Connect with us

Latest News

Popular Gambling App Exposed Millions of Users in Massive Data Leak

Published

on

Reading Time: 5 minutes

 

Led by Noam Rotem and Ran Locar, vpnMentor’s research team discovered a data breach on casino gambling app Clubillion.

The breach originated in a technical database built on an Elasticsearch engine and was recording the daily activities of millions of Clubillion players around the world.

Aside from leaking activity on the app, the breached database also exposed private user information.

With this information publicly available, Clubillion’s users were vulnerable to fraud and various online attacks with potentially devastating results.

Company Profile

Clubillion is a free online casino game available for iOS and Android, offering players 30+ free slot games. While each app is listed under a different developer – Ouroboros on iOS and T7 Games on Android – these are most likely owned by the same company.

Both versions of Clubillion were released in 2019 and became instant hits. Each is now ranked the #1 ‘social slots’ casino app on Google Play and the App Store, with a 4.8 star on both.

Timeline of Discovery and Owner Reaction

Sometimes, the extent of a data breach and the owner of the database are obvious, and the issue quickly resolved. But rare are these times. Most often, we need days of investigation before we understand what’s at stake or who’s leaking the data.

Understanding a breach and its potential impact takes careful attention and time. We work hard to publish accurate and trustworthy reports, ensuring everybody who reads them understands their seriousness.

Some affected parties deny the facts, disregarding our research, or playing down its impact. So, we need to be thorough and make sure everything we find is correct and accurate.

In this case, the database was built on Elasticsearch and hosted on Amazon Web Services (AWS), with Clubillion’s name on its apps, and links to assets owned by the company.

Once Clubillion was confirmed as the owner of the database, we reached out to the developers. While awaiting a reply, we also contacted AWS with details of the leak. It was closed a few days later.

  • Date discovered: 19th March 2020
  • Date vendors contacted: 23rd March 2020
  • Date of contact with AWS: 31st March 2020
  • Date of Action: Approx. 5th April 2020

Example of Entries in the Database

Clubillion’s exposed database contained technical logs for millions of Clubillion users around the world, on both iOS and Android devices. Every time an individual player took any action on the app, a record was logged. Examples of records include:

  • “enter game”
  • “win”
  • “lose”
  • “update account”
  • “create account”

During our investigation of the database, new entries continued to appear continuously. We estimated an average of approximately 200 million records per day – and sometimes, considerably more.

In total, this amounted to over 50GB of exposed records in the database every single day.

Within many of these records, were various forms of user Personally Identifiable Information (PII) data, including:

  • IP addresses
  • Email addresses
  • Winnings
  • Private messages

This data breach was truly global, with millions of records originating from Clubillion’s daily users all over the world. The following list is just a sample of countries affected, along with the average number of daily users from each country:

  • USA – 10,000+
  • UK – 2,475+
  • France – 1,650+
  • Israel – 408+
  • Germany – 1,582+
  • Spain – 1,026+
  • Italy – 2,407+
  • Netherlands – 622+
  • Australia – 6,251+
  • Canada – 7,792+
  • Brazil – 3,859+
  • Sweden – 191+
  • Russia – 547+

Other countries affected included Uzbekistan, India, Poland, Romania, Vietnam, Lebanon, Indonesia, Philippines, Pakistan, Thailand, Austria, Hungry, and Latvia.

As you can see, on a single day, 10,000s of individual Clubillion players were exposed. Each one of these players could be targeted by malicious hackers for fraud and cyberattacks – along with millions more whose records were also contained in the database.

Data Breach Impact

Studies have shown that free gambling and gaming apps are especially prone to attacks and hacking from cybercriminals. They are routinely targeted for theft of private data and embedding malicious software on users’ devices.

Despite their popularity, gambling and casino apps often lack transparency, and it can be impossible to know what steps they’re taking to prevent cybercriminals successfully targeting their users.

One study of 23,000 free gambling apps found that: 3,200 posed a ‘moderate risk’ to users; 379 had known security vulnerabilities; 52 contained malicious software.

Any of these issues could be exploited to target app users in a wide range of frauds and cyberattacks, and Clubillion is no different.

With the exposed user PII and knowledge of their activity on the app, hackers could create elaborate schemes to defraud users. For example, some entries also included transaction errors for attempted card payments on Clubillion.

With the information in these transaction errors, hackers could target users with phishing campaigns, with the following aims:

  1. Trick them into providing their credit card details
  2. Trick them into providing additional PII to be used against them in further fraud
  3. Clicking a link that embeds malware, spyware, or ransomware onto their device.

If cybercriminals used Clubillion to embed malware or similar onto a user’s phone, they could potentially hack other apps, access files stored on the device, make calls, and send texts from the hacked device. They could even access a user’s phone contacts and steal the PII data of their friends and family.

Worse still, as people across the globe now find themselves under quarantine or self-isolation, as a result of the Coronavirus pandemic, the impact of a leak like this is potentially even more significant.

Clubillion stands to gain many new users, along with regular users playing more frequently. Hackers will be aware of this and looking for opportunities to exploit any vulnerabilities in the data security of such a massively popular app.

Had criminal hackers discovered Clubillion’s database, they could have targeted millions of people around the world, with devastating results.

Impact on Clubillion and it’s Developers

The most immediate risk for Clubillion is the loss of players. Data security is a growing concern for everyone these days, and this leak could turn many players off the app. Clubillion is not unique, and players have plenty of other choices for free gambling apps.

With fewer players, Clubillion will lose advertising revenue and reduced profits.

As many of Clubillion’s players reside within the EU, the app is under the jurisdiction of GDPR. The rules of GDPR also apply to apps, and Clubillion will need to take specific actions to ensure the regulatory body in charge doesn’t reprimand it.

Finally, Clubillion could also potentially be removed from Google Play and the App Store. Both Apple and Google are clamping down on apps that pose a risk to their users, removing apps embedded with malware, and taking data leaks much more seriously.

Each of these outcomes has a different likelihood of happening, but they would all negatively impact Clubillion’s revenue and business.

Advice from the Experts

Clubillion’s developers could have easily avoided this leak if they had taken some basic security measures to protect the database. These include, but are not limited to:

  1. Securing their servers.
  2. Implementing proper access rules.
  3. Never leaving a system that doesn’t require authentication open to the internet.

Any company can replicate the same steps, no matter its size.

For a more in-depth guide on how to protect your business, check out our guide to securing your website and online database from hackers.

For Clubillion Users

If you play on Clubillion and are concerned about how this breach might impact you, contact the app’s developers directly to find out what steps it’s taking to protect your data.

To learn about data vulnerabilities in general, read our complete guide to online privacy.

It shows you the many ways cybercriminals target internet users, and the steps you can take to stay safe.

How and Why We Discovered the Breach

The vpnMentor research team discovered the breach in Clubillion’s database as part of a huge web mapping project. Our researchers use port scanning to examine particular IP blocks and test different systems for weaknesses or vulnerabilities. They examine each weakness for any data being leaked.

Our team was able to access this database because it was completely unsecured and unencrypted. 

Whenever we find a data breach, we use expert techniques to verify the owner of the database, usually a commercial company.

As ethical hackers, we’re obliged to inform a company when we discover flaws in their online security. We reached out to Clubillion’s developers, not only to let them know about the vulnerability but also to suggest ways in which they could make their system secure.

These ethics also mean we carry a responsibility to the public. Clubillion users must be aware of a data breach that exposes so much of their sensitive data.

The purpose of this web mapping project is to help make the internet safer for all users.

 

Source

Continue Reading
Advertisement

BETBY

BETBY ACHIEVES GLI CERTIFICATION FOR PERU, EXPANDING ITS FOOTPRINT IN LATIN AMERICA’S REGULATED MARKETS

Published

on

betby-achieves-gli-certification-for-peru,-expanding-its-footprint-in-latin-america’s-regulated-markets

 

BETBY, a top-tier sports betting supplier, has received certification from Gaming Laboratories International (GLI) to provide its sportsbook solution in Peru’s regulated market. This certification marks another significant milestone in BETBY’s continued expansion across Latin America.

With the Peruvian government formalizing its regulated sports betting framework, GLI certification has emerged as a crucial requirement for providers aiming to serve licensed operators in the country. BETBY is now authorized to deliver its innovative and tailored sportsbook solutions in Peru’s rapidly expanding regulated betting market.

GLI’s certification, recognized as a benchmark for excellence, validates BETBY’s ability to meet Peru’s strict technical requirements, including those related to sportsbook functionality, information security management systems, and information security standards. Peru’s regulatory framework is primarily based on GLI-33 certification, which BETBY successfully achieved in early 2025. As a result, the company was well-positioned to swiftly meet the country’s compliance standards.

“Peru represents a key step in our broader Latin American growth strategy, as the region continues to adopt clearer regulatory frameworks for online sports betting,” said Ilze Ramolina, Head of Legal & Compliance at BETBY. “Securing GLI certification for this market, which has a growing digital infrastructure and tech-savvy audience, allows us to support licensed operators in launching compliant and competitive offerings from day one. This is yet another step forward in our mission to deliver tailored, localized solutions that meet both local requirements and regional expectations across the region.”

This achievement follows BETBY’s previous certification for the Brazilian market, solidifying its presence in two of Latin America’s most promising jurisdictions. The supplier’s flexible and highly localised sportsbook platform, combined with its commitment to compliance, positions it as a trusted partner for operators looking to thrive in newly regulated environments.

By entering the Peruvian market, BETBY continues to demonstrate its strategic focus on Latin America, providing hyper-localized, engaging, and secure sports betting experiences for both operators and players.

To find out more about BETBY, visit: https://betby.com/

The post BETBY ACHIEVES GLI CERTIFICATION FOR PERU, EXPANDING ITS FOOTPRINT IN LATIN AMERICA’S REGULATED MARKETS appeared first on Gaming and Gambling Industry in the Americas.

Continue Reading

Latest News

HIPTHER Welcomes Daniela Zelená as New Marketing & Community Engagement Coordinator

Published

on

hipther-welcomes-daniela-zelena-as-new-marketing-&-community-engagement-coordinator
Reading Time: < 1 minute

 

HIPTHER, the leading media and events hub connecting Gaming and Technology sectors across Europe and beyond, is thrilled to officially announce that Daniela Zelená has joined the team as Marketing & Community Engagement Coordinator.

Daniela, who most recently served as Event Marketing Manager at Endorphina, brings with her a wealth of industry experience, creativity, and a deep understanding of community-driven engagement. Her passion for authentic connection and audience-first thinking perfectly aligns with HIPTHER’s mission to elevate both digital and in-person experiences across its events, media, and community initiatives.

Daniela officially joined the HIPTHER team one month ago and has already become an integral part of our fast-moving ecosystem. From leading communications across key channels to launching new community formats and audience engagement strategies, she is helping shape the next phase of HIPTHER’s expansion.

Zoltán Tűndik, Co-Founder and Head of Business at HIPTHER, commented: ”Daniela’s experience, energy, and approach to marketing and community-building is exactly what HIPTHER needs as we grow. We’re building something unique here, and we are excited to have her on this journey with us.”

With Daniela’s expertise and vision, HIPTHER is further strengthening its commitment to creative content, meaningful industry dialogue, and a vibrant community that goes beyond events.

Join us in welcoming Daniela to team #hipthers, and stay tuned as we continue to roll out new initiatives designed to connect and inspire the Gaming & TECH community in bold new ways.

 

About HIPTHER

HIPTHER is the leading conference organizer and media agency for Gaming and Technology industries across Europe and the Americas. Through its events, digital media platforms, and original content, HIPTHER connects innovators, operators, and thought leaders across Gaming, eSports, Fintech, Blockchain, AI, and more.

For more information, visit www.hipther.com or follow us on LinkedIn and Instagram.

The post HIPTHER Welcomes Daniela Zelená as New Marketing & Community Engagement Coordinator appeared first on European Gaming Industry News.

Continue Reading

Canada

Thunderkick’s portfolio makes Ontario debut through SkillOnNet brands

Published

on

thunderkick’s-portfolio-makes-ontario-debut-through-skillonnet-brands

Global entertainment brand SkillOnNet is deepening its existing partnership with Stockholm-based game studio Thunderkick to launch the developer’s unique, engaging slot titles in Ontario.

The Canadian province is one of the most exciting regulated markets in North America, and the Ontario players will now gain access to Thunderkick’s full portfolio of highly acclaimed games via SkillOnNet-powered online casino brands such as PlayOJO, SlotsMagic, and SpinGenie.

Thunderkick is known for its independent, boundary-pushing slot games like Pink Elephants, Esqueleto Explosivo, and Beat the Beast and has established a strong reputation for creativity and originality in the iGaming space. The deal allows the studio to further expand its global footprint while giving Ontario players the chance to enjoy a fresh wave of premium content.

Ontario’s regulated online gaming market, which officially opened in 2022, has quickly become a key market for the iGaming industry, and SkillOnNet was among the first brands to secure licensing in the province. The expansion reinforces SkillOnNet’s commitment to delivering top-tier entertainment in regulated markets globally.

Jani Kontturi at SkillOnNet said: “Thunderkick has been a key partner of ours in other markets, and we’re delighted to bring their outstanding content to Ontario. This region is fast becoming a vital part of our operations, and we’re confident players here will respond just as positively to Thunderkick’s games as they have elsewhere.”

Mariam Dodosh, Account Manager at Thunderkick said: “We’re thrilled to expand our relationship with SkillOnNet and enter the Ontario market together. Our games have a track record of strong performance, and we’re excited to see them go live in one of the most dynamic new regions in iGaming.”

The post Thunderkick’s portfolio makes Ontario debut through SkillOnNet brands appeared first on Gaming and Gambling Industry in the Americas.

Continue Reading

Trending