Connect with us
MARE BALTICUM Gaming & TECH Summit 2024

Latest News

Popular Gambling App Exposed Millions of Users in Massive Data Leak

Published

on

Reading Time: 5 minutes

 

Led by Noam Rotem and Ran Locar, vpnMentor’s research team discovered a data breach on casino gambling app Clubillion.

The breach originated in a technical database built on an Elasticsearch engine and was recording the daily activities of millions of Clubillion players around the world.

Aside from leaking activity on the app, the breached database also exposed private user information.

Advertisement

With this information publicly available, Clubillion’s users were vulnerable to fraud and various online attacks with potentially devastating results.

Company Profile

Clubillion is a free online casino game available for iOS and Android, offering players 30+ free slot games. While each app is listed under a different developer – Ouroboros on iOS and T7 Games on Android – these are most likely owned by the same company.

Both versions of Clubillion were released in 2019 and became instant hits. Each is now ranked the #1 ‘social slots’ casino app on Google Play and the App Store, with a 4.8 star on both.

Timeline of Discovery and Owner Reaction

Sometimes, the extent of a data breach and the owner of the database are obvious, and the issue quickly resolved. But rare are these times. Most often, we need days of investigation before we understand what’s at stake or who’s leaking the data.

Understanding a breach and its potential impact takes careful attention and time. We work hard to publish accurate and trustworthy reports, ensuring everybody who reads them understands their seriousness.

Advertisement

Some affected parties deny the facts, disregarding our research, or playing down its impact. So, we need to be thorough and make sure everything we find is correct and accurate.

In this case, the database was built on Elasticsearch and hosted on Amazon Web Services (AWS), with Clubillion’s name on its apps, and links to assets owned by the company.

Once Clubillion was confirmed as the owner of the database, we reached out to the developers. While awaiting a reply, we also contacted AWS with details of the leak. It was closed a few days later.

  • Date discovered: 19th March 2020
  • Date vendors contacted: 23rd March 2020
  • Date of contact with AWS: 31st March 2020
  • Date of Action: Approx. 5th April 2020

Example of Entries in the Database

Clubillion’s exposed database contained technical logs for millions of Clubillion users around the world, on both iOS and Android devices. Every time an individual player took any action on the app, a record was logged. Examples of records include:

  • “enter game”
  • “win”
  • “lose”
  • “update account”
  • “create account”

During our investigation of the database, new entries continued to appear continuously. We estimated an average of approximately 200 million records per day – and sometimes, considerably more.

In total, this amounted to over 50GB of exposed records in the database every single day.

Within many of these records, were various forms of user Personally Identifiable Information (PII) data, including:

Advertisement
  • IP addresses
  • Email addresses
  • Winnings
  • Private messages

This data breach was truly global, with millions of records originating from Clubillion’s daily users all over the world. The following list is just a sample of countries affected, along with the average number of daily users from each country:

  • USA – 10,000+
  • UK – 2,475+
  • France – 1,650+
  • Israel – 408+
  • Germany – 1,582+
  • Spain – 1,026+
  • Italy – 2,407+
  • Netherlands – 622+
  • Australia – 6,251+
  • Canada – 7,792+
  • Brazil – 3,859+
  • Sweden – 191+
  • Russia – 547+

Other countries affected included Uzbekistan, India, Poland, Romania, Vietnam, Lebanon, Indonesia, Philippines, Pakistan, Thailand, Austria, Hungry, and Latvia.

As you can see, on a single day, 10,000s of individual Clubillion players were exposed. Each one of these players could be targeted by malicious hackers for fraud and cyberattacks – along with millions more whose records were also contained in the database.

Data Breach Impact

Studies have shown that free gambling and gaming apps are especially prone to attacks and hacking from cybercriminals. They are routinely targeted for theft of private data and embedding malicious software on users’ devices.

Despite their popularity, gambling and casino apps often lack transparency, and it can be impossible to know what steps they’re taking to prevent cybercriminals successfully targeting their users.

One study of 23,000 free gambling apps found that: 3,200 posed a ‘moderate risk’ to users; 379 had known security vulnerabilities; 52 contained malicious software.

Any of these issues could be exploited to target app users in a wide range of frauds and cyberattacks, and Clubillion is no different.

Advertisement

With the exposed user PII and knowledge of their activity on the app, hackers could create elaborate schemes to defraud users. For example, some entries also included transaction errors for attempted card payments on Clubillion.

With the information in these transaction errors, hackers could target users with phishing campaigns, with the following aims:

  1. Trick them into providing their credit card details
  2. Trick them into providing additional PII to be used against them in further fraud
  3. Clicking a link that embeds malware, spyware, or ransomware onto their device.

If cybercriminals used Clubillion to embed malware or similar onto a user’s phone, they could potentially hack other apps, access files stored on the device, make calls, and send texts from the hacked device. They could even access a user’s phone contacts and steal the PII data of their friends and family.

Worse still, as people across the globe now find themselves under quarantine or self-isolation, as a result of the Coronavirus pandemic, the impact of a leak like this is potentially even more significant.

Clubillion stands to gain many new users, along with regular users playing more frequently. Hackers will be aware of this and looking for opportunities to exploit any vulnerabilities in the data security of such a massively popular app.

Had criminal hackers discovered Clubillion’s database, they could have targeted millions of people around the world, with devastating results.

Advertisement

Impact on Clubillion and it’s Developers

The most immediate risk for Clubillion is the loss of players. Data security is a growing concern for everyone these days, and this leak could turn many players off the app. Clubillion is not unique, and players have plenty of other choices for free gambling apps.

With fewer players, Clubillion will lose advertising revenue and reduced profits.

As many of Clubillion’s players reside within the EU, the app is under the jurisdiction of GDPR. The rules of GDPR also apply to apps, and Clubillion will need to take specific actions to ensure the regulatory body in charge doesn’t reprimand it.

Finally, Clubillion could also potentially be removed from Google Play and the App Store. Both Apple and Google are clamping down on apps that pose a risk to their users, removing apps embedded with malware, and taking data leaks much more seriously.

Each of these outcomes has a different likelihood of happening, but they would all negatively impact Clubillion’s revenue and business.

Advertisement

Advice from the Experts

Clubillion’s developers could have easily avoided this leak if they had taken some basic security measures to protect the database. These include, but are not limited to:

  1. Securing their servers.
  2. Implementing proper access rules.
  3. Never leaving a system that doesn’t require authentication open to the internet.

Any company can replicate the same steps, no matter its size.

For a more in-depth guide on how to protect your business, check out our guide to securing your website and online database from hackers.

For Clubillion Users

If you play on Clubillion and are concerned about how this breach might impact you, contact the app’s developers directly to find out what steps it’s taking to protect your data.

To learn about data vulnerabilities in general, read our complete guide to online privacy.

It shows you the many ways cybercriminals target internet users, and the steps you can take to stay safe.

Advertisement

How and Why We Discovered the Breach

The vpnMentor research team discovered the breach in Clubillion’s database as part of a huge web mapping project. Our researchers use port scanning to examine particular IP blocks and test different systems for weaknesses or vulnerabilities. They examine each weakness for any data being leaked.

Our team was able to access this database because it was completely unsecured and unencrypted. 

Whenever we find a data breach, we use expert techniques to verify the owner of the database, usually a commercial company.

As ethical hackers, we’re obliged to inform a company when we discover flaws in their online security. We reached out to Clubillion’s developers, not only to let them know about the vulnerability but also to suggest ways in which they could make their system secure.

These ethics also mean we carry a responsibility to the public. Clubillion users must be aware of a data breach that exposes so much of their sensitive data.

Advertisement

The purpose of this web mapping project is to help make the internet safer for all users.

 

Source

Continue Reading
Advertisement

Latest News

BGaming donates to Brazilian art institute in support of creative children’s projects

Published

on

bgaming-donates-to-brazilian-art-institute-in-support-of-creative-children’s-projects
Reading Time: 2 minutes

 

Popular iGaming content provider BGaming has bolstered its ongoing commitment to grassroots arts by making donations to the A7MA Galeria Institute in Sao Paulo, Brazil, which supports children’s creative development.

As part of its ‘When Art Meets Gaming’ project, BGaming has collaborated with several local artists to create murals for industry events over the last year. For SiGMA Americas in April, the studio also chose to give back to the host city by funding art projects for children.

BGaming made a donation to support three charity initiatives. A portion was donated to coordinate a visit to the A7MA Gallery, where children from the Felicidarte Project took a tour of popular tourist attraction ‘Batman’s Alley’ and learnt about the art. Later, A7MA funded an activity where children were invited to transform the facades of their homes into colourful murals.

Advertisement

Another part of the donation was allocated to renovations for Felicidarte Project’s warehouse space, to revamp the area so it can invite school groups each week and distribute food to the underprivileged areas.

The significant charitable push follows a successful SiGMA Americas in Sao Paulo from 23rd to 26th April, where BGaming collaborated with artistic duo, Clandestinos Art, to reinterpret BGaming’s iconic game heroes, and create a limited edition merchandise collection, branded gifts and their stand design.

Marina Ostrovtsova, CEO at BGaming, said: “At BGaming, it brings us so much joy to see our donations promoting art among the young people of Sao Paulo.

“As we have proven over the past year with our ‘Art Meets Gaming’ project, creativity unites us all and we were delighted to hear how much the children enjoyed the activities provided. We can’t wait to hear about these budding artist’s creations in the future.”

Marcos Ramos Enivo, Artist and Counsellor at A7MA Galeria Institute, said: “We are grateful to BGaming for their support of our work at A7MA. The activities exceeded our expectations, with 47 artists present and 46 facades revitalised by the children.

Advertisement

“It was an absolute success. People in the favelas who are sometimes invisible to the government can now feel seen, recognised and valued.”

 

BGaming is a fast-growing iGaming content provider converting gambling into gaming. Thanks to an expert team and a player-driven approach, the studio creates innovative and engaging products featured on reputable platforms and 1,100+ online casinos worldwide. BGaming is the world’s first to support cryptocurrencies and offer Provably Fair games. Today the brand’s portfolio includes 150+ products with HD graphics and a clear user interface for every device. The studio is also known for its brand exclusives created in partnerships with leading operators in the industry.

The post BGaming donates to Brazilian art institute in support of creative children’s projects appeared first on European Gaming Industry News.

Advertisement
Continue Reading

eSports

Revolut unveiled as presenting partner for the BLAST Premier Spring Final at London’s OVO Arena Wembley

Published

on

revolut-unveiled-as-presenting-partner-for-the-blast-premier-spring-final-at-london’s-ovo-arena-wembley
Reading Time: 2 minutes

 

Esport entertainment company BLAST has revealed the global financial technology company Revolut as presenting partner for the BLAST Premier Spring Final, ahead of Counter-Strike’s long-awaited return to the United Kingdom in the summer.

The partnership with BLAST is Revolut’s first foray into esports – an industry known for its next-level global entertainment and world-class experiences. It is part of the fintech’s strategy to provide unique experiences to a global audience of tech-savvy gamers.

With more than 40 million customers worldwide in 38 countries, Revolut’s popular online banking platform aims to revolutionise the way people spend, send, save and interact with money.

Advertisement

Revolut comes on board as the Official Finance and Payments Partner of the BLAST Premier Spring Final, which is due to take place at London’s OVO Arena Wembley from 12-16 June. Revolut will feature heavily across the event, with both digital broadcast integration across BLAST.tv, Twitch and YouTube, with dedicated Revolut broadcast segments and physical branding and activations at the arena.

The Spring Final 2024 will be the biggest Counter-Strike event to take place in the United Kingdom since the London Major 2018, which took place in the OVO Arena Wembley and saw Danish organisation Astralis crowned champions.

Fans online will enjoy an economy focussed broadcast segment as well as a bespoke giveaway with fantastic prizes. Revolut will be kicking off the Spring Final action with an opening party on Friday, 14th June. A Revolut booth on-site will allow fans to sign up to exclusive discounts for Revolut customers and exclusive perks including queue skip for meet and greets with professional esports players.

Alexander Lewin, SVP, Commercial Revenue at BLAST said: “We’re thrilled to mark the historic return of CS arena events to the UK with a groundbreaking presenting partnership. Revolut has been at the forefront of digital banking and financial innovation for nearly a decade, and shares BLAST’s dedication to creating fantastic experiences for fans and customers. As presenting partner, Revolut will feature prominently across our entire broadcast and arena experience, and we look forward to incorporating their innovative digital-first approach. This partnership is testament to the value esports can bring to a leading global brand, and we are delighted Revolut has chosen BLAST for their first entry into competitive gaming.”

Deborah Wajsbrot, Head of Growth – Strategic Partnerships & Sponsorships at Revolut, said: “We’re delighted to be able to unveil Revolut’s marketing partnership with BLAST – our first in esports. BLAST is a world-class esports tournament and an iconic event for the gaming community. Just like Revolut, the gaming industry is at the forefront of innovation worldwide. This partnership is the beginning of our efforts to bring unique and unforgettable experiences to Revolut customers and gaming fans – not just at Wembley, but worldwide.”

Advertisement

The BLAST Premier Spring Final gets underway on Wednesday, 12th June, with eight of Counter-Strike’s best teams descending on the UK’s capital to battle for a total prize pool of $425,000. The winning team will qualify for the BLAST Premier World Final later this year.

Participating teams: Astralis, FaZe Clan, G2 Esports, Natus Vincere, SAW, Virtus.pro, Team Spirit and Team Vitality.

The post Revolut unveiled as presenting partner for the BLAST Premier Spring Final at London’s OVO Arena Wembley appeared first on European Gaming Industry News.

Continue Reading

Latest News

Golden Whale forms strategic sales partnership with SCCG management

Published

on

golden-whale-forms-strategic-sales-partnership-with-sccg-management
Reading Time: 2 minutes

 

Golden Whale Productions, the pioneering data science company that specialises in AI and machine learning-powered solutions for the iGaming industry, has announced that it has formed a new strategic partnership with advisory firm, SCCG Management.

While the industry expertise brought by the firm will undoubtedly bring myriad benefits to Golden Whale’s operations, the major goal of the collaboration will be to promote awareness of the company’s products and services across the Americas and beyond over the coming months.

Founded by Stephen A. Crystal – a seasoned veteran in the global gaming industry with over 30 years of experience under his belt – SCCG Management has an established track record of delivering expert solutions for strategic success in areas such as iGaming and casino technology.

Advertisement

With a global network of clients and offices in Europe, Africa, Asia, South America and Latin America, SCCG is well-known for connecting companies with the right strategic partners for global-scale growth, which is exactly what Golden Whale is looking for as it enters its next phase.

Having already made a major impression across Europe – where its innovative data-driven solutions and pioneering products for the Gaming industry such as Foundation – scalable optimization modules for high-leverage decision making or the iterative machine learning system, LOOPs, have already been short-listed for a number of industry awards – Golden Whale its understandably keen to expand its outreach and the new partnership will give it the foothold to do precisely that.

As such, both parties are looking forward to the collaboration and the business opportunities SCCG will create for Golden Whale in the near future, with the former’s industry know-how and far-reaching network combining with the latter’s trailblazing technology to hopefully great effect.

Eberhard Dürrschmid, Chief Executive Officer at Golden Whale, said: “While Golden Whale has enjoyed an incredible year of growth during which the company quadrupled its revenue without the help of an external investor, our partnership with SCCG is definitely the next big step.

“By teaming up with an industry expert like Stephen, we’ll be able to broaden our horizons, expand our reach and really start pushing our game-changing products across the Americas and beyond. We’re really looking forward to collaboration and are hugely optimistic about the business opportunities it’ll bring as Golden Whale enters the next exciting stage of its evolution.”

Advertisement

Stephen Crystal, Founder and CEO of SCCG Management, expressed his enthusiasm for the partnership: “Golden Whale Productions brings a wealth of expertise and a proven track record in data science to the gaming industry. By combining their state-of-the-art technology with our global reach and extensive industry relationships, we are well-positioned to deliver unparalleled value to gaming operators worldwide. This partnership will empower companies to maximize their data potential and achieve new levels of success.”

The post Golden Whale forms strategic sales partnership with SCCG management appeared first on European Gaming Industry News.

Continue Reading

Trending