Latest News
MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability

Reading Time: 3 minutes
Attackers could exploit the SQL Injection flaw to compromise the game’s database and steal user data.
The CyberNews.com Investigation team discovered a critical vulnerability in Street Mobster, a browser-based massively multiplayer online game created by Bulgarian development company BigMage Studios.
Street Mobster is a free to play, browser-based online game in the mafia empire genre where players manage a fictional criminal enterprise. The game boasts a 1.9+ million player base and stores a user record database that can be accessed by threat actors by committing an SQL Injection (SQLi) attack on the game’s website.
Other games created by BigMage Studios are also potentially vulnerable to the same type of attack, which means that there is a possibility that even more users might be at risk.
The records that can be compromised by exploiting the SQLi vulnerability in Street Mobster potentially include the players’ usernames, email addresses, and passwords, as well as other game-related data that is stored on the database.
Fortunately, after we reported the vulnerability to BigMage Studios, CERT Bulgaria, and the Bulgarian data protection authority, the issue has been fixed by the developers and the user database is no longer accessible to potential attackers.
What is SQL Injection?
First found back in 1998, SQLi is deemed by the Open Web Application Security Project (OWASP) as the number one web application security risk.
Even though this vulnerability is relatively easy to fix, researchers found that 8% of websites and web applications are still vulnerable to SQLi attacks in 2020. Which, from a security perspective, is inexcusable. So much so, in fact, that UK internet service provider TalkTalk was hit with a record £400,000 fine over succumbing to a cyberattack that involved SQLi.
The vulnerability works by injecting an unexpected payload (a piece of code) into the input box on the website or in its URL address. Instead of reading the text as part of the URL, the website’s server reads the attacker’s payload as code and then proceeds to execute the attacker’s command or output data that would otherwise be inaccessible to unauthorized parties. Attackers can exploit SQLi even further by uploading pieces of code or even malware to the vulnerable server.
The fact that Street Mobster is susceptible to SQLi attacks clearly shows the disappointing and dangerous neglect of basic security practices on the part of the developers at BigMage Studios.
How we found this vulnerability
Our security team identified an SQL Injection vulnerability on the Street Mobster website and were able to confirm the vulnerability by performing a simple command injection test on the website URL. The CyberNews team did not extract any data from the vulnerable Street Mobster database.
What’s the impact of the vulnerability?
The data in the vulnerable Street Mobster database can be used in a variety of ways against the players whose information was exposed:
By injecting malicious payloads on Street Mobster’s server, attackers can potentially gain access to said server, where they can install malware on the game’s website and cause harm to the visitors – from using the players’ devices to mine cryptocurrency to redirecting them to other malicious websites, installing malware, and more.
The 1.9 million user credentials stored on the database can net the attackers user email addresses and passwords, which they can potentially use for credential stuffing attacks to hack the players’ accounts on other gaming platforms like Steam or other online services.
Because Street Mobster is a free-to-play game that incorporates microtransactions, bad actors could also make a lot of money from selling hacked player accounts on gray market websites.
What to do if you’ve been affected?
If you have a Street Mobster account, make sure to change your password immediately and make it as complex as possible. If you’ve been using your Street Mobster password on any other websites or services, change that password as well. This will prevent potential attackers from accessing your accounts on these websites in case they try to reuse your password for credential stuffing attacks.
However, it’s ultimately up to BigMage Studios to completely secure your Street Mobster account against attacks like SQLi.
Disclosure and lack of communication from BigMage Studios
Following our vulnerability disclosure guidelines, we notified the BigMage Studios about the leak on August 31, 2020. However, we received no reply. Our follow-up emails were left unanswered as well.
We then reached out to CERT Bulgaria on September 11 in order to help secure the website. CERT contacted the BigMage Studios and informed the company about the misconfiguration.
Throughout the disclosure process, BigMage Studios stayed radio silent and refused to get in touch with CyberNews.com. Due to this reason, we also notified the Bulgarian data protection agency about the incident on October 9 in the hopes that the agency would be able to pressure the company into fixing the issue.
Eventually, however, BigMage Studios appear to have fixed the SLQi vulnerability on streetmobster.com, without informing either CyberNews.com or CERT Bulgaria about that fact.
Source: Latest News on European Gaming Media Network
This is a Syndicated News piece. Photo credits or photo sources can be found on the source article: MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability
Latest News
FairPlay Sports Media and FOX Sports Digital Launch New Betting Hub
FairPlay’s betting technology and AI-powered predictive content drive deeper fan engagement and deliver media opportunities and revenue
FOX Sports Digital and FairPlay Sports Media, the fan-focused and AI-powered global sports media network, have announced a strategic betting tech, affiliate and sports media agreement.
Under the multi-year agreement, FairPlay will serve as the exclusive sports betting affiliate technology provider of FOX Sports Digital, deploying its market-leading odds components, advanced AI-powered predictive data and analytics, and cutting-edge technology solutions on FOXSports.com and the FOX Sports mobile application.
The new relationship powers the newly released FOX Sports Betting Hub which integrates FairPlay’s innovative sports betting-related content enhanced with bespoke, value-added experiences derived from FairPlay’s deep relationships with global sportsbook operators.
“FOX Sports is one of the largest sports rights holders in the world, with incredible access to live games and global events,” said Stuart Simms, Group CEO of FairPlay Sports Media. “FairPlay is excited to work with the FOX Sports Digital team, and we’re honored to serve their millions of users with more engaging, insightful sports media experiences that have proven to drive loyalty, engagement and deliver on brand differentiation.”
FairPlay’s advanced AI technology and robust odds components are already delivering real-time, data-driven insights to help FOX Sports fans and bettors, while monetization frameworks being deployed create revenue opportunities for operators, sportsbooks and digital media buyers.
The agreement enhances and elevates fan engagement by bringing FairPlay’s betting information technology and AI-powered tools to FOX Sports’ digital platforms. FairPlay’s approach enables FOX Sports digital users and fans to access personalized, data-driven betting analytics that deepen their connection and engagement with sports content. As the sports media and betting landscapes continue to evolve, the FOX Sports and FairPlay agreement delivers pioneering, scalable digital experiences for fans and operators alike.
The post FairPlay Sports Media and FOX Sports Digital Launch New Betting Hub appeared first on Gaming and Gambling Industry Newsroom.
Latest News
Betfred Launches Checkd Dev’s Automated Betting System to Strengthen Football Betting Offering
Checkd Dev, part of the award-winning Checkd Group and a leading iGaming technology provider, has signed a multi-year agreement to supply its Automated Betting System (ABS) to UK bookmaker Betfred, introducing new levels of efficiency and engagement to pre-match football accumulator betting.
Through the partnership, Betfred has launched a suite of pre-configured, one-click accumulator bets, powered by Checkd Dev’s ABS technology and seamlessly integrated with Betfred’s proprietary pricing.
The solution enhances the customer betting journey while equipping Betfred’s trading team with a robust backend platform to streamline bet creation, management, and settlement. Customers benefit from football bets that are dynamically assigned probabilities based on historic form, providing greater insight and confidence in their selections.
The launch of ABS reinforces Betfred’s reputation as an industry innovator, offering customers smarter, faster, and more engaging betting experiences.
Checkd Dev has refined its ABS user interface through deployments with multiple tier-one operators. Betfred has further strengthened the proposition by integrating its competitive Acca Flex bonus offer, available from launch. Customers can access additional bonuses if their bet wins, while also benefiting from a money-back guarantee if a single leg loses.
Since its introduction two years ago, Checkd Dev’s ABS has evolved from a statistics-driven tool to increase operator conversion rates into a comprehensive system designed to meet the growing demand for automated, pre-configured betting products, powered by the company’s proprietary BRUNO platform.
This agreement extends Checkd Dev’s recent growth trajectory, following high-profile partnerships with William Hill on a fully automated, stats-powered Bet Builder, and a three-year deal with OpenBet to launch a new Trending BetBuilder to market.
Andrew Grimshaw, Commercial Director at Checkd Dev, commented: “We are delighted to be working with fellow Mancunians Betfred on our Trending Bets product. More and more major bookmakers are recognising the tangible value of our automated betting solutions, and it is especially gratifying to collaborate with a local partner on this launch.”
Mark Hartley, Head of Product at Betfred, added: “Since moving onto our propriety platform, we’ve been able to bring new ideas to market much faster. This partnership with Checkd Dev is a great example, helping us solve a simple problem for football fans: researching and building an accumulator can sometimes feel like hard work!
“With one-click, data-driven selections we’ve made the process quicker and easier, while still giving customers the choice and depth they want. Accas are already one of our most compelling propositions, thanks to our popular promotion Acca Flex, and this launch makes them even more engaging. We’re also looking forward to exploring further opportunities to work with Checkd Dev in the future.”
The post Betfred Launches Checkd Dev’s Automated Betting System to Strengthen Football Betting Offering appeared first on Gaming and Gambling Industry Newsroom.
Latest News
Slotland’s Crown Jewel, Gods of Egypt, Resurrects with Enhanced Features
Legendary Title Reborn for a New Generation of Fortune Seekers with Freebies and Bonuses until December 28th
Slotland Entertainment has ceremoniously relaunched its legendary title, Gods of Egypt, across its casinos Slotland, Winaday and now including CryptoSlots and CryptoWins. This revered 5×4, 30-payline slot invites players into a grand temple of mythic wealth.
Wager $1.50 to $30 to awaken divine features: Ra’s Sticky Expanding Wilds, Bastet’s gem-triggered Free Spins, and a Pick Me Bonus with layered treasures. For those betting $15 or more, five Pharaoh symbols unlock the progressive jackpot.
“Gods of Egypt has always been a crown jewel in our collection,” said Michael Hilary, Manager at Slotland. “This relaunch across our entire empire allows a new generation of players to experience its timeless magic and seek its legendary rewards.”
Framed by the regal visages of Anubis and a jeweled queen, the game creates a ceremonial atmosphere of arcade spectacle. It is a call to modern seekers: enter and claim your ancient riches.
WINADAY CASINO: Available December 19 – 28, 2025
Up to $111 FREEBIE chip
- For platinum VIPs, $88 for Gold VIPs, $55 for Silver VIPs, $44 for Bronze VIPs, $20 for ALL
- Redeem: 1x, wager: 29x, max cashout 5x, depositing players only
- Bonus Code: FREEBIE2025
Up to 155% NEW GAME BONUS
- For VIPs, 100% for ALL
- On deposits on $10 – $250
- Redeem: 2x per day, wager: 29x, valid: Gods of Egypt
- Bonus code: NEWSLOT
CRYPTOSLOTS: Available December 17 – 25, 2025
123% VIP TREASURE MATCH
- On deposits $50-500
- Redeem: 1x per day, wager: 35x, valid: Gods of Egypt
- Bonus code: VIPNEW
77$ DESERT GOLD MATCH
- On deposits 200 – $400, 65% on $100 – $199, 50% on $10 – $99
- Redeem: 2x per day, wager: 35x, valid: Gods of Egypt
- Bonus code: NEWIN
The post Slotland’s Crown Jewel, Gods of Egypt, Resurrects with Enhanced Features appeared first on Gaming and Gambling Industry Newsroom.
-
Latest News3 months ago
Announcement: 25th September 2025
-
Latest News6 days agoSCCG Announces Strategic Partnership with Yellow Elephant Studios to Expand Multi-Channel Gaming Content Worldwide
-
Latest News1 month ago
JioBLAST Launches All Stars vs India powered by Campa Energy: A New Era of Creator-Driven Esports Entertainment
-
Latest News3 months ago
The Countdown is On: Less Than 3 Months to Go Until The Games of The Future 2025 Kicks Off in Abu Dhabi
-
eSports1 month ago
CS:GO Betting Gains Momentum in the iGaming Sector
-
Latest News2 weeks ago
THE 2025 PUBG MOBILE GLOBAL CHAMPIONSHIP GROUP STAGE WRAPS UP WITH LAST CHANCE IN SIGHT
-
Latest News3 months ago
Leading The Charge! Euronics Group Joins LEC As Official Electronics Retail Partner
-
Latest News3 months ago
Evolution launches Sneaky Slots — a Bold New Slot Studio


You must be logged in to post a comment Login