Connect with us
European Gaming Congress 2024

Latest News

Popular Gambling App Exposed Millions of Users in Massive Data Leak

Published

on

Reading Time: 5 minutes

 

Led by Noam Rotem and Ran Locar, vpnMentor’s research team discovered a data breach on casino gambling app Clubillion.

The breach originated in a technical database built on an Elasticsearch engine and was recording the daily activities of millions of Clubillion players around the world.

Aside from leaking activity on the app, the breached database also exposed private user information.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

With this information publicly available, Clubillion’s users were vulnerable to fraud and various online attacks with potentially devastating results.

Company Profile

Clubillion is a free online casino game available for iOS and Android, offering players 30+ free slot games. While each app is listed under a different developer – Ouroboros on iOS and T7 Games on Android – these are most likely owned by the same company.

Both versions of Clubillion were released in 2019 and became instant hits. Each is now ranked the #1 ‘social slots’ casino app on Google Play and the App Store, with a 4.8 star on both.

Timeline of Discovery and Owner Reaction

Sometimes, the extent of a data breach and the owner of the database are obvious, and the issue quickly resolved. But rare are these times. Most often, we need days of investigation before we understand what’s at stake or who’s leaking the data.

Understanding a breach and its potential impact takes careful attention and time. We work hard to publish accurate and trustworthy reports, ensuring everybody who reads them understands their seriousness.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

Some affected parties deny the facts, disregarding our research, or playing down its impact. So, we need to be thorough and make sure everything we find is correct and accurate.

In this case, the database was built on Elasticsearch and hosted on Amazon Web Services (AWS), with Clubillion’s name on its apps, and links to assets owned by the company.

Once Clubillion was confirmed as the owner of the database, we reached out to the developers. While awaiting a reply, we also contacted AWS with details of the leak. It was closed a few days later.

  • Date discovered: 19th March 2020
  • Date vendors contacted: 23rd March 2020
  • Date of contact with AWS: 31st March 2020
  • Date of Action: Approx. 5th April 2020

Example of Entries in the Database

Clubillion’s exposed database contained technical logs for millions of Clubillion users around the world, on both iOS and Android devices. Every time an individual player took any action on the app, a record was logged. Examples of records include:

  • “enter game”
  • “win”
  • “lose”
  • “update account”
  • “create account”

During our investigation of the database, new entries continued to appear continuously. We estimated an average of approximately 200 million records per day – and sometimes, considerably more.

In total, this amounted to over 50GB of exposed records in the database every single day.

Within many of these records, were various forms of user Personally Identifiable Information (PII) data, including:

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)
  • IP addresses
  • Email addresses
  • Winnings
  • Private messages

This data breach was truly global, with millions of records originating from Clubillion’s daily users all over the world. The following list is just a sample of countries affected, along with the average number of daily users from each country:

  • USA – 10,000+
  • UK – 2,475+
  • France – 1,650+
  • Israel – 408+
  • Germany – 1,582+
  • Spain – 1,026+
  • Italy – 2,407+
  • Netherlands – 622+
  • Australia – 6,251+
  • Canada – 7,792+
  • Brazil – 3,859+
  • Sweden – 191+
  • Russia – 547+

Other countries affected included Uzbekistan, India, Poland, Romania, Vietnam, Lebanon, Indonesia, Philippines, Pakistan, Thailand, Austria, Hungry, and Latvia.

As you can see, on a single day, 10,000s of individual Clubillion players were exposed. Each one of these players could be targeted by malicious hackers for fraud and cyberattacks – along with millions more whose records were also contained in the database.

Data Breach Impact

Studies have shown that free gambling and gaming apps are especially prone to attacks and hacking from cybercriminals. They are routinely targeted for theft of private data and embedding malicious software on users’ devices.

Despite their popularity, gambling and casino apps often lack transparency, and it can be impossible to know what steps they’re taking to prevent cybercriminals successfully targeting their users.

One study of 23,000 free gambling apps found that: 3,200 posed a ‘moderate risk’ to users; 379 had known security vulnerabilities; 52 contained malicious software.

Any of these issues could be exploited to target app users in a wide range of frauds and cyberattacks, and Clubillion is no different.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

With the exposed user PII and knowledge of their activity on the app, hackers could create elaborate schemes to defraud users. For example, some entries also included transaction errors for attempted card payments on Clubillion.

With the information in these transaction errors, hackers could target users with phishing campaigns, with the following aims:

  1. Trick them into providing their credit card details
  2. Trick them into providing additional PII to be used against them in further fraud
  3. Clicking a link that embeds malware, spyware, or ransomware onto their device.

If cybercriminals used Clubillion to embed malware or similar onto a user’s phone, they could potentially hack other apps, access files stored on the device, make calls, and send texts from the hacked device. They could even access a user’s phone contacts and steal the PII data of their friends and family.

Worse still, as people across the globe now find themselves under quarantine or self-isolation, as a result of the Coronavirus pandemic, the impact of a leak like this is potentially even more significant.

Clubillion stands to gain many new users, along with regular users playing more frequently. Hackers will be aware of this and looking for opportunities to exploit any vulnerabilities in the data security of such a massively popular app.

Had criminal hackers discovered Clubillion’s database, they could have targeted millions of people around the world, with devastating results.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

Impact on Clubillion and it’s Developers

The most immediate risk for Clubillion is the loss of players. Data security is a growing concern for everyone these days, and this leak could turn many players off the app. Clubillion is not unique, and players have plenty of other choices for free gambling apps.

With fewer players, Clubillion will lose advertising revenue and reduced profits.

As many of Clubillion’s players reside within the EU, the app is under the jurisdiction of GDPR. The rules of GDPR also apply to apps, and Clubillion will need to take specific actions to ensure the regulatory body in charge doesn’t reprimand it.

Finally, Clubillion could also potentially be removed from Google Play and the App Store. Both Apple and Google are clamping down on apps that pose a risk to their users, removing apps embedded with malware, and taking data leaks much more seriously.

Each of these outcomes has a different likelihood of happening, but they would all negatively impact Clubillion’s revenue and business.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

Advice from the Experts

Clubillion’s developers could have easily avoided this leak if they had taken some basic security measures to protect the database. These include, but are not limited to:

  1. Securing their servers.
  2. Implementing proper access rules.
  3. Never leaving a system that doesn’t require authentication open to the internet.

Any company can replicate the same steps, no matter its size.

For a more in-depth guide on how to protect your business, check out our guide to securing your website and online database from hackers.

For Clubillion Users

If you play on Clubillion and are concerned about how this breach might impact you, contact the app’s developers directly to find out what steps it’s taking to protect your data.

To learn about data vulnerabilities in general, read our complete guide to online privacy.

It shows you the many ways cybercriminals target internet users, and the steps you can take to stay safe.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

How and Why We Discovered the Breach

The vpnMentor research team discovered the breach in Clubillion’s database as part of a huge web mapping project. Our researchers use port scanning to examine particular IP blocks and test different systems for weaknesses or vulnerabilities. They examine each weakness for any data being leaked.

Our team was able to access this database because it was completely unsecured and unencrypted. 

Whenever we find a data breach, we use expert techniques to verify the owner of the database, usually a commercial company.

As ethical hackers, we’re obliged to inform a company when we discover flaws in their online security. We reached out to Clubillion’s developers, not only to let them know about the vulnerability but also to suggest ways in which they could make their system secure.

These ethics also mean we carry a responsibility to the public. Clubillion users must be aware of a data breach that exposes so much of their sensitive data.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

The purpose of this web mapping project is to help make the internet safer for all users.

 

Source

Continue Reading
Advertisement

eSports

Oddin.gg Breaks New Ground as Ohio Marks its 5th North American Betting License

Published

on

oddin.gg-breaks-new-ground-as-ohio-marks-its-5th-north-american-betting-license

 

Oddin.gg is proud to announce that it has secured a full 3-year sports betting license in Ohio, further strengthening its standing as the esports betting solutions provider with the most licenses in North America. With this latest addition, Oddin.gg now holds four US licenses—New Jersey, Colorado, West Virginia, and Ohio—and a total of five across North America, including Ontario, Canada.

The Ohio license is a strategic milestone, as the state is set to become one of the most active betting markets in the American Midwest. According to projections from the Ohio Legislative Service Commission, the state’s sports gaming market is expected to reach approximately $3.35 billion annually as it matures. By securing this license, Oddin.gg is well-positioned to support operators in tapping into this significant potential.

Obtaining the Ohio license also demonstrates Oddin.gg’s ability to meet the state’s comprehensive regulatory standards, which include arduous assessments of financial stability, operational integrity, and adherence to state laws. This achievement reinforces Oddin.gg’s reputation for compliance and reliability, enhancing its capability to deliver full-service esports betting solutions tailored to a growing market.

Ohio’s sports betting legislation imposes a 10% tax on sports gaming receipts, contributing to public education and initiatives supporting veterans in the state. Oddin.gg’s entry into this regulated environment reinforces its role as a leader in shaping the future of esports betting in the US while offering operators a pathway to engage with a new generation of bettors in a secure and exciting way.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

Vlastimil Venclík, CEO of Oddin.gg, shared his enthusiasm about the news: “Securing a license from the Ohio Casino Control Commission is a significant step in our North American journey. Ohio is poised to become one of the most dynamic betting markets in the US, and gaining this
approval aer meeting the state’s rigorous standards is a true reflection of our commitment to integrity and excellence both in Ohio and beyond. However, this license isn’t just about expanding our reach; it’s about ensuring our partners have access to market-leading esports betting solutions that fully align with all local regulatory requirements.”

He continued, “Ohio’s market is gearing up to be something special, and we’re excited to help operators tap into that potential. As esports betting continues to evolve, Oddin.gg is ready to provide the expertise, technology, and support to make sure our partners succeed.

Continue Reading

Latest News

Week 40/2024 slot games releases

Published

on

week-40/2024-slot-games-releases
Reading Time: 4 minutes

 

Here are this weeks latest slots releases compiled by European Gaming

Amusnet has released 40 Bulky Dice – a classic video slot full of lucky dice symbols with a modern twist, which tempts with lots of entertainment and fantastic prizes. This 5-reel, 40 fixed paylines slot game offers vivid gameplay, epic sound effects and an easy-to-use interface. Watch out for the colourful Joker, which is the Wild symbol and appears on the second, third and fourth reels.

 

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

BGaming has teamed up with famous rapper and record producer Snoop Dogg to create an iconic new slot, Snoop Dogg Dollars. The themed game is BGaming’s first branded content in collaboration with a celebrity and was exclusively launched with Roobet on 25th September, before going live across the wider network on 30th October.

BGaming releases first-ever celebrity-branded slot Snoop Doggy Dollars

 

Relax Gaming has delivered a knockout blow with its latest release, Feather Fury. Fists are flying in this 3×2 boxing-themed slot, where players can win up to 5,000x their stake thanks to a truly unique mechanic that awards respins following dead spins. Every dead spin that is registered automatically adds a notch to the bar, with 10 dead spins being enough to trigger Feather Fury’s respin feature.

Get set to ruffle feathers in Relax Gaming release Feather Fury

 

Reel Rabbit” from Hölle Games is already live, a new entry in the Reel franchise. This 5×3, 25 payline slot continues in the footsteps of furry friends Fox, Tiger and Wolf, and while it might be the most mild-mannered mammal of the bunch, Reel Rabbit still packs a hefty punch!

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

 

Step into the vibrant world of Muertos Fortuna, an exciting slot game from Zillion Games, featuring 3D animation and engaging features. Muertos Fortuna, inspired by Día de los Muertos and Halloween, brings vibrant animations and the unique presence of Catrina Muerte, who may appear during gameplay to interact and cheer you on with fun phrases, adding an engaging element to the experience.

Zillion Games launches new slot game Muertos Fortuna

 

Play’n GO invites players to revisit the mystical world of the beyond in Lady of Fortune Remastered, where the future holds untold riches and mysterious revelations. Venture where the veil between our world and the unknown is thin, and fortunes await those who dare to look. This 5×3 video slot revisits the popular title, Lady of Fortune, now with enhanced visuals and enriched gameplay.

Discover Your Fate with Lady of Fortune Remastered

 

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

 

Belatra Games has released its latest hot shot, Lucky Bandits. This exhilarating escapade launches players into the lawless lands of the Wild West that are brought to life with stunning visuals, immersive soundscapes, and thrilling gameplay. The game is bursting with engaging features such as Free Games, Hot Mode, and the intense Shot and Dynamite Bonuses.

Belatra releases explosive Lucky Bandits slot

Intrepid players are being given the chance to venture back in time to a land ruled by the great Pharaohs where they can uncover relics, treasures and big wins in Gold of Egypt, the latest slot from Silverback Gaming. In Gold of Egypt, players find themselves in a hot and arid desert at the entrance to a secret tomb. As the reels spin, ancient symbols land on the reels including a Cat, Snake, Scorpion and Scarab, as well as different hieroglyphics.

Discover relics and big wins in Gold of Egypt from Silverback Gaming

 

They say Rome wasn’t built in a day, but in Swintt’s all-new slot sensation, Hidden Treasures of Rome, players’ fortunes can certainly be built up in seconds thanks to the presence of Free Spins, a rewarding tumble feature and random multipliers that offer a maximum payout of up to 5,000x the stated win.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

 

On October 2nd Endorphina, released its newest slot game, Panda Strike, now available for play in most online casinos. Panda Strike is a 5-reel, 4-row oriental slot with 40 fixed paylines. Set in a small Chinese town, the slot encourages players to master concentration and self-discipline, leading them to face the legendary panda, a master of the martial arts.

Panda Strike: A New Oriental Game from Endorphina

 

Amusnet has released its new online slot game, 10 Vampire Bites. The game has 11 symbols scattered across 5 reels and 10 paylines. The video slot game also showcases a hauntingly beautiful gothic design that immerses players in a world of mystery, while the atmospheric soundtrack further enhances the eerie experience, drawing players deeper into the chilling narrative.

 

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

 

The post Week 40/2024 slot games releases appeared first on European Gaming Industry News.

Continue Reading

Conferences

EGT Digital to make a long-lasting impression at G2E Las Vegas 2024

Published

on

egt-digital-to-make-a-long-lasting-impression-at-g2e-las-vegas-2024

 

EGT Digital will present its impressive iGaming portfolio at this year’s G2E Las Vegas show. Along with Euro Games Technology, the company will demonstrate its latest developments and top-performing products on booths 2452 and 3352.

Visitors will be able to get acquainted with the 4 jackpot bestsellers Bell Link, High Cash, Clover Chance and Single Progressive Jackpot, including more than 100 titles on different themes. Among them the latest slot in EGT Digital’s portfolio Senor Muerto will stand out. Inspired by Dia de los Muertos, the latest addition to Clover Chance will take players to a world of mystery and vibrant festivities, where the Toppling reels with Multiplier feature will add even more thrill to the game.

EGT Digital’s in-house developed “all-in-one” betting platform X-Nave will be on display as well to demonstrate how it could help operators to build and maintain a successful business online. Its 4 main modules: CRM Engine, Sport Product, Gaming Aggregator, and Payment Gateway, can be part of the complete solution or function independently, as they allow integration with solutions of third-party developers.

X-Nave’s CRM Engine will show numerous new competition opportunities, including different games and tournaments, which will enrich even further the betting sites’ capabilities to offer more attractive gaming options to its customers. The operators also will be able to make more detailed player segmentation and will have at their disposal an AI/ML chatbot and a new AI/ML module, which will make selection of casino games based on visitors’ behavior.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

The main highlight in EGT Digital’s Sport Product for the show will be the new Customizable tournament page, which aims to enhance user engagement and simplify navigation. Thanks to it players will be able to access relevant information and place bets very easily. The page is divided into different tabs: Lobby, Matches, Boosted, Outrights, Bet Feed, Teams, Groups, Brackets, Promotions, and Quiz. This way players will enjoy more personalized and engaging betting experience.

The Gaming Aggregator will show its extensive portfolio, currently consisting of more than 12,000 titles, including slots, live games, table games, bingo, lottery, Poker, TV games, and skill-based games from over 110 popular providers. Operators will be able to learn more about the newly-added leaderboard widget as well.

X-Nave’s Payment Gateway will present its wide range of payment methods, which includes Open Banking. The guests will also have the chance to become familiar with the Quick Deposit feature – a small Cashier that can be opened directly from the casino games, i.e. the players don’t have to leave the game in order to take advantage of it.

Tsvetomira Drumeva, Head of Sales at EGT Digital, commented: “We are excited to participate in G2E Las Vegas for another year in a row. We have prepared properly for the event and will welcome our guests with an attractive selection of products that I am confident will arouse great interest among them. We are looking forward to meet our current and potential new clients on October 8-10.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)
Continue Reading

Trending