Latest News
Popular Gambling App Exposed Millions of Users in Massive Data Leak
Led by Noam Rotem and Ran Locar, vpnMentor’s research team discovered a data breach on casino gambling app Clubillion.
The breach originated in a technical database built on an Elasticsearch engine and was recording the daily activities of millions of Clubillion players around the world.
Aside from leaking activity on the app, the breached database also exposed private user information.
With this information publicly available, Clubillion’s users were vulnerable to fraud and various online attacks with potentially devastating results.
Company Profile
Clubillion is a free online casino game available for iOS and Android, offering players 30+ free slot games. While each app is listed under a different developer – Ouroboros on iOS and T7 Games on Android – these are most likely owned by the same company.
Both versions of Clubillion were released in 2019 and became instant hits. Each is now ranked the #1 ‘social slots’ casino app on Google Play and the App Store, with a 4.8 star on both.
Timeline of Discovery and Owner Reaction
Sometimes, the extent of a data breach and the owner of the database are obvious, and the issue quickly resolved. But rare are these times. Most often, we need days of investigation before we understand what’s at stake or who’s leaking the data.
Understanding a breach and its potential impact takes careful attention and time. We work hard to publish accurate and trustworthy reports, ensuring everybody who reads them understands their seriousness.
Some affected parties deny the facts, disregarding our research, or playing down its impact. So, we need to be thorough and make sure everything we find is correct and accurate.
In this case, the database was built on Elasticsearch and hosted on Amazon Web Services (AWS), with Clubillion’s name on its apps, and links to assets owned by the company.
Once Clubillion was confirmed as the owner of the database, we reached out to the developers. While awaiting a reply, we also contacted AWS with details of the leak. It was closed a few days later.
- Date discovered: 19th March 2020
- Date vendors contacted: 23rd March 2020
- Date of contact with AWS: 31st March 2020
- Date of Action: Approx. 5th April 2020
Example of Entries in the Database
Clubillion’s exposed database contained technical logs for millions of Clubillion users around the world, on both iOS and Android devices. Every time an individual player took any action on the app, a record was logged. Examples of records include:
- “enter game”
- “win”
- “lose”
- “update account”
- “create account”
During our investigation of the database, new entries continued to appear continuously. We estimated an average of approximately 200 million records per day – and sometimes, considerably more.
In total, this amounted to over 50GB of exposed records in the database every single day.
Within many of these records, were various forms of user Personally Identifiable Information (PII) data, including:
- IP addresses
- Email addresses
- Winnings
- Private messages
This data breach was truly global, with millions of records originating from Clubillion’s daily users all over the world. The following list is just a sample of countries affected, along with the average number of daily users from each country:
- USA – 10,000+
- UK – 2,475+
- France – 1,650+
- Israel – 408+
- Germany – 1,582+
- Spain – 1,026+
- Italy – 2,407+
- Netherlands – 622+
- Australia – 6,251+
- Canada – 7,792+
- Brazil – 3,859+
- Sweden – 191+
- Russia – 547+
Other countries affected included Uzbekistan, India, Poland, Romania, Vietnam, Lebanon, Indonesia, Philippines, Pakistan, Thailand, Austria, Hungry, and Latvia.
As you can see, on a single day, 10,000s of individual Clubillion players were exposed. Each one of these players could be targeted by malicious hackers for fraud and cyberattacks – along with millions more whose records were also contained in the database.
Data Breach Impact
Studies have shown that free gambling and gaming apps are especially prone to attacks and hacking from cybercriminals. They are routinely targeted for theft of private data and embedding malicious software on users’ devices.
Despite their popularity, gambling and casino apps often lack transparency, and it can be impossible to know what steps they’re taking to prevent cybercriminals successfully targeting their users.
One study of 23,000 free gambling apps found that: 3,200 posed a ‘moderate risk’ to users; 379 had known security vulnerabilities; 52 contained malicious software.
Any of these issues could be exploited to target app users in a wide range of frauds and cyberattacks, and Clubillion is no different.
With the exposed user PII and knowledge of their activity on the app, hackers could create elaborate schemes to defraud users. For example, some entries also included transaction errors for attempted card payments on Clubillion.
With the information in these transaction errors, hackers could target users with phishing campaigns, with the following aims:
- Trick them into providing their credit card details
- Trick them into providing additional PII to be used against them in further fraud
- Clicking a link that embeds malware, spyware, or ransomware onto their device.
If cybercriminals used Clubillion to embed malware or similar onto a user’s phone, they could potentially hack other apps, access files stored on the device, make calls, and send texts from the hacked device. They could even access a user’s phone contacts and steal the PII data of their friends and family.
Worse still, as people across the globe now find themselves under quarantine or self-isolation, as a result of the Coronavirus pandemic, the impact of a leak like this is potentially even more significant.
Clubillion stands to gain many new users, along with regular users playing more frequently. Hackers will be aware of this and looking for opportunities to exploit any vulnerabilities in the data security of such a massively popular app.
Had criminal hackers discovered Clubillion’s database, they could have targeted millions of people around the world, with devastating results.
Impact on Clubillion and it’s Developers
The most immediate risk for Clubillion is the loss of players. Data security is a growing concern for everyone these days, and this leak could turn many players off the app. Clubillion is not unique, and players have plenty of other choices for free gambling apps.
With fewer players, Clubillion will lose advertising revenue and reduced profits.
As many of Clubillion’s players reside within the EU, the app is under the jurisdiction of GDPR. The rules of GDPR also apply to apps, and Clubillion will need to take specific actions to ensure the regulatory body in charge doesn’t reprimand it.
Finally, Clubillion could also potentially be removed from Google Play and the App Store. Both Apple and Google are clamping down on apps that pose a risk to their users, removing apps embedded with malware, and taking data leaks much more seriously.
Each of these outcomes has a different likelihood of happening, but they would all negatively impact Clubillion’s revenue and business.
Advice from the Experts
Clubillion’s developers could have easily avoided this leak if they had taken some basic security measures to protect the database. These include, but are not limited to:
- Securing their servers.
- Implementing proper access rules.
- Never leaving a system that doesn’t require authentication open to the internet.
Any company can replicate the same steps, no matter its size.
For a more in-depth guide on how to protect your business, check out our guide to securing your website and online database from hackers.
For Clubillion Users
If you play on Clubillion and are concerned about how this breach might impact you, contact the app’s developers directly to find out what steps it’s taking to protect your data.
To learn about data vulnerabilities in general, read our complete guide to online privacy.
It shows you the many ways cybercriminals target internet users, and the steps you can take to stay safe.
How and Why We Discovered the Breach
The vpnMentor research team discovered the breach in Clubillion’s database as part of a huge web mapping project. Our researchers use port scanning to examine particular IP blocks and test different systems for weaknesses or vulnerabilities. They examine each weakness for any data being leaked.
Our team was able to access this database because it was completely unsecured and unencrypted.
Whenever we find a data breach, we use expert techniques to verify the owner of the database, usually a commercial company.
As ethical hackers, we’re obliged to inform a company when we discover flaws in their online security. We reached out to Clubillion’s developers, not only to let them know about the vulnerability but also to suggest ways in which they could make their system secure.
These ethics also mean we carry a responsibility to the public. Clubillion users must be aware of a data breach that exposes so much of their sensitive data.
The purpose of this web mapping project is to help make the internet safer for all users.
Aquisitions/Mergers
The Chiliz Group acquires OG Esports, reuniting with original co-founders to launch new era

-
Chiliz Group acquires 51% of OG Esports, investing to grow the team, expand operations, and strengthen fan and player engagement.
-
Xavier Oswald, a former co-founder and shareholder of OG, becomes CEO, while OG co-founders Johan “n0tail” Sundstein and Sébastien “Ceb” Debs launch a new strategic project consolidating the team’s competitive foundation.
-
Socios.com becomes the exclusive platform for $OG Fan Tokens, $OG will act as the showcase for blockchain-based utility.
The Chiliz Group, the world’s leading blockchain provider for the sports and entertainment industry and operator of Socios.com, today announced it has acquired a 51% controlling stake in OG Esports, one of the most iconic and innovative names in global esports.
Founded in 2015 by legendary Dota 2 players Johan “n0tail” Sundstein and Sébastien “Ceb” Debs, OG is the first team in history to win back-to-back titles at The International. Since then, OG has expanded into Counter-Strike, Honor of Kings and Mobile Legends: Bang Bang, building one of the most successful and culturally significant organisations in esports.
OG has a track record of delivering a fan-driven culture through innovation and launched the $OG Fan Token in 2020. The $OG Fan Token recently became the first esports Fan Token to surpass a $100 million market capitalization, driven by surging global demand for digital fan assets. Having delivered exclusive voting rights, VIP experiences, merchandise, and direct access to the team for fans worldwide, $OG represents a thriving $100m+ digital fan economy.
As part of the acquisition, Xavier Oswald will take on the role of CEO of OG, guiding the organisation into its next chapter, while co-founders Johan “n0tail” Sundstein and Sébastien “Ceb” Debs will lead a new strategic project consolidating the team’s competitive foundation, driving innovation at the intersection of esports and Web3.
At the same time, Socios.com will become the exclusive wallet and engagement platform for $OG Fan Tokens, establishing $OG as the flagship example of the new fan economy. The token will now showcase how fan assets can evolve – serving as the blockchain layer for tickets, merchandise, in-stadium perks, and digital content, while also integrating real-world assets and club revenues through mechanisms like buybacks to deliver deeper influence and tangible value to supporters.
Through The Chiliz Group’s global network of more than 80 leading sports properties, OG will now be able to expand into new countries and markets, building a larger international footprint and new commercial opportunities. Backed by the financial strength of a global group, OG will become more resilient and sustainable, ensuring long-term stability while focusing on what matters most: players, fans, and innovation.
More details about the acquisition will be released in the coming weeks.
“OG has always been about community and innovation, and since 2020 it has demonstrated that Fan Tokens can create genuine economic value and meaningful engagement,” said Alex Dreyfus, CEO and Founder of Chiliz. “With a $100 million fan token economy already established, OG represents the perfect case study for what’s truly possible when we place Fan Tokens at the centre of the fan economy. This acquisition allows us to showcase the next evolution – Fan Tokens 2.0.”
“This marks the start of a bold new era for OG,” said Xavier Oswald, incoming CEO of OG. “With Chiliz as our majority partner, we can scale our teams, grow our global community, and unlock a new dimension of engagement through the $OG Fan Token. We’ve always believed that fans should be at the centre of everything we do, and now we have the tools and the backing to make that vision a reality.”
“With Chiliz, we share a common vision based on strong values: passion, transparency, and the power of communities.” said Johan “N0tail” Sundstein, co-founder and historic figure of OG Esports. “From winning back-to-back Internationals to competing against OpenAI Five in a world-first showcase of human-AI collaboration, OG has always been about pushing boundaries. This alliance will allow us to stay true to our identity while continuing to grow.”
“This agreement marks the beginning of a new competitive cycle,’ added Sébastien “Ceb” Debs, two-time world champion with OG. “We want to once again become a major force on the international stage and inspire a new generation of players and fans. With the support of Chiliz, we now have the means to build an ambitious and sustainable project.”
The post The Chiliz Group acquires OG Esports, reuniting with original co-founders to launch new era appeared first on European Gaming Industry News.
20 Armadillos
SlotMatrix unleashes the wild riches of 20 Armadillos

SlotMatrix, the world’s largest casino content aggregator, proudly announces the launch of 20 Armadillos, a thrilling new slot adventure set deep in a jungle where fortunes roll wild.
In this untamed land, the Armadillos and their fierce animal allies guard treasures waiting to be uncovered. Players spin the reels as claws of luck and paws of fortune guide them towards potential big wins, daring them to crack the shell of jungle secrets and claim the rewards within.
20 Armadillos is a 5-reel, 4-row slot with 20 lines, medium-high volatility and RTP options of 94.16% and 96.96%. With a maximum multiplier of 30,000x and a responsive, mobile-first design, the game blends rich visuals with high win potential.
The game’s feature set is as wild as its setting. Landing Wild Symbols triggers Wild Respins, extending the action and paving the way to the Bonus Game, where Wilds transform into Armadillo Credits with random cash values.
Prizepot mechanics give players the chance to collect Mini, Minor, Major, and Mega wins, while filling the board unlocks the ultimate Grand Prizepot.
Pick Enhancement Accumulation allows players to build up powerful modifiers over time, unlocking even more rewards when Free Spins begin.
In the Pre-Free Spins Picks phase, collected enhancements such as global multipliers, payout boosts, extra credits, and sticky animals create a truly personalised bonus round.
The Free Spins bonus doubles down on excitement with Both Ways Pay and Animals Double Feature, combining sticky animals, extra spins, and double-win mechanics for massive payouts.
20 Armadillos is exclusively available through SlotMatrix. As with all SlotMatrix titles, the game is enhanced by EveryMatrix’s proprietary gamification features, including free spins and leaderboards, and can be integrated with EngageSuite, the all-in-one player loyalty solution.
Bjorn Sjoberg, COO, SlotMatrix, said: “With 20 Armadillos, we’re showcasing how layered gameplay, vibrant storytelling, and innovative mechanics can captivate players.
“From the jungle-themed prizepots to double-paying animal features, 20 Armadillos delivers an experience to remember for players worldwide.”
The post SlotMatrix unleashes the wild riches of 20 Armadillos appeared first on Gaming and Gambling Industry in the Americas.
Latest News
REEVO Announces Strategic Partnership with betFIRST

REEVO, the next-generation B2B content and aggregation provider, has announced a strategic partnership with betFIRST, Belgium’s leading retail and online sports betting operator and part of the Betsson Group. Through this collaboration, REEVO’s extensive portfolio of high-performing, engaging and innovative games will now be available to betFIRST players across Belgium.
This partnership marks another significant step in REEVO’s mission to deliver world-class iGaming content to operators and their players worldwide, strengthening its footprint in Europe and beyond.
Karl Grech, Head of Business Development at REEVO, said: “We are thrilled to partner with betFIRST, a brand synonymous with excellence and leadership in Belgium. At REEVO, our mission is to push the boundaries of iGaming innovation and deliver content that resonates with players everywhere. By joining forces with betFIRST, we’re confident that our games will not only entertain but also drive strong engagement and value for their players.”
Rhianna Binns, Games Delivery Manager at betFIRST, said: “We’re always looking to bring fresh, engaging, and innovative content to our players, and partnering with REEVO allows us to do just that. Their portfolio adds real variety and excitement to our games offering, and we’re confident it will further enhance the entertainment experience that betFIRST is known for in Belgium.”
With REEVO’s expanding library of cutting-edge in-house titles and a rapidly growing aggregation platform featuring content from top-tier third-party studios, betFIRST players will gain access to a diverse range of games designed to enhance engagement and retention.
betFIRST, renowned for its strong online presence and the largest retail network of betting shops in Belgium, will now bring REEVO’s content to its customers, enriching their entertainment experience with premium slot gameplay and innovation-driven mechanics.
The post REEVO Announces Strategic Partnership with betFIRST appeared first on European Gaming Industry News.
-
gaming3 years ago
ODIN by 4Players: Immersive, state-of-the-art in-game audio launches into the next generation of gaming
-
EEG iGaming Directory9 years ago
iSoftBet continues to grow with new release Forest Mania
-
News8 years ago
Softbroke collaborates with Asia Live Tech for the expansion of the service line in the igaming market
-
News7 years ago
Super Bowl LIII: NFL Fans Can Bet on the #1 Sportsbook Review Site Betting-Super-Bowl.com, Providing Free Unbiased and Trusted News, Picks and Predictions
-
iGaming Industry8 years ago
Rick Meitzler appointed to the Indian Gaming Magazine Advisory Board for 2018
-
News7 years ago
REVEALED: Top eSports players set to earn $3.2 million in 2019
-
iGaming Industry8 years ago
French Senator raises Loot Boxes to France’s Gambling Regulator
-
News7 years ago
Exclusive Interview with Miklos Handa (Founder of the email marketing solutions, “MailMike.net”), speaker at Vienna International Gaming Expo 2018