Latest News
Popular Gambling App Exposed Millions of Users in Massive Data Leak
Led by Noam Rotem and Ran Locar, vpnMentor’s research team discovered a data breach on casino gambling app Clubillion.
The breach originated in a technical database built on an Elasticsearch engine and was recording the daily activities of millions of Clubillion players around the world.
Aside from leaking activity on the app, the breached database also exposed private user information.
With this information publicly available, Clubillion’s users were vulnerable to fraud and various online attacks with potentially devastating results.
Company Profile
Clubillion is a free online casino game available for iOS and Android, offering players 30+ free slot games. While each app is listed under a different developer – Ouroboros on iOS and T7 Games on Android – these are most likely owned by the same company.
Both versions of Clubillion were released in 2019 and became instant hits. Each is now ranked the #1 ‘social slots’ casino app on Google Play and the App Store, with a 4.8 star on both.
Timeline of Discovery and Owner Reaction
Sometimes, the extent of a data breach and the owner of the database are obvious, and the issue quickly resolved. But rare are these times. Most often, we need days of investigation before we understand what’s at stake or who’s leaking the data.
Understanding a breach and its potential impact takes careful attention and time. We work hard to publish accurate and trustworthy reports, ensuring everybody who reads them understands their seriousness.
Some affected parties deny the facts, disregarding our research, or playing down its impact. So, we need to be thorough and make sure everything we find is correct and accurate.
In this case, the database was built on Elasticsearch and hosted on Amazon Web Services (AWS), with Clubillion’s name on its apps, and links to assets owned by the company.
Once Clubillion was confirmed as the owner of the database, we reached out to the developers. While awaiting a reply, we also contacted AWS with details of the leak. It was closed a few days later.
- Date discovered: 19th March 2020
- Date vendors contacted: 23rd March 2020
- Date of contact with AWS: 31st March 2020
- Date of Action: Approx. 5th April 2020
Example of Entries in the Database
Clubillion’s exposed database contained technical logs for millions of Clubillion users around the world, on both iOS and Android devices. Every time an individual player took any action on the app, a record was logged. Examples of records include:
- “enter game”
- “win”
- “lose”
- “update account”
- “create account”
During our investigation of the database, new entries continued to appear continuously. We estimated an average of approximately 200 million records per day – and sometimes, considerably more.
In total, this amounted to over 50GB of exposed records in the database every single day.
Within many of these records, were various forms of user Personally Identifiable Information (PII) data, including:
- IP addresses
- Email addresses
- Winnings
- Private messages
This data breach was truly global, with millions of records originating from Clubillion’s daily users all over the world. The following list is just a sample of countries affected, along with the average number of daily users from each country:
- USA – 10,000+
- UK – 2,475+
- France – 1,650+
- Israel – 408+
- Germany – 1,582+
- Spain – 1,026+
- Italy – 2,407+
- Netherlands – 622+
- Australia – 6,251+
- Canada – 7,792+
- Brazil – 3,859+
- Sweden – 191+
- Russia – 547+
Other countries affected included Uzbekistan, India, Poland, Romania, Vietnam, Lebanon, Indonesia, Philippines, Pakistan, Thailand, Austria, Hungry, and Latvia.
As you can see, on a single day, 10,000s of individual Clubillion players were exposed. Each one of these players could be targeted by malicious hackers for fraud and cyberattacks – along with millions more whose records were also contained in the database.
Data Breach Impact
Studies have shown that free gambling and gaming apps are especially prone to attacks and hacking from cybercriminals. They are routinely targeted for theft of private data and embedding malicious software on users’ devices.
Despite their popularity, gambling and casino apps often lack transparency, and it can be impossible to know what steps they’re taking to prevent cybercriminals successfully targeting their users.
One study of 23,000 free gambling apps found that: 3,200 posed a ‘moderate risk’ to users; 379 had known security vulnerabilities; 52 contained malicious software.
Any of these issues could be exploited to target app users in a wide range of frauds and cyberattacks, and Clubillion is no different.
With the exposed user PII and knowledge of their activity on the app, hackers could create elaborate schemes to defraud users. For example, some entries also included transaction errors for attempted card payments on Clubillion.
With the information in these transaction errors, hackers could target users with phishing campaigns, with the following aims:
- Trick them into providing their credit card details
- Trick them into providing additional PII to be used against them in further fraud
- Clicking a link that embeds malware, spyware, or ransomware onto their device.
If cybercriminals used Clubillion to embed malware or similar onto a user’s phone, they could potentially hack other apps, access files stored on the device, make calls, and send texts from the hacked device. They could even access a user’s phone contacts and steal the PII data of their friends and family.
Worse still, as people across the globe now find themselves under quarantine or self-isolation, as a result of the Coronavirus pandemic, the impact of a leak like this is potentially even more significant.
Clubillion stands to gain many new users, along with regular users playing more frequently. Hackers will be aware of this and looking for opportunities to exploit any vulnerabilities in the data security of such a massively popular app.
Had criminal hackers discovered Clubillion’s database, they could have targeted millions of people around the world, with devastating results.
Impact on Clubillion and it’s Developers
The most immediate risk for Clubillion is the loss of players. Data security is a growing concern for everyone these days, and this leak could turn many players off the app. Clubillion is not unique, and players have plenty of other choices for free gambling apps.
With fewer players, Clubillion will lose advertising revenue and reduced profits.
As many of Clubillion’s players reside within the EU, the app is under the jurisdiction of GDPR. The rules of GDPR also apply to apps, and Clubillion will need to take specific actions to ensure the regulatory body in charge doesn’t reprimand it.
Finally, Clubillion could also potentially be removed from Google Play and the App Store. Both Apple and Google are clamping down on apps that pose a risk to their users, removing apps embedded with malware, and taking data leaks much more seriously.
Each of these outcomes has a different likelihood of happening, but they would all negatively impact Clubillion’s revenue and business.
Advice from the Experts
Clubillion’s developers could have easily avoided this leak if they had taken some basic security measures to protect the database. These include, but are not limited to:
- Securing their servers.
- Implementing proper access rules.
- Never leaving a system that doesn’t require authentication open to the internet.
Any company can replicate the same steps, no matter its size.
For a more in-depth guide on how to protect your business, check out our guide to securing your website and online database from hackers.
For Clubillion Users
If you play on Clubillion and are concerned about how this breach might impact you, contact the app’s developers directly to find out what steps it’s taking to protect your data.
To learn about data vulnerabilities in general, read our complete guide to online privacy.
It shows you the many ways cybercriminals target internet users, and the steps you can take to stay safe.
How and Why We Discovered the Breach
The vpnMentor research team discovered the breach in Clubillion’s database as part of a huge web mapping project. Our researchers use port scanning to examine particular IP blocks and test different systems for weaknesses or vulnerabilities. They examine each weakness for any data being leaked.
Our team was able to access this database because it was completely unsecured and unencrypted.
Whenever we find a data breach, we use expert techniques to verify the owner of the database, usually a commercial company.
As ethical hackers, we’re obliged to inform a company when we discover flaws in their online security. We reached out to Clubillion’s developers, not only to let them know about the vulnerability but also to suggest ways in which they could make their system secure.
These ethics also mean we carry a responsibility to the public. Clubillion users must be aware of a data breach that exposes so much of their sensitive data.
The purpose of this web mapping project is to help make the internet safer for all users.
Gambling in the USA
Gaming Americas Weekly Roundup – April 7-13

Welcome to our weekly roundup of American gambling news again! Here, we are going through the weekly highlights of the American gambling industry which include the latest news and new partnerships. Read on and get updated.
Latest News
WyoLotto’s COO, Robin Medina, has been named to join a national committee to support problem gambling initiatives. The committee is through the National Council on Problem Gambling and will manage the annual selection of nominations and election of the Board of Directors that oversees NCPG. Last year WyoLotto applied for and was accepted to the NCPG and NASPL’s (North American State and Provincial Lotteries) Responsible Gambling Verification Programme. WyoLotto’s Responsible Gambling Programme includes an in depth plan to ensure the organisation honours its commitment to educating players, retailers and the general public about how to gamble responsibly and what to do if gambling becomes a problem for yourself or someone you know.
As Hard Rock Hotel & Casino Tejon moves closer to its highly anticipated grand opening, the company is engaging with the Kern County community through exclusive informational sessions at Bakersfield College’s Renegade Event Room located at 1801 Panorama Drive. The first session, held on April 4, provided local leaders and invited guests with insights into upcoming job and vendor opportunities in the region. The second session took place on April 5 from 10:00 AM to 12:30 PM. Job opportunities for Hard Rock Hotel & Casino Tejon will be posted on the recruitment site, www.gotoworkhappy.com, starting in May.
An investigation by the Delaware Division of Gaming Enforcement (DGE) into VGW Luckyland – a subsidiary of the Australian-based VGW Holdings – revealed that VGW Luckyland was operating illegal online gaming. Delaware officials concluded that VGW misrepresented its services as a promotional sweepstakes while enabling players to purchase coins for casino-style games, leading to potential cash winnings. These types of real-money games offered to Delaware residents by an unlicensed entity violate the Delaware Constitution, the Delaware Penal Code and the Delaware Gaming Competitiveness Act of 2012. With the support of the Delaware State Lottery, DGE issued a cease-and-desist order to VGW.
Partnerships
AC Milan announced a new partnership with Reals, a company renowned for its excellence in Brazil’s sports betting and online gaming market, which will become Official Regional Betting Partner of the Rossoneri’s Club in Latin America. Elected in 2024 as the “Best Sportsbook Operator” in Brazil by SiGMA World – the largest international authority in iGaming – Reals has been consolidating its position in the sector, reinforcing its growing trajectory of ascent. The brand is aligned with the best market practices, presenting sustainable growth based on innovation, strategic partnerships and sports engagement.
Scientific Games’ SciQ retail technology is set to roll out at North Carolina Education Lottery retailers as part of the Lottery’s focus on improving the retail environment for its Scratch-Off games. The company will deploy 1000 SciQ units at lottery retailers across North Carolina. NCEL Scratch-Off games represented more than $2.9 billion in retail sales in fiscal year 2024, anchoring NCEL among the world’s top 15 performing instant game lotteries (La Fleur’s 2024 World Almanac). Offering real-time scratch game inventory management data that amplifies the power of Scientific Games’ SciTrak predictive ordering system used by NCEL, SciQ creates supply chain efficiencies proven to lift scratch game sales.
The post Gaming Americas Weekly Roundup – April 7-13 appeared first on European Gaming Industry News.
Compliance Updates
Navigating Legal Frontiers: Nordic Legal’s Vision for the Finnish Gambling Market

The Prague Gaming & TECH Summit 2025 brought together top experts across the iGaming and tech landscape, and Nordic Legal stood out as the event’s Scandinavian Legal Expertise Sponsor. A renowned legal advisory firm in the Nordic region, Nordic Legal continues to shape the future of gambling legislation and compliance in Europe.
In this post-event interview, we caught up with Pekka Ilmivalta, Head of the Finnish Office at Nordic Legal, to dive deeper into the firm’s insights on the upcoming Finnish gambling reform, the legal challenges it poses, and the opportunities it presents for operators preparing to enter the market.
Finland is preparing to launch its regulated gambling sector in January 2026. As an expert with over 20 years of experience in the gambling industry, how do you view its draft legislation and the current state of the Finnish gambling market?
Finns are used to gambling online, and the size of the market is close to 2 billion euros in GGR. As the market share of the national monopoly operator, Veikkaus, has declined to around 50 percent, nearly half of the gambling spending already takes place outside the Finnish regulation. Therefore, the gambling legislation reform is really needed.
The Government Proposal now being dealt with in the Finnish Parliament is generally a comprehensive and a good package. As the political parties are quite unanimous about the need for the reform, I expect the parliamentary discussion to concentrate on the balance between responsibility measures and the features making the market interesting enough for the operators to enter the regulated market. Especially marketing, use of affiliates and bonusing will, and should, be discussed.
I believe that the Parliament will approve the new legislation early next autumn and that the B2C license application process will be able to begin already in January next year.
The Finnish legislative review council has raised concerns about potential increases in gambling harms under the new regulatory framework. What measures do you believe are necessary to mitigate these risks, and how could Finland balance market liberalization with responsible gambling practices?
Personally, I think that gambling harms must be taken seriously. However, as almost half of the Finnish gambling now happens outside the regulated market, I am convinced that succeeding in channelization is a crucial starting point to really mitigate gambling harms. Therefore, attractiveness of the market and measures against the black market are extremely important. Furthermore, self-exclusion and responsible gambling tools are, of course, needed for the players. Generally, I believe that AI assisted monitoring could and will have an important role in preventing harmful gambling in the future. To really work, responsible gambling tools need to be both pragmatic and relevant for each individual player.
Considering Finland’s upcoming gambling reform, what legal and operational challenges should gambling operators be prepared for, particularly regarding compliance and player protection? Which key trends do you see shaping the market’s future?
As it seems now that affiliates and welcome bonuses will be banned, operators will have to find other means to build their brand and acquire customers. Even though traditional marketing and sponsoring are widely acceptable, I would expect to see innovative solutions to stand out from the probable marketing avalanche during the first months after the market opening. Perhaps new kinds of sponsorships or retail activities? Or even enhanced player protection measures to gain a competitive edge?
Overall, I would advise operators to start their market entry preparations early enough. The licensing procedure could take several (6 to 9) months. Also, adjusting to the local technical and player protection requirements might not happen overnight.
What insights could help Finland create a balanced and effective gambling market?
I believe that the new legislation will provide a good enough framework for a functional gambling market. However, based on experiences from Sweden and Denmark, I would point out two practical aspects crucial to making the new legislation effective: First, there needs to be collaboration between licensed operators and the new regulator. Dialogue and a mutual will to find solutions should be the common mindset. Secondly, the regulator hopefully has enough resources (tools, persons and persistence) to interfere with the black-market operations, which will evidently still exist also after the reform.
Nordic Legal has extensive experience advising European governments on regulatory best practices. How can your firm assist operators looking to enter the Finnish market and navigate the evolving legal landscape?
With our deep knowledge of Finnish legislation, extensive experience from regulatory developments in other jurisdictions, and strong industry relationships, we are well-positioned to support operators and B2B suppliers entering the Finnish market. We can offer comprehensive guidance not only on compliance and licensing, but also on navigating strategic challenges, ensuring our clients are well-prepared for a dynamic and shifting legal landscape. Our proactive approach enables us to identify regulatory changes early and help clients stay ahead of industry developments.
The post Navigating Legal Frontiers: Nordic Legal’s Vision for the Finnish Gambling Market appeared first on European Gaming Industry News.
Latest News
The Power of Influencers in iGaming – Insights from the EEGS Webinar

In an increasingly digital world, the influence of social media personalities is undeniable, especially within the iGaming industry. To stay competitive and engage with a broader audience, brands must adapt to the growing power of influencers. Recently, the dynamic EEGS Webinar, “The Rising Power of Influencers in iGaming: Use Their Power for Your Success,” brought together key experts to explore how influencers can elevate iGaming brands to new heights. Expert speakers Jekaterina Dubnicka, Alexandra Voronetskaya, and Wojciech Trzaska shared their valuable insights on the nuances of influencer marketing, and how companies can leverage this to succeed.
The Brave Step of Working with Influencers
Alexandra Voronetskaya emphasized how significant the decision to collaborate with influencers is for any company. “When a company decides to work with influencers, it is a very brave step,” she noted. This decision means not only expanding a brand’s visibility but also committing to a much more open communication strategy.
Working with influencers is not just about showcasing a product; it’s about creating an authentic connection. Brands must be prepared for heightened visibility, quicker responses to public feedback, and increased flexibility in their strategies. “You have to answer quicker, you should be more flexible,” Alexandra explained, underscoring the evolving nature of marketing in today’s fast-paced world. This openness can be daunting for some brands, but it can also bring tremendous benefits when executed well.
Getting Real: The Importance of Authenticity
Jekaterina Dubnicka on the other hand delivered a powerful message about the importance of authenticity when collaborating with influencers. “If you decide to go live and public, there is one crucial thing you need to know: No subscriber is interested in your surface. Everyone wants to see something deeper,” Jekaterina said. This statement couldn’t be more fitting in the context of influencer marketing. Audiences today crave genuine connections and transparency, rather than polished advertisements.
She went on to challenge companies considering influencer partnerships: “Before you decide to work with influencers, you need to answer yourself: Why?” This question serves as a reminder that influencer partnerships should be rooted in a clear strategic vision. It’s not enough to just follow trends — businesses need to understand why they want to engage with influencers and how they plan to create value for both their brand and the influencer’s audience.
The Power of Smaller Influencers
A common misconception in influencer marketing is that success is tied to having millions of followers. However, Jekaterina pointed out that the number of followers doesn’t always equate to success. “The huge amount of followers doesn’t necessarily bring success,” she noted, pointing to the fact that smaller influencers often yield greater engagement. Smaller influencers tend to have a more loyal and interactive audience, making them more flexible and responsive to brand messages.
In iGaming, where emotional connection plays a key role, Alexandra emphasized the importance of finding influencers whose values and approach resonate with the brand. “Working with influencers is about emotions, and when you are on the same page, that is magic,” she said. It’s about creating an authentic, emotional link that transcends the transactional nature of traditional advertising.
All attendees of the EEGS Webinar received a Certificate of Attendance, acknowledging their commitment to continuous learning and professional development in the iGaming industry.
For those who missed the live session, the on-demand video is now available – featuring key insights on how influencers are reshaping the marketing strategies, and practical tips on choosing, briefing, and collaborating with them effectively.
You can watch the full session here: www.youtube.com/@eegamingsummit
Stay tuned for more updates and upcoming events by following EEGS on social media and visiting their official website.
The post The Power of Influencers in iGaming – Insights from the EEGS Webinar appeared first on European Gaming Industry News.
-
gaming3 years ago
ODIN by 4Players: Immersive, state-of-the-art in-game audio launches into the next generation of gaming
-
EEG iGaming Directory8 years ago
iSoftBet continues to grow with new release Forest Mania
-
News7 years ago
Softbroke collaborates with Asia Live Tech for the expansion of the service line in the igaming market
-
News6 years ago
Super Bowl LIII: NFL Fans Can Bet on the #1 Sportsbook Review Site Betting-Super-Bowl.com, Providing Free Unbiased and Trusted News, Picks and Predictions
-
iGaming Industry7 years ago
Rick Meitzler appointed to the Indian Gaming Magazine Advisory Board for 2018
-
News6 years ago
REVEALED: Top eSports players set to earn $3.2 million in 2019
-
iGaming Industry7 years ago
French Senator raises Loot Boxes to France’s Gambling Regulator
-
News7 years ago
Exclusive Interview with Miklos Handa (Founder of the email marketing solutions, “MailMike.net”), speaker at Vienna International Gaming Expo 2018