Industry News
MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability
Attackers could exploit the SQL Injection flaw to compromise the game’s database and steal user data.
The CyberNews.com Investigation team discovered a critical vulnerability in Street Mobster, a browser-based massively multiplayer online game created by Bulgarian development company BigMage Studios.
Street Mobster is a free to play, browser-based online game in the mafia empire genre where players manage a fictional criminal enterprise. The game boasts a 1.9+ million player base and stores a user record database that can be accessed by threat actors by committing an SQL Injection (SQLi) attack on the game’s website.
Other games created by BigMage Studios are also potentially vulnerable to the same type of attack, which means that there is a possibility that even more users might be at risk.
The records that can be compromised by exploiting the SQLi vulnerability in Street Mobster potentially include the players’ usernames, email addresses, and passwords, as well as other game-related data that is stored on the database.
Fortunately, after we reported the vulnerability to BigMage Studios, CERT Bulgaria, and the Bulgarian data protection authority, the issue has been fixed by the developers and the user database is no longer accessible to potential attackers.
What is SQL Injection?
First found back in 1998, SQLi is deemed by the Open Web Application Security Project (OWASP) as the number one web application security risk.
Even though this vulnerability is relatively easy to fix, researchers found that 8% of websites and web applications are still vulnerable to SQLi attacks in 2020. Which, from a security perspective, is inexcusable. So much so, in fact, that UK internet service provider TalkTalk was hit with a record £400,000 fine over succumbing to a cyberattack that involved SQLi.
The vulnerability works by injecting an unexpected payload (a piece of code) into the input box on the website or in its URL address. Instead of reading the text as part of the URL, the website’s server reads the attacker’s payload as code and then proceeds to execute the attacker’s command or output data that would otherwise be inaccessible to unauthorized parties. Attackers can exploit SQLi even further by uploading pieces of code or even malware to the vulnerable server.
The fact that Street Mobster is susceptible to SQLi attacks clearly shows the disappointing and dangerous neglect of basic security practices on the part of the developers at BigMage Studios.
How we found this vulnerability
Our security team identified an SQL Injection vulnerability on the Street Mobster website and were able to confirm the vulnerability by performing a simple command injection test on the website URL. The CyberNews team did not extract any data from the vulnerable Street Mobster database.
What’s the impact of the vulnerability?
The data in the vulnerable Street Mobster database can be used in a variety of ways against the players whose information was exposed:
By injecting malicious payloads on Street Mobster’s server, attackers can potentially gain access to said server, where they can install malware on the game’s website and cause harm to the visitors – from using the players’ devices to mine cryptocurrency to redirecting them to other malicious websites, installing malware, and more.
The 1.9 million user credentials stored on the database can net the attackers user email addresses and passwords, which they can potentially use for credential stuffing attacks to hack the players’ accounts on other gaming platforms like Steam or other online services.
Because Street Mobster is a free-to-play game that incorporates microtransactions, bad actors could also make a lot of money from selling hacked player accounts on gray market websites.
What to do if you’ve been affected?
If you have a Street Mobster account, make sure to change your password immediately and make it as complex as possible. If you’ve been using your Street Mobster password on any other websites or services, change that password as well. This will prevent potential attackers from accessing your accounts on these websites in case they try to reuse your password for credential stuffing attacks.
However, it’s ultimately up to BigMage Studios to completely secure your Street Mobster account against attacks like SQLi.
Disclosure and lack of communication from BigMage Studios
Following our vulnerability disclosure guidelines, we notified the BigMage Studios about the leak on August 31, 2020. However, we received no reply. Our follow-up emails were left unanswered as well.
We then reached out to CERT Bulgaria on September 11 in order to help secure the website. CERT contacted the BigMage Studios and informed the company about the misconfiguration.
Throughout the disclosure process, BigMage Studios stayed radio silent and refused to get in touch with CyberNews.com. Due to this reason, we also notified the Bulgarian data protection agency about the incident on October 9 in the hopes that the agency would be able to pressure the company into fixing the issue.
Eventually, however, BigMage Studios appear to have fixed the SLQi vulnerability on streetmobster.com, without informing either CyberNews.com or CERT Bulgaria about that fact.
Industry News
TipRanks to Become Official Sponsor of 5-Time U.S. Chess Champion Hikaru Nakamura

TipRanks, a leading financial research platform with more than 9 million monthly active users, has announced a strategic sponsorship with Grandmaster Hikaru Nakamura, a 5-time US Chess Champion who is currently ranked 2nd in the world. Powered by a new set of AI tools, the partnership is designed to help investors make better, data-driven decisions through the combination of TipRanks’ cutting-edge tools and Nakamura’s strategic mindset.
As part of the partnership, Nakamura will create and manage a Stream Portfolio on TipRanks. Viewers and fans of Hikaru will be able to track his investment research in real time on his widely followed video channels and social media — plus share ideas in the stream chat to help shape the portfolio’s holdings. Working with TipRanks’ award-winning platform, Nakamura will showcase how he evaluates opportunities, while emphasizing that all content is for educational purposes only and does not constitute investment advice.
Nakamura’s dominance in chess stems from his ability to absorb vast amounts of information, analyze multiple outcomes and make decisive moves under pressure—skills that closely mirror successful investing.
“TipRanks offers a wide variety of insights on thousands of stocks and equities, helping me to think strategically about all of my investments. Just like in chess, beating the market depends on making wise, fully informed decisions. Harnessing data to think several moves ahead is second nature to me,” said Nakamura.
“While other investing websites might sponsor more popular spectator sports such as soccer, our partnership with a chess champion is pitch perfect. We are tailor-made for investors who seek to act strategically, just like Hikaru does,” said Uri Gruenbaum, Founder and CEO of TipRanks.
The post TipRanks to Become Official Sponsor of 5-Time U.S. Chess Champion Hikaru Nakamura appeared first on European Gaming Industry News.
Industry News
PENN Entertainment Celebrates Grand Opening of Hollywood Casino Joliet

PENN Entertainment has officially opened the doors of its new Hollywood Casino Joliet on Monday, August 11.
The $185 million state-of-the-art casino replaces the former riverboat property that operated on the shores of the Des Plaines River since 1992.
Legislators and area dignitaries, Illinois Gaming Board officials, Chicago Bears executives and NFL legend and Joliet native Tom Thayer joined the PENN team members for the ribbon-cutting ceremony. Hollywood Casino Joliet then opened to the public at 4:00 p.m. and welcomed guests to experience approximately 1000 of the newest slot machines, 43 table games, a retail ESPN BET sportsbook, upscale national and Chicagoland celebrity-led dining and, above all, a premier guest experience.
“We would like to officially welcome players and guests to the all-new Hollywood Casino Joliet. After approximately 20 months of construction, we are thrilled to open the doors to this land-based entertainment destination. We are proud of our 30-year history in Will County and are committed to continuing our investment in the community by creating new jobs, providing important tax revenue, and serving as a new attraction to bring even more visitors to the area,” said Jay Snowden, CEO and President of PENN Entertainment.
“This opening marks an exciting new era of entertainment in Joliet. We’re grateful for the support from the city of Joliet, the Illinois Gaming Board, and our business and community partners who contributed to the successful development of this new property. We look forward to delivering an elevated experience with world class dining, entertainment, and gaming options for patrons across the region,” said Todd George, Executive Vice President of Operations for PENN.
The roughly 189,000 square foot entertainment destination employs approximately 600 team members and generated around 450 construction jobs. Open seven days a week and 24 hours a day, the fun and excitement will continue 365 days a year.
The post PENN Entertainment Celebrates Grand Opening of Hollywood Casino Joliet appeared first on European Gaming Industry News.
Gambling in the USA
Gaming Americas Weekly Roundup – August 4-10

Welcome to our weekly roundup of American gambling news again! Here, we are going through the weekly highlights of the American gambling industry which include the latest news and new partnerships. Read on and get updated.
Latest News
SA Gaming has announced that its game portfolio and Remote Gaming Server have officially obtained Gaming Laboratories International certifications in Brazil. This milestone underscores SA Gaming’s commitment to delivering premium gaming experiences, with a particular focus on the Brazilian market. The regulated Brazilian online gaming market, which launched on January 1, 2025, is projected to become the largest in Latin America. Under the new framework, only licensed operators are legally permitted to offer online gaming and betting services.
The National Indian Gaming Commission announced Gross Gaming Revenues of $43.9B for fiscal year 2024. This historic figure reflects a $2.0 billion increase over FY 2023, representing an overall growth of 4.6% across the Indian gaming industry. The GGR figure is calculated from independently audited financial statements from 532 independently audited gaming operations owned by 243 federally recognised tribes across 29 states. Two NIGC regions, Oklahoma City and Washington, D.C., reported double-digit growth over the previous fiscal year.
The Michigan Gaming Control Board has issued cease-and-desist letters to six unlicensed online gambling platforms attempting to target Michigan residents without state authorisation. The action underscores the MGCB’s relentless, ongoing efforts to shut down illegal gambling operations and protect Michigan consumers from financial risk, identity theft and unfair play. The targeted sites—Crypto Slots, NitroBetting, NewVegas, Las Vegas USA Casino, Grand Rush Casino and Slotgard Casino—were found to be operating in violation of Michigan laws that require licensure for internet gaming and sports betting. This enforcement action is part of the MGCB’s larger crackdown on illegal online gambling platforms.
Partnerships
Table Trac Inc announced that a new Nevada casino partner is installing the CasinoTrac CMS system, and a long-time customer is upgrading from its classic system to the latest comprehensive technology stack featuring enhanced capabilities for Loyalty, Bonusing, & Operations. Barton’s Club 93 Casino Hotel, under new ownership, GLM Gaming, as part of a significant property remodel and renovation is upgrading the slot system to CasinoTrac’s high-speed, Secure, Unified and Stable PlayerLINQ network, which drives player engagement through the programmatic, custom SlotSUITE platform while turbocharging efficiency and time on device with SelfPAY. Border Inn Casino will deploy CasinoTrac’s high-speed, Secure, Unified and Stable PlayerLINQ network, NV Tech Standard 3-compliant accounting and CTLoyalty for Patron & Club Management, powered by CasinoTrac’s bonusing, auto-tiering and reflexive rewards functions.
Caesars Entertainment Inc announced it is the first in the industry to launch IGT’s newest installment of its beloved slot title, Kitty Glitter Grand. The game is now live across Caesars Palace Online Casino, Horseshoe Online Casino, and Caesars Sportsbook & Casino in New Jersey, Pennsylvania, Michigan, West Virginia, and Ontario. It’s also available at Caesars Rewards destinations in Atlantic City, including Caesars and Harrah’s, with Tropicana set to join the lineup soon, subject to final regulatory approval. This debut marks IGT’s first simultaneous exclusive launch of a game both online and in casinos in the US. As a result, Caesars is currently the only place where fans of the Kitty Glitter franchise can experience this latest installment, whether in person or online.
The post Gaming Americas Weekly Roundup – August 4-10 appeared first on European Gaming Industry News.
-
gaming3 years ago
ODIN by 4Players: Immersive, state-of-the-art in-game audio launches into the next generation of gaming
-
EEG iGaming Directory8 years ago
iSoftBet continues to grow with new release Forest Mania
-
News7 years ago
Softbroke collaborates with Asia Live Tech for the expansion of the service line in the igaming market
-
News7 years ago
Super Bowl LIII: NFL Fans Can Bet on the #1 Sportsbook Review Site Betting-Super-Bowl.com, Providing Free Unbiased and Trusted News, Picks and Predictions
-
iGaming Industry8 years ago
Rick Meitzler appointed to the Indian Gaming Magazine Advisory Board for 2018
-
News7 years ago
REVEALED: Top eSports players set to earn $3.2 million in 2019
-
iGaming Industry8 years ago
French Senator raises Loot Boxes to France’s Gambling Regulator
-
News7 years ago
Exclusive Interview with Miklos Handa (Founder of the email marketing solutions, “MailMike.net”), speaker at Vienna International Gaming Expo 2018