Connect with us
Prague Gaming & TECH Summit 2025 (25-26 March)

Latest News

Popular Gambling App Exposed Millions of Users in Massive Data Leak

Published

on

Reading Time: 5 minutes

 

Led by Noam Rotem and Ran Locar, vpnMentor’s research team discovered a data breach on casino gambling app Clubillion.

The breach originated in a technical database built on an Elasticsearch engine and was recording the daily activities of millions of Clubillion players around the world.

Aside from leaking activity on the app, the breached database also exposed private user information.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

With this information publicly available, Clubillion’s users were vulnerable to fraud and various online attacks with potentially devastating results.

Company Profile

Clubillion is a free online casino game available for iOS and Android, offering players 30+ free slot games. While each app is listed under a different developer – Ouroboros on iOS and T7 Games on Android – these are most likely owned by the same company.

Both versions of Clubillion were released in 2019 and became instant hits. Each is now ranked the #1 ‘social slots’ casino app on Google Play and the App Store, with a 4.8 star on both.

Timeline of Discovery and Owner Reaction

Sometimes, the extent of a data breach and the owner of the database are obvious, and the issue quickly resolved. But rare are these times. Most often, we need days of investigation before we understand what’s at stake or who’s leaking the data.

Understanding a breach and its potential impact takes careful attention and time. We work hard to publish accurate and trustworthy reports, ensuring everybody who reads them understands their seriousness.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

Some affected parties deny the facts, disregarding our research, or playing down its impact. So, we need to be thorough and make sure everything we find is correct and accurate.

In this case, the database was built on Elasticsearch and hosted on Amazon Web Services (AWS), with Clubillion’s name on its apps, and links to assets owned by the company.

Once Clubillion was confirmed as the owner of the database, we reached out to the developers. While awaiting a reply, we also contacted AWS with details of the leak. It was closed a few days later.

  • Date discovered: 19th March 2020
  • Date vendors contacted: 23rd March 2020
  • Date of contact with AWS: 31st March 2020
  • Date of Action: Approx. 5th April 2020

Example of Entries in the Database

Clubillion’s exposed database contained technical logs for millions of Clubillion users around the world, on both iOS and Android devices. Every time an individual player took any action on the app, a record was logged. Examples of records include:

  • “enter game”
  • “win”
  • “lose”
  • “update account”
  • “create account”

During our investigation of the database, new entries continued to appear continuously. We estimated an average of approximately 200 million records per day – and sometimes, considerably more.

In total, this amounted to over 50GB of exposed records in the database every single day.

Within many of these records, were various forms of user Personally Identifiable Information (PII) data, including:

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)
  • IP addresses
  • Email addresses
  • Winnings
  • Private messages

This data breach was truly global, with millions of records originating from Clubillion’s daily users all over the world. The following list is just a sample of countries affected, along with the average number of daily users from each country:

  • USA – 10,000+
  • UK – 2,475+
  • France – 1,650+
  • Israel – 408+
  • Germany – 1,582+
  • Spain – 1,026+
  • Italy – 2,407+
  • Netherlands – 622+
  • Australia – 6,251+
  • Canada – 7,792+
  • Brazil – 3,859+
  • Sweden – 191+
  • Russia – 547+

Other countries affected included Uzbekistan, India, Poland, Romania, Vietnam, Lebanon, Indonesia, Philippines, Pakistan, Thailand, Austria, Hungry, and Latvia.

As you can see, on a single day, 10,000s of individual Clubillion players were exposed. Each one of these players could be targeted by malicious hackers for fraud and cyberattacks – along with millions more whose records were also contained in the database.

Data Breach Impact

Studies have shown that free gambling and gaming apps are especially prone to attacks and hacking from cybercriminals. They are routinely targeted for theft of private data and embedding malicious software on users’ devices.

Despite their popularity, gambling and casino apps often lack transparency, and it can be impossible to know what steps they’re taking to prevent cybercriminals successfully targeting their users.

One study of 23,000 free gambling apps found that: 3,200 posed a ‘moderate risk’ to users; 379 had known security vulnerabilities; 52 contained malicious software.

Any of these issues could be exploited to target app users in a wide range of frauds and cyberattacks, and Clubillion is no different.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

With the exposed user PII and knowledge of their activity on the app, hackers could create elaborate schemes to defraud users. For example, some entries also included transaction errors for attempted card payments on Clubillion.

With the information in these transaction errors, hackers could target users with phishing campaigns, with the following aims:

  1. Trick them into providing their credit card details
  2. Trick them into providing additional PII to be used against them in further fraud
  3. Clicking a link that embeds malware, spyware, or ransomware onto their device.

If cybercriminals used Clubillion to embed malware or similar onto a user’s phone, they could potentially hack other apps, access files stored on the device, make calls, and send texts from the hacked device. They could even access a user’s phone contacts and steal the PII data of their friends and family.

Worse still, as people across the globe now find themselves under quarantine or self-isolation, as a result of the Coronavirus pandemic, the impact of a leak like this is potentially even more significant.

Clubillion stands to gain many new users, along with regular users playing more frequently. Hackers will be aware of this and looking for opportunities to exploit any vulnerabilities in the data security of such a massively popular app.

Had criminal hackers discovered Clubillion’s database, they could have targeted millions of people around the world, with devastating results.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

Impact on Clubillion and it’s Developers

The most immediate risk for Clubillion is the loss of players. Data security is a growing concern for everyone these days, and this leak could turn many players off the app. Clubillion is not unique, and players have plenty of other choices for free gambling apps.

With fewer players, Clubillion will lose advertising revenue and reduced profits.

As many of Clubillion’s players reside within the EU, the app is under the jurisdiction of GDPR. The rules of GDPR also apply to apps, and Clubillion will need to take specific actions to ensure the regulatory body in charge doesn’t reprimand it.

Finally, Clubillion could also potentially be removed from Google Play and the App Store. Both Apple and Google are clamping down on apps that pose a risk to their users, removing apps embedded with malware, and taking data leaks much more seriously.

Each of these outcomes has a different likelihood of happening, but they would all negatively impact Clubillion’s revenue and business.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

Advice from the Experts

Clubillion’s developers could have easily avoided this leak if they had taken some basic security measures to protect the database. These include, but are not limited to:

  1. Securing their servers.
  2. Implementing proper access rules.
  3. Never leaving a system that doesn’t require authentication open to the internet.

Any company can replicate the same steps, no matter its size.

For a more in-depth guide on how to protect your business, check out our guide to securing your website and online database from hackers.

For Clubillion Users

If you play on Clubillion and are concerned about how this breach might impact you, contact the app’s developers directly to find out what steps it’s taking to protect your data.

To learn about data vulnerabilities in general, read our complete guide to online privacy.

It shows you the many ways cybercriminals target internet users, and the steps you can take to stay safe.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

How and Why We Discovered the Breach

The vpnMentor research team discovered the breach in Clubillion’s database as part of a huge web mapping project. Our researchers use port scanning to examine particular IP blocks and test different systems for weaknesses or vulnerabilities. They examine each weakness for any data being leaked.

Our team was able to access this database because it was completely unsecured and unencrypted. 

Whenever we find a data breach, we use expert techniques to verify the owner of the database, usually a commercial company.

As ethical hackers, we’re obliged to inform a company when we discover flaws in their online security. We reached out to Clubillion’s developers, not only to let them know about the vulnerability but also to suggest ways in which they could make their system secure.

These ethics also mean we carry a responsibility to the public. Clubillion users must be aware of a data breach that exposes so much of their sensitive data.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

The purpose of this web mapping project is to help make the internet safer for all users.

 

Source

Continue Reading
Advertisement

Gambling in the USA

Gila River Resorts & Casinos hosts $5.9 million Big Game prop play contest

Published

on

gila-river-resorts-&-casinos-hosts-$5.9-million-big-game-prop-play-contest
To celebrate the Big Game, Gila River Resorts & Casinos is offering one lucky player the chance to win a $5.9 million prize by correctly predicting the outcome of 26 Big Game prop plays through its $5.9 Million Prop Play Contest.
“Nobody does full gaming entertainment like Gila River Resorts & Casinos, and we’re proving it with an unprecedented chance to win $5.9 million,” said Dominic Orozco, President and Chief Marketing Officer, Gila River Resorts & Casinos. “As a sports-centric gaming brand, we’re not just offering the largest casino sportsbook in the state—we’re delivering a complete Las Vegas-style entertainment experience across four incredible properties. This isn’t just another game day promotion; this is our way of making the Big Game bigger and better for everyone. Let’s make history together.”
In addition to traditional game predictions, the 26 prop plays span the entire Big Game experience. From predicting which team will win the coin toss to the game MVP, the contest brings an immersive way to engage with the game. In addition to the $5.9 million jackpot prize, there will be lower-tier prizes and other instant win opportunities.
Players can enter the contest by completing a prop card online and activating it at any Gila River Resorts & Casinos property. Entry is free; players will need to provide their full name, email and date of birth. Guests must be 21 or older to play. Entries and activations will be accepted from Jan. 27 to Feb. 8 at 11:59 p.m. The winner(s) will be announced on Monday, Feb. 10.

The post Gila River Resorts & Casinos hosts $5.9 million Big Game prop play contest appeared first on Gaming and Gambling Industry in the Americas.

Continue Reading

Gambling in the USA

Spinomenal makes US debut with New Jersey market entry

Published

on

spinomenal-makes-us-debut-with-new-jersey-market-entry

Spinomenal, the leading iGaming content provider, has made its US debut after launching an exciting collaboration with a leading operator in the state of New Jersey, and is anticipating many more valuable collaborations with top tier online casinos.

Following impressive growth rates, Spinomenal is making a major move into the New Jersey iGaming market, marking a key step in its global expansion. By entering this crucial U.S. region, Spinomenal will bring its innovative games to a new audience, strengthening its presence and leadership in the iGaming industry.

Spinomenal’s specially selected titles will be going live via Pariplay’s Fusion aggregation platform in the New Jersey market. Some of the outstanding titles being made available for NJ players are Demi Gods II, Majestic Wild Buffalo and Kitsune’s Scrolls.

This marks a major milestone in Spinomenal’s strategic expansion plan, as this debut establishes the company’s initial presence within the New Jersey market, with further growth anticipated across the US iGaming ecosystem. This move underscores Spinomenal’s commitment to expanding its global footprint and further solidifying its position as a leader in the online casino industry.

Lior Shvartz, CEO for Spinomenal commented: “After a decade of establishing and positioning Spinomenal as a leading provider in the iGaming industry, we have now taken a big leap and will provide our exciting content to the esteemed New Jersey audience. We are highly optimistic about entering this prominent market, following the process of obtaining approval from the DGE.”

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

The post Spinomenal makes US debut with New Jersey market entry appeared first on Gaming and Gambling Industry in the Americas.

Continue Reading

Hard Rock International

Hard Rock Bet, Unity by Hard Rock Loyalty Programs Come Together for Unprecedented Rewards

Published

on

hard-rock-bet,-unity-by-hard-rock-loyalty-programs-come-together-for-unprecedented-rewards

 

Hard Rock International announced that Hard Rock Bet is now fully integrated into Unity by Hard Rock, a one-of-a-kind loyalty program that rewards members for doing the things they love across Hard Rock’s portfolio of more than 200 locations including hotels, casinos, cafes, and Rock Shops around the world.

Hard Rock Bet, Hard Rock International, and Seminole Gaming’s top-rated sports betting and online casino platform, will maintain its free online Loyalty Rewards program, which gives players the opportunity to earn points and one-of-a-kind rewards for their play. With the Unity integration, players will earn Tier Credits for both programs with their online play at Hard Rock Bet and can seamlessly transfer points between the two programs for online and on-property rewards. Upon signing up for Hard Rock Bet, players will automatically be registered for a Unity by Hard Rock account if they aren’t already a member.

The complimentary Unity by Hard Rock global loyalty program offers an array of benefits and services at participating Hard Rock locations where members can earn and redeem Unity Points toward free nights, dining experiences, great merch, and free play. Hard Rock also embarked on a partnership with Royal Caribbean International and Celebrity Cruises to reward travelers on land, sea and at ports of call with reciprocal benefits through Unity by Hard Rock, Royal Caribbean’s Club Royale and Celebrity Cruises’ Blue Chip Club. Now inclusive of Hard Rock Bet players, members gain exclusive access to offers, promotions, and rewards, as well as discounts to participating Hard Rock properties.

“Integrating Hard Rock Bet into Unity will be a game-changer for guest engagement. This enhancement not only offers a fun, interactive way for guests to earn points when placing bets, but also significantly boosts loyalty. By rewarding guests for their playtime, we create a win-win scenario where guests enjoy an enriched experience, and we foster an introduction to all the amazing verticals in our brand through point redemption opportunities at Hotels, Casinos, Cafes, Rock Shops and entertainment venues,” said Keith Sheldon, President of Entertainment & Brand Management at Hard Rock International and Seminole Gaming.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

The post Hard Rock Bet, Unity by Hard Rock Loyalty Programs Come Together for Unprecedented Rewards appeared first on Gaming and Gambling Industry in the Americas.

Continue Reading

Trending