Connect with us
MARE BALTICUM Gaming & TECH Summit 2024

Latest News

Popular Gambling App Exposed Millions of Users in Massive Data Leak

Published

on

Reading Time: 5 minutes

 

Led by Noam Rotem and Ran Locar, vpnMentor’s research team discovered a data breach on casino gambling app Clubillion.

The breach originated in a technical database built on an Elasticsearch engine and was recording the daily activities of millions of Clubillion players around the world.

Aside from leaking activity on the app, the breached database also exposed private user information.

Advertisement

With this information publicly available, Clubillion’s users were vulnerable to fraud and various online attacks with potentially devastating results.

Company Profile

Clubillion is a free online casino game available for iOS and Android, offering players 30+ free slot games. While each app is listed under a different developer – Ouroboros on iOS and T7 Games on Android – these are most likely owned by the same company.

Both versions of Clubillion were released in 2019 and became instant hits. Each is now ranked the #1 ‘social slots’ casino app on Google Play and the App Store, with a 4.8 star on both.

Timeline of Discovery and Owner Reaction

Sometimes, the extent of a data breach and the owner of the database are obvious, and the issue quickly resolved. But rare are these times. Most often, we need days of investigation before we understand what’s at stake or who’s leaking the data.

Understanding a breach and its potential impact takes careful attention and time. We work hard to publish accurate and trustworthy reports, ensuring everybody who reads them understands their seriousness.

Advertisement

Some affected parties deny the facts, disregarding our research, or playing down its impact. So, we need to be thorough and make sure everything we find is correct and accurate.

In this case, the database was built on Elasticsearch and hosted on Amazon Web Services (AWS), with Clubillion’s name on its apps, and links to assets owned by the company.

Once Clubillion was confirmed as the owner of the database, we reached out to the developers. While awaiting a reply, we also contacted AWS with details of the leak. It was closed a few days later.

  • Date discovered: 19th March 2020
  • Date vendors contacted: 23rd March 2020
  • Date of contact with AWS: 31st March 2020
  • Date of Action: Approx. 5th April 2020

Example of Entries in the Database

Clubillion’s exposed database contained technical logs for millions of Clubillion users around the world, on both iOS and Android devices. Every time an individual player took any action on the app, a record was logged. Examples of records include:

  • “enter game”
  • “win”
  • “lose”
  • “update account”
  • “create account”

During our investigation of the database, new entries continued to appear continuously. We estimated an average of approximately 200 million records per day – and sometimes, considerably more.

In total, this amounted to over 50GB of exposed records in the database every single day.

Within many of these records, were various forms of user Personally Identifiable Information (PII) data, including:

Advertisement
  • IP addresses
  • Email addresses
  • Winnings
  • Private messages

This data breach was truly global, with millions of records originating from Clubillion’s daily users all over the world. The following list is just a sample of countries affected, along with the average number of daily users from each country:

  • USA – 10,000+
  • UK – 2,475+
  • France – 1,650+
  • Israel – 408+
  • Germany – 1,582+
  • Spain – 1,026+
  • Italy – 2,407+
  • Netherlands – 622+
  • Australia – 6,251+
  • Canada – 7,792+
  • Brazil – 3,859+
  • Sweden – 191+
  • Russia – 547+

Other countries affected included Uzbekistan, India, Poland, Romania, Vietnam, Lebanon, Indonesia, Philippines, Pakistan, Thailand, Austria, Hungry, and Latvia.

As you can see, on a single day, 10,000s of individual Clubillion players were exposed. Each one of these players could be targeted by malicious hackers for fraud and cyberattacks – along with millions more whose records were also contained in the database.

Data Breach Impact

Studies have shown that free gambling and gaming apps are especially prone to attacks and hacking from cybercriminals. They are routinely targeted for theft of private data and embedding malicious software on users’ devices.

Despite their popularity, gambling and casino apps often lack transparency, and it can be impossible to know what steps they’re taking to prevent cybercriminals successfully targeting their users.

One study of 23,000 free gambling apps found that: 3,200 posed a ‘moderate risk’ to users; 379 had known security vulnerabilities; 52 contained malicious software.

Any of these issues could be exploited to target app users in a wide range of frauds and cyberattacks, and Clubillion is no different.

Advertisement

With the exposed user PII and knowledge of their activity on the app, hackers could create elaborate schemes to defraud users. For example, some entries also included transaction errors for attempted card payments on Clubillion.

With the information in these transaction errors, hackers could target users with phishing campaigns, with the following aims:

  1. Trick them into providing their credit card details
  2. Trick them into providing additional PII to be used against them in further fraud
  3. Clicking a link that embeds malware, spyware, or ransomware onto their device.

If cybercriminals used Clubillion to embed malware or similar onto a user’s phone, they could potentially hack other apps, access files stored on the device, make calls, and send texts from the hacked device. They could even access a user’s phone contacts and steal the PII data of their friends and family.

Worse still, as people across the globe now find themselves under quarantine or self-isolation, as a result of the Coronavirus pandemic, the impact of a leak like this is potentially even more significant.

Clubillion stands to gain many new users, along with regular users playing more frequently. Hackers will be aware of this and looking for opportunities to exploit any vulnerabilities in the data security of such a massively popular app.

Had criminal hackers discovered Clubillion’s database, they could have targeted millions of people around the world, with devastating results.

Advertisement

Impact on Clubillion and it’s Developers

The most immediate risk for Clubillion is the loss of players. Data security is a growing concern for everyone these days, and this leak could turn many players off the app. Clubillion is not unique, and players have plenty of other choices for free gambling apps.

With fewer players, Clubillion will lose advertising revenue and reduced profits.

As many of Clubillion’s players reside within the EU, the app is under the jurisdiction of GDPR. The rules of GDPR also apply to apps, and Clubillion will need to take specific actions to ensure the regulatory body in charge doesn’t reprimand it.

Finally, Clubillion could also potentially be removed from Google Play and the App Store. Both Apple and Google are clamping down on apps that pose a risk to their users, removing apps embedded with malware, and taking data leaks much more seriously.

Each of these outcomes has a different likelihood of happening, but they would all negatively impact Clubillion’s revenue and business.

Advertisement

Advice from the Experts

Clubillion’s developers could have easily avoided this leak if they had taken some basic security measures to protect the database. These include, but are not limited to:

  1. Securing their servers.
  2. Implementing proper access rules.
  3. Never leaving a system that doesn’t require authentication open to the internet.

Any company can replicate the same steps, no matter its size.

For a more in-depth guide on how to protect your business, check out our guide to securing your website and online database from hackers.

For Clubillion Users

If you play on Clubillion and are concerned about how this breach might impact you, contact the app’s developers directly to find out what steps it’s taking to protect your data.

To learn about data vulnerabilities in general, read our complete guide to online privacy.

It shows you the many ways cybercriminals target internet users, and the steps you can take to stay safe.

Advertisement

How and Why We Discovered the Breach

The vpnMentor research team discovered the breach in Clubillion’s database as part of a huge web mapping project. Our researchers use port scanning to examine particular IP blocks and test different systems for weaknesses or vulnerabilities. They examine each weakness for any data being leaked.

Our team was able to access this database because it was completely unsecured and unencrypted. 

Whenever we find a data breach, we use expert techniques to verify the owner of the database, usually a commercial company.

As ethical hackers, we’re obliged to inform a company when we discover flaws in their online security. We reached out to Clubillion’s developers, not only to let them know about the vulnerability but also to suggest ways in which they could make their system secure.

These ethics also mean we carry a responsibility to the public. Clubillion users must be aware of a data breach that exposes so much of their sensitive data.

Advertisement

The purpose of this web mapping project is to help make the internet safer for all users.

 

Source

Continue Reading
Advertisement

Latest News

Week 17/2024 slot games releases

Published

on

week-17/2024-slot-games-releases
Reading Time: 5 minutes

 

Here are this weeks latest slots releases compiled by European Gaming

Belatra Games, the specialist online slots developer, is on point with its latest sharply designed game, Golden øks. This Norse-inspired adventure carries on from the popular Axe of Fortune title that hit the market at the turn of the year. Golden øks is set against a 5×3 layout and is brought to life with a powerful soundtrack to heighten the atmosphere.

Belatra grows games portfolio with Golden øks title

Endorphina, has announced the release of its brand-new title, Jolly Queen, which will join its portfolio on April 27th. Jolly Queen is a 5-reel, 5-row fruit slot with 50 fixed paylines, introducing players to the lifestyle of the nobles. On top of the aristocratic ambiance, Jolly Queen provides players with Free Games, allowing them to master the reels.

Advertisement

Endorphina releases its newest title - Jolly Queen!

Evoplay has released Candy Craze, a vibrant slot stacked with features and modifiers, including the powerful Gum Drop Multiplier which boosts win potential. Set amidst the backdrop of sumptuous sweets within a cloudy landscape, the 5×5 cascading reels title gives players a sugary rush when the Gum Drop Multiplier activates, revealing a mystery value at the end of each winning spin up to x100, enhancing the chance for wins during the main game and Free Spins.

Yggdrasil, a leading iGaming publisher, has revived the gold rush in a jackpot-filled game that embodies the spirit of old west prospecting in Gold Frontier Jackpots FastPot5™. Fans of lower volatility slots with straightforward mechanics that get fortune seekers right to the heart of the action are tasked with gathering keys to enter the treasure bonus game.

Relax Gaming is offering players some opulence in its latest release Sultan Spins. This high volatility slot sees its gold-trimmed reels set against a sprawling desert metropolis. Players have the chance to rack up riches via an entertaining free spins feature and lucrative local jackpot.

Greentube has introduced its latest title in the popular Diamond Link ™ series, Diamond Link ™: Mighty Dwarves Inc. Set deep in underground mines, this adventurous 5×3 slot is packed with innovative features for ample chance to win across its 25 paylines when players spin the reels adorned with hammers, hard hats and laser symbols.

Get your eyes ready because it’s time to take a trip to the pet centre to meet the ugliest, quirkiest, wildest-looking pets you’ve ever seen in the brand new slot, Fugly Pets, from Stakelogic. Fugly Pets takes players to a banged-up old pet store to explore its collection of weird and charming, downright ugly pets. Meet a scruffy parrot, a catnip crazed kitty, and an unfortunate-looking little dog.

Advertisement

 

 

Load your tackle box, bait your hook and get ready to reel in the catch of the day in Fishin’ The Biggest from Apparat Gaming, the in-demand German software provider’s latest splash hit slot that sees players trawl the sea for free spins and massively multiplied prizes. Played over five reels, three rows and ten fixed paylines, Fishin’ The Biggest is a highly-volatile title with an outdoor angling theme.

Thunderkick has announced the launch of Midas Golden Touch 2, the highly-anticipated sequel to the acclaimed 2019 original. This latest release invites players to rediscover an enchanted realm where everything King Midas touches turns to gold. The 3×5 video slot boasts 15 paylines and showcases Thunderkick’s signature high-quality design and innovative features.

Belatra Games, the specialist online slots developer, has served up another classic with its tasty Chef’s Sticky Fruits slot. This latest release from Belatra’s studio  is a vibrant and juicy addition to its renowned catalogue of slots. It’s a 5×4 slot game bursting with colour that’s heightened with an upbeat, retro soundtrack that perfectly captures the essence of fun at the heart of every play.

Advertisement

Belatra serves up tasty Chef’s Sticky Fruits slot

3 Oaks Gaming has launched 3 China Pots: Hold and Win, the first time the company has integrated the popular 3 Pots mechanic within a Far East-themed title. The latest instalment from 3 Oaks to incorporate the 3 Pots functionality sees players transported to the allure of the Orient, where the Extra, Double and Multi modifiers influence the Bonus Game once activated.

3 Oaks Gaming presents a feature-rich trip to the Far East in 3 China Pots: Hold and Win

Pragmatic Play has unleashed roaming wild re-spins and random guaranteed wins in Release the Bison. Symbols of the American frontier abound in this 5×4 slot, where hitting four or more rampaging bison triggers the wild re-spin feature, during which all wilds roam the reels to boost win potential.

Blueprint Gaming’s latest slot release tasks players to look for the leprechaun’s pot of gold under the water rather than at the end of the rainbow in Plenty O’ Fish, a 6×4 hybrid of sea creatures and shimmering rewards. Players must look to unlock a tackle box of treasure with a jaunty leprechaun being the key to wins, lurking behind a dynamically coloured underwater background that changes when the bonus game is triggered.

Booming Games has launched its latest sweet sensation to its collection of engaging slot games – Fruit Heaven Hold and Win™. This is a deliciously designed 5×3 slot game with 25 paylines, which promises players an exciting experience full of fantastic fruity features and Stacked Wilds.

Wazdan is multiplying jackpots in the follow-up to its top-performing game Mighty Wild™: Panther Grand Gold Edition. Venturing to the depths of the jungle where a black panther rules the reels on a 5×3 gameboard, the new edition provides even larger win potential. With the increased value of the Cash symbols and Cash Infinity™ symbols, there is also a more lucrative Grand Jackpot of 1500x the base bet.

Advertisement

The post Week 17/2024 slot games releases appeared first on European Gaming Industry News.

Continue Reading

BiS SiGMA Americas

GR8 Tech Brings “Best Workplace 2024” and Fresh LatAm Insights from BIS SiGMA Americas

Published

on

gr8-tech-brings-“best-workplace-2024”-and-fresh-latam-insights-from-bis-sigma-americas

 

GR8 Tech’s participation at the recent BIS SiGMA Americas event held in São Paulo was quite successful, highlighted by winning the ‘BEST WORKPLACE 2024’ award at the SiGMA Americas Awards and holding over 150 meetings with operators and other stakeholders. These interactions have laid a solid foundation for GR8 Tech’s strategic expansion in the region and provided the team with significant insights into the evolving Latin American iGaming market.

A Closer Look at the Brazilian Market and Wider LatAm

Brazil is not synonymous with Latin America. Each country on the continent has its own unique characteristics,Evgen Belousov, GR8 Tech CEO.

The most important thing to understand in the LatAm region is that it’s very diverse. There are significant cultural and operational differences that necessitate a localized approach. For example, “Brazil’s rhythm is distinct; life starts in the afternoon, and business interactions reflect this laid-back pace. To thrive here, understanding and integrating into the local lifestyle is essential.

Advertisement

Belousov further discussed the Brazilian market’s competitive nature, highlighting retention strategies’ crucial role. “The churn rate is high as players frequently shift between operators lured by aggressive marketing. Hence, having robust retention mechanisms, such as real-time tools and enticing bonus mechanics, is crucial to maintaining a loyal customer base,” he added.

Yevhen Krazhan, CBDO, addressed trending compliance and market preferences. “Regulation is a hot topic, with a keen focus on product compliance. Moreover, while classic sportsbooks saturate the market, emerging interests lie in areas like fantasy sports and social gaming, which present new opportunities for differentiation and growth.”

Thomas Carvalhaes, Senior Business Development Manager for the Latin America region, provided his expertise during the panel discussion “Understanding the demands and evolution of the B2B market”, highlighting the demand for localization and intuitive technology. “In Latin America, where many markets are still learning the ropes of iGaming, the simplicity of the technology is key. Products need to be user-friendly to ensure they meet the expectations of a clientele that values straightforward and engaging gaming experiences,” Carvalhaes explained.

Future Directions and Engagements

Building on the insights and achievements from BIS SiGMA Americas, GR8 Tech is actively expanding its presence in Brazil and LatAm, establishing its reputation as a key player in the region. The company is also exploring opportunities in other global markets, with Asia as the next target at SiGMA Asia, scheduled for June 3-6 in Manila, Philippines. This upcoming event presents another fantastic opportunity for GR8 Tech to demonstrate the capabilities of its flagship GR8 Sportsbook platform and forge new partnerships in another exciting and diverse region. We invite all our partners and clients to stay tuned, following our updates at https://gr8.tech/.

Advertisement
Continue Reading

Latest News

EL Executive Committee Names Mr Ionut-Valeriu Andrei as New Member

Published

on

el-executive-committee-names-mr-ionut-valeriu-andrei-as-new-member
Reading Time: < 1 minute

 

The EL Executive Committee has named Mr. Ionut-Valeriu Andrei as its newest member during its meeting on April 5. Mr. Andrei is the General Manager of Loteria Română since 2022, and succeeds Mr. Olgierd Cieslik, whose term as CEO of Totalisator Sportowy (Poland) has concluded.

”It is with great pleasure to welcome Mr Ionut-Valeriu Andrei as a new Executive Committee member. As an experienced executive, Mr Andrei has already contributed in various ways to our Association and the EL Executive Committee members trust he will continue to do so in the future,” Arjan van ‘t Veer, Secretary General of EL, said.

Mr Andrei will oversee the learning and development activities of EL. His appointment underscores the further commitment of the European Lotteries to inclusivity and collaboration among its members.

Advertisement

”I am honoured to join the EL Executive Committee and look forward to working closely with my colleagues to advance the mission and values of the Association,” Ionut-Valeriu Andrei said.

Mr Andrei’s co-optation will be formalised during the upcoming EL General Assembly in Salzburg (Austria) on 17 June 2024.

The post EL Executive Committee Names Mr Ionut-Valeriu Andrei as New Member appeared first on European Gaming Industry News.

Continue Reading

Trending