Latest News
Popular Gambling App Exposed Millions of Users in Massive Data Leak
Led by Noam Rotem and Ran Locar, vpnMentor’s research team discovered a data breach on casino gambling app Clubillion.
The breach originated in a technical database built on an Elasticsearch engine and was recording the daily activities of millions of Clubillion players around the world.
Aside from leaking activity on the app, the breached database also exposed private user information.
With this information publicly available, Clubillion’s users were vulnerable to fraud and various online attacks with potentially devastating results.
Company Profile
Clubillion is a free online casino game available for iOS and Android, offering players 30+ free slot games. While each app is listed under a different developer – Ouroboros on iOS and T7 Games on Android – these are most likely owned by the same company.
Both versions of Clubillion were released in 2019 and became instant hits. Each is now ranked the #1 ‘social slots’ casino app on Google Play and the App Store, with a 4.8 star on both.
Timeline of Discovery and Owner Reaction
Sometimes, the extent of a data breach and the owner of the database are obvious, and the issue quickly resolved. But rare are these times. Most often, we need days of investigation before we understand what’s at stake or who’s leaking the data.
Understanding a breach and its potential impact takes careful attention and time. We work hard to publish accurate and trustworthy reports, ensuring everybody who reads them understands their seriousness.
Some affected parties deny the facts, disregarding our research, or playing down its impact. So, we need to be thorough and make sure everything we find is correct and accurate.
In this case, the database was built on Elasticsearch and hosted on Amazon Web Services (AWS), with Clubillion’s name on its apps, and links to assets owned by the company.
Once Clubillion was confirmed as the owner of the database, we reached out to the developers. While awaiting a reply, we also contacted AWS with details of the leak. It was closed a few days later.
- Date discovered: 19th March 2020
- Date vendors contacted: 23rd March 2020
- Date of contact with AWS: 31st March 2020
- Date of Action: Approx. 5th April 2020
Example of Entries in the Database
Clubillion’s exposed database contained technical logs for millions of Clubillion users around the world, on both iOS and Android devices. Every time an individual player took any action on the app, a record was logged. Examples of records include:
- “enter game”
- “win”
- “lose”
- “update account”
- “create account”
During our investigation of the database, new entries continued to appear continuously. We estimated an average of approximately 200 million records per day – and sometimes, considerably more.
In total, this amounted to over 50GB of exposed records in the database every single day.
Within many of these records, were various forms of user Personally Identifiable Information (PII) data, including:
- IP addresses
- Email addresses
- Winnings
- Private messages
This data breach was truly global, with millions of records originating from Clubillion’s daily users all over the world. The following list is just a sample of countries affected, along with the average number of daily users from each country:
- USA – 10,000+
- UK – 2,475+
- France – 1,650+
- Israel – 408+
- Germany – 1,582+
- Spain – 1,026+
- Italy – 2,407+
- Netherlands – 622+
- Australia – 6,251+
- Canada – 7,792+
- Brazil – 3,859+
- Sweden – 191+
- Russia – 547+
Other countries affected included Uzbekistan, India, Poland, Romania, Vietnam, Lebanon, Indonesia, Philippines, Pakistan, Thailand, Austria, Hungry, and Latvia.
As you can see, on a single day, 10,000s of individual Clubillion players were exposed. Each one of these players could be targeted by malicious hackers for fraud and cyberattacks – along with millions more whose records were also contained in the database.
Data Breach Impact
Studies have shown that free gambling and gaming apps are especially prone to attacks and hacking from cybercriminals. They are routinely targeted for theft of private data and embedding malicious software on users’ devices.
Despite their popularity, gambling and casino apps often lack transparency, and it can be impossible to know what steps they’re taking to prevent cybercriminals successfully targeting their users.
One study of 23,000 free gambling apps found that: 3,200 posed a ‘moderate risk’ to users; 379 had known security vulnerabilities; 52 contained malicious software.
Any of these issues could be exploited to target app users in a wide range of frauds and cyberattacks, and Clubillion is no different.
With the exposed user PII and knowledge of their activity on the app, hackers could create elaborate schemes to defraud users. For example, some entries also included transaction errors for attempted card payments on Clubillion.
With the information in these transaction errors, hackers could target users with phishing campaigns, with the following aims:
- Trick them into providing their credit card details
- Trick them into providing additional PII to be used against them in further fraud
- Clicking a link that embeds malware, spyware, or ransomware onto their device.
If cybercriminals used Clubillion to embed malware or similar onto a user’s phone, they could potentially hack other apps, access files stored on the device, make calls, and send texts from the hacked device. They could even access a user’s phone contacts and steal the PII data of their friends and family.
Worse still, as people across the globe now find themselves under quarantine or self-isolation, as a result of the Coronavirus pandemic, the impact of a leak like this is potentially even more significant.
Clubillion stands to gain many new users, along with regular users playing more frequently. Hackers will be aware of this and looking for opportunities to exploit any vulnerabilities in the data security of such a massively popular app.
Had criminal hackers discovered Clubillion’s database, they could have targeted millions of people around the world, with devastating results.
Impact on Clubillion and it’s Developers
The most immediate risk for Clubillion is the loss of players. Data security is a growing concern for everyone these days, and this leak could turn many players off the app. Clubillion is not unique, and players have plenty of other choices for free gambling apps.
With fewer players, Clubillion will lose advertising revenue and reduced profits.
As many of Clubillion’s players reside within the EU, the app is under the jurisdiction of GDPR. The rules of GDPR also apply to apps, and Clubillion will need to take specific actions to ensure the regulatory body in charge doesn’t reprimand it.
Finally, Clubillion could also potentially be removed from Google Play and the App Store. Both Apple and Google are clamping down on apps that pose a risk to their users, removing apps embedded with malware, and taking data leaks much more seriously.
Each of these outcomes has a different likelihood of happening, but they would all negatively impact Clubillion’s revenue and business.
Advice from the Experts
Clubillion’s developers could have easily avoided this leak if they had taken some basic security measures to protect the database. These include, but are not limited to:
- Securing their servers.
- Implementing proper access rules.
- Never leaving a system that doesn’t require authentication open to the internet.
Any company can replicate the same steps, no matter its size.
For a more in-depth guide on how to protect your business, check out our guide to securing your website and online database from hackers.
For Clubillion Users
If you play on Clubillion and are concerned about how this breach might impact you, contact the app’s developers directly to find out what steps it’s taking to protect your data.
To learn about data vulnerabilities in general, read our complete guide to online privacy.
It shows you the many ways cybercriminals target internet users, and the steps you can take to stay safe.
How and Why We Discovered the Breach
The vpnMentor research team discovered the breach in Clubillion’s database as part of a huge web mapping project. Our researchers use port scanning to examine particular IP blocks and test different systems for weaknesses or vulnerabilities. They examine each weakness for any data being leaked.
Our team was able to access this database because it was completely unsecured and unencrypted.
Whenever we find a data breach, we use expert techniques to verify the owner of the database, usually a commercial company.
As ethical hackers, we’re obliged to inform a company when we discover flaws in their online security. We reached out to Clubillion’s developers, not only to let them know about the vulnerability but also to suggest ways in which they could make their system secure.
These ethics also mean we carry a responsibility to the public. Clubillion users must be aware of a data breach that exposes so much of their sensitive data.
The purpose of this web mapping project is to help make the internet safer for all users.
Dario Leiman Head of Business Development in Latin America at SOFTSWISS
SOFTSWISS Promotes Dario Leiman to Head of Business Development in Latin America

SOFTSWISS, a leading global provider of iGaming software, announces the promotion of Dario Leiman from Regional Business Development Manager to Head of Business Development in Latin America.
SOFTSWISS has been actively focusing on building a solid foundation in Latin America since early 2024. As Regional Business Development Manager, Dario successfully established key partnerships that helped the company become a prominent player in the region. His efforts secured certifications for the SOFTSWISS Jackpot Aggregator in Brazil and the Game Aggregator in both Brazil and Peru. These milestones underscore the company’s commitment to meeting local regulatory requirements.
Rubens Barrichello, Non-Executive Director in Latin America at SOFTSWISS, comments: “SOFTSWISS has assembled one of the strongest teams of professionals for such a crucial market as Latin America. Dario’s promotion ensures we have the right expertise to guide our expansion here. I’m looking forward to seeing how the region will continue to grow under his leadership.”
In his new role as Head of Business Development in Latin America, Dario will oversee the development of business strategies to enhance SOFTSWISS’ market position in the region. This includes building new and nurturing existing partnerships and implementing the latest tech innovations that meet operators’ and players’ needs.
Dario Leiman, Head of Business Development in Latin America at SOFTSWISS, shares: “I am truly honoured to take on this role. Our recent certifications in Brazil and Peru have opened up incredible prospects for local and international operators. I’ll do my best to ensure that SOFTSWISS continues to deliver best-in-class solutions tailored to the unique gaming landscape of Latin America.”
About SOFTSWISS
SOFTSWISS is an international technology company with over 15 years of experience developing innovative solutions for the iGaming industry. SOFTSWISS holds a number of gaming licences and provides comprehensive software for managing iGaming projects. The company’s product portfolio includes the Online Casino Platform, the Game Aggregator with over 27,800 casino games, the Affilka Affiliate Platform, the Sportsbook Software and the Jackpot Aggregator. In 2013, SOFTSWISS revolutionised the industry by introducing the world’s first Bitcoin-optimised online casino solution. The expert team, based in Malta, Poland, and Georgia, counts over 2,000 employees.
The post SOFTSWISS Promotes Dario Leiman to Head of Business Development in Latin America appeared first on Gaming and Gambling Industry in the Americas.
Latest News
Altenar offers sportsbook advice with ‘Behind The Bet’ webinars

Altenar is launching a series of free online webinars with helpful tips and advice for operators to gain a better understanding of how to maximise the potential of their sportsbook.
In the webinars titled ‘Behind The Bet’, experts from across Altenar’s departments will present their thoughts on a range of topics aimed at educating the audience and helping them optimise their sportsbook offering.
As a leading sportsbook provider in regulated markets around the world, Altenar’s products are tailored to the demands of various regions and are developed based on the localised expertise of the team.
Account managers already play an important role in the business development of existing clients but ‘Behind The Bet’ will allow both current and potential customers to improve their understanding of various markets, regulations and sportsbook products.
The webinars will be held in English, Spanish and Portuguese to cater to the needs of a global audience, with the presentations followed by a question-and-answer session.
The first edition of Behind The Bet will focus on one of the hottest topics in the iGaming industry as Altenar’s Head of Licensing and Regulatory Compliance Magno Neiva and Sales Manager Frederico Caputi discuss the legal landscape in Brazil.
Charlie Williams, Commercial Director at Altenar, said: “The newly regulated market has opened up exciting opportunities for iGaming companies, but there are also many regulatory challenges to overcome in order to maximize market potential. Altenar’s success in highly regulated markets across the globe, and in South America, positions us to deliver a flexible range of products and services to help our clients grow in Brazil.”
Magno Neiva, Head of Licensing and Regulatory Compliance, said: “The Brazilian iGaming market is evolving rapidly, presenting exciting opportunities for operators and providers alike. As one of the most dynamic and promising regions in the industry, Brazil is at the centre of innovation and the new regulatory advancements are shaping the future of online betting and gaming in South America.
“Altenar is proud to be part of this journey, bringing its expertise and cutting-edge solutions to a market that is poised for significant growth.”
This webinar, the first in a series, could not have chosen a more relevant market to explore. Through this discussion, Altenar aims to showcase how its advanced sportsbook and gaming solutions can help businesses thrive in this fast-moving environment.
The first edition of Behind The Bet will be held in Portuguese and takes place on March 12 at 11am (Brazilian Standard Time).
The post Altenar offers sportsbook advice with ‘Behind The Bet’ webinars appeared first on European Gaming Industry News.
Brazil
Delasport’s Full Platform Now Certified in Brazil

After becoming one of the first B2B suppliers to get their sportsbook solution successfully GLI-certified for Brazil, Delasport has now achieved compliance with the requirements of SIGAP regarding its iGaming platform.
Obtaining the required GLI certifications and the integration with the Brazilian DataVault through SIGAP’s official API means that the solution is fully ready to dive headfirst into the market.
The certifications granted by Gaming Labs International to Delasport include the required set of approvals: the technical certificates for Betting System, Sports Betting Server (Sportsbook), a.k.a. Remote Game Server (RGS), and more.
Delasport also covers the geofencing requirements and the requirements for safer gambling monitoring and AML transaction monitoring.
Part of the implementations include an intricate system with multi-factor authentication and a modern KYC provider, meeting all requirements of the market.
Just days ago, Delasport announced its first Brazilian deal with Latam-based B2B platform provider Vibra Solutions. This is all part of the company’s global expansion strategy where Brazil and LatAm in general is a key region to get established in.
“Successfully completing this second phase of GLI certification for Brazil reinforces the trust that players and operators place in Delasport’s products”, says Filippo Ferri, Delasport’s Chief Compliance Officer. “This certification highlights our ability to uphold the highest industry standards of integrity and fairness”, he concludes.
The post Delasport’s Full Platform Now Certified in Brazil appeared first on Gaming and Gambling Industry in the Americas.
-
gaming2 years ago
ODIN by 4Players: Immersive, state-of-the-art in-game audio launches into the next generation of gaming
-
EEG iGaming Directory8 years ago
iSoftBet continues to grow with new release Forest Mania
-
News7 years ago
Softbroke collaborates with Asia Live Tech for the expansion of the service line in the igaming market
-
News6 years ago
Super Bowl LIII: NFL Fans Can Bet on the #1 Sportsbook Review Site Betting-Super-Bowl.com, Providing Free Unbiased and Trusted News, Picks and Predictions
-
iGaming Industry7 years ago
Rick Meitzler appointed to the Indian Gaming Magazine Advisory Board for 2018
-
News6 years ago
REVEALED: Top eSports players set to earn $3.2 million in 2019
-
iGaming Industry7 years ago
French Senator raises Loot Boxes to France’s Gambling Regulator
-
News7 years ago
Exclusive Interview with Miklos Handa (Founder of the email marketing solutions, “MailMike.net”), speaker at Vienna International Gaming Expo 2018