Connect with us
Prague Gaming & TECH Summit 2025 (25-26 March)

Industry News

MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability

Published

on

Reading Time: 3 minutes

Attackers could exploit the SQL Injection flaw to compromise the game’s database and steal user data.

The CyberNews.com Investigation team discovered a critical vulnerability in Street Mobster, a browser-based massively multiplayer online game created by Bulgarian development company BigMage Studios.

Street Mobster is a free to play, browser-based online game in the mafia empire genre where players manage a fictional criminal enterprise. The game boasts a 1.9+ million player base and stores a user record database that can be accessed by threat actors by committing an SQL Injection (SQLi) attack on the game’s website.

Other games created by BigMage Studios are also potentially vulnerable to the same type of attack, which means that there is a possibility that even more users might be at risk.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

The records that can be compromised by exploiting the SQLi vulnerability in Street Mobster potentially include the players’ usernames, email addresses, and passwords, as well as other game-related data that is stored on the database.

Fortunately, after we reported the vulnerability to BigMage Studios, CERT Bulgaria, and the Bulgarian data protection authority, the issue has been fixed by the developers and the user database is no longer accessible to potential attackers.

What is SQL Injection?

First found back in 1998, SQLi is deemed by the Open Web Application Security Project (OWASP) as the number one web application security risk.

Even though this vulnerability is relatively easy to fix, researchers found that 8% of websites and web applications are still vulnerable to SQLi attacks in 2020. Which, from a security perspective, is inexcusable. So much so, in fact, that UK internet service provider TalkTalk was hit with a record £400,000 fine over succumbing to a cyberattack that involved SQLi.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

The vulnerability works by injecting an unexpected payload (a piece of code) into the input box on the website or in its URL address. Instead of reading the text as part of the URL, the website’s server reads the attacker’s payload as code and then proceeds to execute the attacker’s command or output data that would otherwise be inaccessible to unauthorized parties. Attackers can exploit SQLi even further by uploading pieces of code or even malware to the vulnerable server.

The fact that Street Mobster is susceptible to SQLi attacks clearly shows the disappointing and dangerous neglect of basic security practices on the part of the developers at BigMage Studios.

 

How we found this vulnerability

Our security team identified an SQL Injection vulnerability on the Street Mobster website and were able to confirm the vulnerability by performing a simple command injection test on the website URL. The CyberNews team did not extract any data from the vulnerable Street Mobster database.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

What’s the impact of the vulnerability?

The data in the vulnerable Street Mobster database can be used in a variety of ways against the players whose information was exposed:

By injecting malicious payloads on Street Mobster’s server, attackers can potentially gain access to said server, where they can install malware on the game’s website and cause harm to the visitors – from using the players’ devices to mine cryptocurrency to redirecting them to other malicious websites, installing malware, and more.

The 1.9 million user credentials stored on the database can net the attackers user email addresses and passwords, which they can potentially use for credential stuffing attacks to hack the players’ accounts on other gaming platforms like Steam or other online services.

Because Street Mobster is a free-to-play game that incorporates microtransactions, bad actors could also make a lot of money from selling hacked player accounts on gray market websites.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

What to do if you’ve been affected?

If you have a Street Mobster account, make sure to change your password immediately and make it as complex as possible. If you’ve been using your Street Mobster password on any other websites or services, change that password as well. This will prevent potential attackers from accessing your accounts on these websites in case they try to reuse your password for credential stuffing attacks.

However, it’s ultimately up to BigMage Studios to completely secure your Street Mobster account against attacks like SQLi.

Disclosure and lack of communication from BigMage Studios

Following our vulnerability disclosure guidelines, we notified the BigMage Studios about the leak on August 31, 2020. However, we received no reply. Our follow-up emails were left unanswered as well.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

We then reached out to CERT Bulgaria on September 11 in order to help secure the website. CERT contacted the BigMage Studios and informed the company about the misconfiguration.

Throughout the disclosure process, BigMage Studios stayed radio silent and refused to get in touch with CyberNews.com. Due to this reason, we also notified the Bulgarian data protection agency about the incident on October 9 in the hopes that the agency would be able to pressure the company into fixing the issue.

Eventually, however, BigMage Studios appear to have fixed the SLQi vulnerability on streetmobster.com, without informing either CyberNews.com or CERT Bulgaria about that fact.

 

Source

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)
Continue Reading
Advertisement

Industry News

CT Interactive Appoints Dimitar Raychev as Technical Support Specialist for Online Services

Published

on

ct-interactive-appoints-dimitar-raychev-as-technical-support-specialist-for-online-services
Reading Time: < 1 minute

 

CT Interactive has appointed Dimitar Raychev as Technical Support Specialist for Online Services.

Over the years, Dimitar has worked with various platforms such as AWS, Active Directory and SAP, allowing him to acquire deep knowledge and skills in managing infrastructures and automating processes. Thanks to his expertise, he has helped many organisations optimise their systems and maintain high levels of efficiency.

“We are thrilled to welcome Dimitar Raychev to the CT Interactive team, where he will take on the role of Technical Support Specialist for Online Services. Dimitar brings extensive experience in providing technical support to global clients, successfully diagnosing and resolving issues with software, hardware and network systems. His commitment to quality service and the technical skills he possesses make him a valuable asset. We look forward to leveraging his knowledge and continuing to provide our clients with impeccable service and support,” the company said.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

The post CT Interactive Appoints Dimitar Raychev as Technical Support Specialist for Online Services appeared first on European Gaming Industry News.

Continue Reading

Industry News

IGT Wins Seven Awards at the 2025 EKG Slot Awards Show

Published

on

igt-wins-seven-awards-at-the-2025-ekg-slot-awards-show
Reading Time: 2 minutes

 

International Game Technology has won seven awards at the 2025 EKG Slot Awards Show. The EKG Slot Awards Show is a performance-based, annual programme produced by Eilers & Krejcik Gaming (EKG) that recognizes excellence in slot game development in the casino gaming industry. IGT won the most awards of any gaming industry supplier, taking home trophies for seven of the program’s 25 categories.

IGT won the following categories at the 2025 EKG Slot Awards Show:

• Top Performing NEW Premium Game: Tiger and Dragon Cash on Reels

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

• Most Innovative Land-Based Game: Tiger and Dragon Cash on Reels

• Top Performing 3rd Party IP Branded Game: Whitney Houston Slots

• Top Performing Game – EMEA: Magic Treasures Dragon

• Top Performing NEW Video Poker/Keno Game: Mega Hot Poker

• Top Performing NEW Online Table Game: Blackjack Poker & Pairs Surrender

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

• Best Overall Supplier of Online Content: IGT PlayDigital

“IGT winning seven awards at the 2025 EKG Slot Awards Show is a significant achievement that speaks to our performance momentum across multiple product categories and the immense talent and dedication of IGT employees worldwide. We look forward to continuing to help our customers benefit from these strong IGT themes in 2025 and beyond via follow-up games for Tiger and Dragon, Whitney Houston Slots, Magic Treasures and Mega Hot Poker,” said Nick Khin, IGT President, Global Gaming.

“It was exciting to see IGT PlayDigital honored at the 2025 EKG Slot Awards Show in the most esteemed iGaming category, ‘Best Overall Supplier of Online Content,’ and recognized with the ‘Top Performing NEW Online Table Game’ award for Blackjack Poker & Pairs Surrender. Developing and delivering market-leading content and performance tools is a cornerstone of IGT PlayDigital’s strategy and I wish to congratulate the entire team on these remarkable accomplishments,” said Gil Rotem, IGT PlayDigital President.

The post IGT Wins Seven Awards at the 2025 EKG Slot Awards Show appeared first on European Gaming Industry News.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)
Continue Reading

Industry News

AskGamblers Surpasses 700,000 Registered Members

Published

on

askgamblers-surpasses-700,000-registered-members
Reading Time: < 1 minute

 

AskGamblers hits a new milestone by surpassing 700,000 registered members on the website. Since 2006, AskGamblers provides accurate and reliable information on online casinos, sportsbooks, bonuses and more, with the motto Get the Truth. Then Play.

The website has grown, but not only in numbers. In 2024, AskGamblers introduced a comprehensive sports betting section where users can access sportsbook reviews, live scores, odds calculators and find exclusive deals.

Additionally, AskGamblers hosts the annual AskGamblers Awards, a prestigious event where players can nominate and vote for their favourites in four categories: Best Casino, Best New Casino, Best New Slot and Best Sportsbook, but six additional industry awards are handed out during the gala ceremony.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

Dijana Radunović, General Manager at AskGamblers, said: “Reaching the milestone of 700,000 registered players is remarkable. It’s great to see new players coming in daily, but the fact that they remain active is what’s truly special!”

The post AskGamblers Surpasses 700,000 Registered Members appeared first on European Gaming Industry News.

Continue Reading

Trending