Industry News
MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability
Attackers could exploit the SQL Injection flaw to compromise the game’s database and steal user data.
The CyberNews.com Investigation team discovered a critical vulnerability in Street Mobster, a browser-based massively multiplayer online game created by Bulgarian development company BigMage Studios.
Street Mobster is a free to play, browser-based online game in the mafia empire genre where players manage a fictional criminal enterprise. The game boasts a 1.9+ million player base and stores a user record database that can be accessed by threat actors by committing an SQL Injection (SQLi) attack on the game’s website.
Other games created by BigMage Studios are also potentially vulnerable to the same type of attack, which means that there is a possibility that even more users might be at risk.
The records that can be compromised by exploiting the SQLi vulnerability in Street Mobster potentially include the players’ usernames, email addresses, and passwords, as well as other game-related data that is stored on the database.
Fortunately, after we reported the vulnerability to BigMage Studios, CERT Bulgaria, and the Bulgarian data protection authority, the issue has been fixed by the developers and the user database is no longer accessible to potential attackers.
What is SQL Injection?
First found back in 1998, SQLi is deemed by the Open Web Application Security Project (OWASP) as the number one web application security risk.
Even though this vulnerability is relatively easy to fix, researchers found that 8% of websites and web applications are still vulnerable to SQLi attacks in 2020. Which, from a security perspective, is inexcusable. So much so, in fact, that UK internet service provider TalkTalk was hit with a record £400,000 fine over succumbing to a cyberattack that involved SQLi.
The vulnerability works by injecting an unexpected payload (a piece of code) into the input box on the website or in its URL address. Instead of reading the text as part of the URL, the website’s server reads the attacker’s payload as code and then proceeds to execute the attacker’s command or output data that would otherwise be inaccessible to unauthorized parties. Attackers can exploit SQLi even further by uploading pieces of code or even malware to the vulnerable server.
The fact that Street Mobster is susceptible to SQLi attacks clearly shows the disappointing and dangerous neglect of basic security practices on the part of the developers at BigMage Studios.
How we found this vulnerability
Our security team identified an SQL Injection vulnerability on the Street Mobster website and were able to confirm the vulnerability by performing a simple command injection test on the website URL. The CyberNews team did not extract any data from the vulnerable Street Mobster database.
What’s the impact of the vulnerability?
The data in the vulnerable Street Mobster database can be used in a variety of ways against the players whose information was exposed:
By injecting malicious payloads on Street Mobster’s server, attackers can potentially gain access to said server, where they can install malware on the game’s website and cause harm to the visitors – from using the players’ devices to mine cryptocurrency to redirecting them to other malicious websites, installing malware, and more.
The 1.9 million user credentials stored on the database can net the attackers user email addresses and passwords, which they can potentially use for credential stuffing attacks to hack the players’ accounts on other gaming platforms like Steam or other online services.
Because Street Mobster is a free-to-play game that incorporates microtransactions, bad actors could also make a lot of money from selling hacked player accounts on gray market websites.
What to do if you’ve been affected?
If you have a Street Mobster account, make sure to change your password immediately and make it as complex as possible. If you’ve been using your Street Mobster password on any other websites or services, change that password as well. This will prevent potential attackers from accessing your accounts on these websites in case they try to reuse your password for credential stuffing attacks.
However, it’s ultimately up to BigMage Studios to completely secure your Street Mobster account against attacks like SQLi.
Disclosure and lack of communication from BigMage Studios
Following our vulnerability disclosure guidelines, we notified the BigMage Studios about the leak on August 31, 2020. However, we received no reply. Our follow-up emails were left unanswered as well.
We then reached out to CERT Bulgaria on September 11 in order to help secure the website. CERT contacted the BigMage Studios and informed the company about the misconfiguration.
Throughout the disclosure process, BigMage Studios stayed radio silent and refused to get in touch with CyberNews.com. Due to this reason, we also notified the Bulgarian data protection agency about the incident on October 9 in the hopes that the agency would be able to pressure the company into fixing the issue.
Eventually, however, BigMage Studios appear to have fixed the SLQi vulnerability on streetmobster.com, without informing either CyberNews.com or CERT Bulgaria about that fact.
Affiliate Industry
Meet MegaList: The Rising Force in iGaming Affiliation

There are affiliate networks, and then there’s MegaList – a performance-first, hype-last kind of operation built for casino and sportsbook brands that prefer results over buzzwords.
In an industry that sometimes feels like it’s powered by vague metrics and recycled content, MegaList steps in as the “Mega Map” – a practical, data-driven network guiding both players and operators to higher ground. Less “look at our reach,” more “here’s your conversion rate.”
So no, this isn’t just another logo-stamped brand promising traffic and delivering bounce rates. This is a carefully engineered affiliate engine built on smart SEO, qualified leads, and just enough caffeine-fueled obsession with results to make even the most skeptical operators pay attention.
The iGaming Affiliate World: Why It (Still) Matters
Let’s be honest – the affiliate space in iGaming has had its fair share of bad actors and empty promises. But when done right, affiliate marketing is still one of the most effective and efficient ways to connect licensed operators with the right players.
Players want fewer popups, more clarity. Operators want actual ROI, not vague impressions.
Enter: the data-driven affiliate network.
It’s simple:
- Informed players make better choices.
- Strategic affiliates deliver better traffic.
- Everyone wins. Except, of course, the shady operators who preferred it the other way.
Meet the MegaList Brands
These aren’t vanity microsites. Each MegaList brand has a specific mission, actual humans behind the content, and a reputation for, well… telling it like it is.
MegaCasinoList
Let’s face it – players don’t need another affiliate promising “top 10 casinos” based on whatever ad paid the most. They need honest, transparent, expert-backed reviews.
That’s where MegaCasinoList comes in – a platform that filters out the noise and delivers legit info on licensed casinos, security, fairness, and gameplay. Slots? Live dealer games? Payout speed? Yep, it’s all in there, and it’s all vetted.
They work with reliable operators only, because – and here’s a crazy idea – not every shiny site deserves your deposit.
MegaTipsList
If you like sports predictions that read like a 20-page legal document, you’re in the wrong place.
MegaTipsList is built for bettors who want real insights, fast reads, accurate tips, and actual value. It delivers predictions, sports news, and timely promotions – minus the fluff and with none of that “win guaranteed” nonsense.
Designed for bettors who like to stay informed without needing a PhD to understand the odds.
MegaBetList
For the practical bettor who just wants the facts: which sites are legit, which ones pay fast, and what to expect before placing your first wager.
MegaBetList reviews betting platforms with a clear, no-nonsense voice. It’s not trying to dazzle; it’s trying to help people bet smarter – and it’s doing a pretty solid job of it.
From licensing to promotions to usability, everything is covered – and everything is filtered through what actually matters to sports fans.
Why This All Matters (And Why It’s Working)
The iGaming world doesn’t need more noise. It needs better filters, smarter partners, and affiliates that actually care whether the traffic leads somewhere useful.
That’s where MegaList comes in – not to impress with buzzwords, but to perform, to scale, and to make sure both operators and players are on the same page for once.
And if we may drop in a little vision while we’re at it:
“At MegaList, we believe informed players and strategic operators shape a stronger, smarter iGaming industry.”
For once, a statement that isn’t just inspirational filler.
So the next time someone pitches you an affiliate network, ask one thing: “Do they have a plan, or just a landing page?”
MegaList has both, and a track record to prove it.
Explore MegaList’s network:
🔗 MegaAffiliatesList.com
The post Meet MegaList: The Rising Force in iGaming Affiliation appeared first on European Gaming Industry News.
Gambling in the USA
Gaming Americas Weekly Roundup – June 2-8

Welcome to our weekly roundup of American gambling news again! Here, we are going through the weekly highlights of the American gambling industry which include the latest news and new partnerships. Read on and get updated.
Latest News
Merkur Gaming is going to participate in this year’s Peru Gaming Show, taking place from June 18 to 19 at the Centro de Convenciones Jockey Plaza in Lima. Representatives from the company’s German headquarters and its local subsidiary, Merkur Gaming Peru, will be on site to present the latest product innovations and engage with customers and visitors alike. The main attraction at the Merkur Gaming stand will be the linked progressive jackpot system Clash Link. This system stands out for its wealth of unique jackpot mechanics, which keep the excitement level consistently high.
PENN Entertainment has launched a new PGA TOUR-branded Blackjack game in New Jersey and Ontario. PGA TOUR Blackjack, now available via online Hollywood Casino in New Jersey and theScore Casino in Ontario, is the first iCasino game featuring PGA TOUR branding across any platform. PGA TOUR Blackjack, created by PENN’s in-house game development studio, PENN Game Studios, offers classic blackjack gameplay, plus poker and pairs side bets. The golf-themed table features official PGA TOUR logos, custom playing cards, chips and golf-themed celebrations. The new title is available on the standalone Hollywood Casino and theScore Casino platforms and is also accessible through ESPN BET in New Jersey and theScore BET in Ontario.
International Game Technology PLC announced the launch of IGT PlayDigital’s MEGA VAULT offering – a new innovation on its player engagement solution. Powered by the IGT PlayDigital Engagement Platform, a customisable suite of player engagement tools, MEGA VAULT brings together its industry-renowned engagement tools—Prize Drops, Leaderboards, Marketing Jackpots and more—into a single promotional experience. Designed to maximise excitement, engagement and rewards, MEGA VAULT aims to deliver seamless high-impact campaigns that captivate players and drive long-term retention.
Partnerships
Zitro has installed its revolutionary CONCEPT cabinets at the Casino La Cima in Mérida, Yucatán. The CONCEPT cabinets feature the Magic Lighting system, which syncs lights and sound with gameplay for a fully immersive experience, and the largest Screen Deck button panel on the market, offering unmatched comfort and ease of use for players and operators. This launch is backed by some of Zitro’s most successful titles — Fortune Legacy, Legendary Sword and King Fu Frog — all proven crowd favourites known for their engaging mechanics and strong performance.
Aristocrat Interactive, under NeoGames US, signed a six-year contract with the Michigan Lottery to provide its full solution of iLottery product offerings, reaffirming its leadership in the U.S. iLottery industry. Under the contract, from July 2026, Aristocrat Interactive will provide services to the Michigan Lottery for six years, with six additional one-year extension opportunities. The relationship with the Michigan Lottery began in 2014 with the launch of its iLottery programme using NeoGames’ iLottery platform and games. This new deal will provide the Michigan Lottery with eInstant games, draw-based games and add-on offerings produced by Aristocrat Interactive’s NeoGames Studio, along with continuing to leverage the company’s iLottery technology. Aristocrat Interactive will also provide the Michigan Lottery with a new website and mobile application services with Gambyt – a software company specialising in the lottery, casino and sports betting industries.
The post Gaming Americas Weekly Roundup – June 2-8 appeared first on European Gaming Industry News.
Industry News
EGBA Announces Dates for This Year’s European Safer Gambling Week

The European Gaming and Betting Association (EGBA) has announced that this year’s European Safer Gambling Week will take place from November 17 to 23.
European Safer Gambling Week is an annual collaborative initiative to raise awareness about safer gambling in Europe and foster a strong culture of player protection. Organised by EGBA, the initiative serves as a platform to inform citizens about safer gambling and promote information and best practice-sharing between stakeholders across Europe’s gambling sector, including operators, regulators, technology providers, support organisations and experts-by-experience.
This year will be the fifth edition of the initiative and follows the unprecedented success of 2024, which saw 195 partners participate in a social media campaign across 26 countries reaching 3.1 million social media users with important safer gambling messages. There were also 20 events held during the week that gathered 3000 attendees.
Building upon this momentum, the 2025 edition will be underpinned by a social media campaign and an array of insightful workshops. These will aim to raise awareness about safer gambling, share best practices and tips, signpost crucial resources and services, and facilitate meaningful discussions about the latest developments in regulation and research.
Maarten Haijer, Secretary General of EGBA, said: “We’re pleased to announce the dates for European Safer Gambling Week 2025 and are excited to build on the exceptional momentum of last year’s campaign. The initiative has become Europe’s leading platform for safer gambling awareness and last year brought together a record coalition of 195 partners across 26 countries to promote player protection. This is a shared commitment and we invite organisations across the industry to join us for this year’s edition and help us foster a strong culture of safe and sustainable gambling in Europe.”
The post EGBA Announces Dates for This Year’s European Safer Gambling Week appeared first on European Gaming Industry News.
-
gaming3 years ago
ODIN by 4Players: Immersive, state-of-the-art in-game audio launches into the next generation of gaming
-
EEG iGaming Directory8 years ago
iSoftBet continues to grow with new release Forest Mania
-
News7 years ago
Softbroke collaborates with Asia Live Tech for the expansion of the service line in the igaming market
-
News6 years ago
Super Bowl LIII: NFL Fans Can Bet on the #1 Sportsbook Review Site Betting-Super-Bowl.com, Providing Free Unbiased and Trusted News, Picks and Predictions
-
iGaming Industry7 years ago
Rick Meitzler appointed to the Indian Gaming Magazine Advisory Board for 2018
-
News6 years ago
REVEALED: Top eSports players set to earn $3.2 million in 2019
-
iGaming Industry8 years ago
French Senator raises Loot Boxes to France’s Gambling Regulator
-
News7 years ago
Exclusive Interview with Miklos Handa (Founder of the email marketing solutions, “MailMike.net”), speaker at Vienna International Gaming Expo 2018