt as the reels spin and Fruit and Coin symbols land – this includes Cherries, Lemons, Pineapples, Strawberries and Watermelons.
Blueprint Gaming™ has upped the ante in its latest instalment to the iconic Cash Strike™ series. With the eye-catching win boost feature offering electric collect wins boosted by multipliers, Cash Strike Win Boost increases the player’s chances of returns up to a striking 50,000x. A familiar feast of classic fruit symbols adorns the 3×3, 125 ways to win slot alongside an array of blazing golden coins, heightening the excitement with enlarged opportunities for wins during base play.
Playson, the renowned digital entertainment supplier, is taking casino gameplay into an electric new dimension in its latest release, Charge the Clovers: Hit the Bonus™, as bonus play leads with unique Super Charge and Multi features. Golden clovers, making a welcome return to the 3×3 grid, take the form of bonus symbols alongside boost icons, featuring swirling blue tornados which radiate vibrant energy and boost the chance of eye-catching payouts for players.
Every fisherman has a story to tell. Booming Games brings these stories to life with the brand-new Fish Tales games series! The first game tells a story of a mythical bass, so large it can fit the entire reel! See if this is just a myth or indeed, there is such a creature roaming the deep and reel yourself in some monster wins! Fish Tales Monster Bass is a 5×3, 20-line slot with a boatload of features. Start to net wins with the Fishin’ Time cash collection.
The post Week 11/2025 slot games releases appeared first on European Gaming Industry News.
Latest News
ELA Games Enters the Danish Market Through New Strategic Collaboration With RoyalCasino
ELA Games, a supplier of innovative games in the iGaming industry, has partnered with RoyalCasino to enter the Danish market.
Royal Casino is Denmark’s only land-based and online casino with over 33 years of experience in the gambling industry. The Danish RoyalCasino Group operates the land-based casino in their top-rated Hotel Royal, offering Danish players an elevated gaming experience.
ELA Games’ collaboration with the prestigious Danish brand marks a significant milestone for the development studio, as they are entering the Danish market. As a result, ELA Games’ innovative content, such as hallmark titles like Cash of Gods, It’s Shark Time and Lucky Dwarfs, will be hosted on the RoyalCasino.dk platform.
David Fall, ELA Games’ Business Development Manager, commented on the partnership, “RoyalCasino is an illustrious figure in the Danish gaming scene, and we’re excited to partner with them to provide our content on their platform. RoyalCasino.dk, despite its pedigree, is a rapidly growing brand. With the various promotions prepared in tandem with this announcement, ELA Games looks forward to expanding in Denmark.”
Jonas Madsen, RoyalCasino’s Director of Retention Marketing, added, “We’re very excited about the addition of ELA Games to our portfolio of games at RoyalCasino.dk. ELA Games is an up-and-coming game provider who, in just a few years, has managed to create captivating games with quality graphics, and we’re confident that their content will cater to the preferences of our growing database of players.”
The post ELA Games Enters the Danish Market Through New Strategic Collaboration With RoyalCasino appeared first on European Gaming Industry News.
-
Latest News3 months ago
GamCare releases Annual Report following record breaking year of support on the National Gambling Helpline
-
Latest News3 months ago
Government support, medals, and global recognition define a landmark year for Indian esports and video gaming in 2024
-
Latest News3 months ago
Kambi Group plc repurchase of shares during 18 December – 23 December 2024
-
Latest News3 months ago
India Levels Up: Emerging as a Global Gaming Powerhouse in 2024
-
Latest News3 months ago
Imagine Live Partners with King.rs
-
Latest News1 month ago
Sportradar’s Alpha Odds Receives Dual Honors at European iGaming Awards 2025
-
Latest News1 month ago
Fall in Love with Nature’s Greatest Romantics This Valentine’s Day at Springbok Casino and Claim 25 Free Spins
-
Latest News1 month ago
Swintt secured ISO 27001: 2022 certification
You must be logged in to post a comment Login