Connect with us
MARE BALTICUM Gaming & TECH Summit 2024

Latest News

Popular Gambling App Exposed Millions of Users in Massive Data Leak

Published

on

Reading Time: 5 minutes

 

Led by Noam Rotem and Ran Locar, vpnMentor’s research team discovered a data breach on casino gambling app Clubillion.

The breach originated in a technical database built on an Elasticsearch engine and was recording the daily activities of millions of Clubillion players around the world.

Aside from leaking activity on the app, the breached database also exposed private user information.

Advertisement

With this information publicly available, Clubillion’s users were vulnerable to fraud and various online attacks with potentially devastating results.

Company Profile

Clubillion is a free online casino game available for iOS and Android, offering players 30+ free slot games. While each app is listed under a different developer – Ouroboros on iOS and T7 Games on Android – these are most likely owned by the same company.

Both versions of Clubillion were released in 2019 and became instant hits. Each is now ranked the #1 ‘social slots’ casino app on Google Play and the App Store, with a 4.8 star on both.

Timeline of Discovery and Owner Reaction

Sometimes, the extent of a data breach and the owner of the database are obvious, and the issue quickly resolved. But rare are these times. Most often, we need days of investigation before we understand what’s at stake or who’s leaking the data.

Understanding a breach and its potential impact takes careful attention and time. We work hard to publish accurate and trustworthy reports, ensuring everybody who reads them understands their seriousness.

Advertisement

Some affected parties deny the facts, disregarding our research, or playing down its impact. So, we need to be thorough and make sure everything we find is correct and accurate.

In this case, the database was built on Elasticsearch and hosted on Amazon Web Services (AWS), with Clubillion’s name on its apps, and links to assets owned by the company.

Once Clubillion was confirmed as the owner of the database, we reached out to the developers. While awaiting a reply, we also contacted AWS with details of the leak. It was closed a few days later.

  • Date discovered: 19th March 2020
  • Date vendors contacted: 23rd March 2020
  • Date of contact with AWS: 31st March 2020
  • Date of Action: Approx. 5th April 2020

Example of Entries in the Database

Clubillion’s exposed database contained technical logs for millions of Clubillion users around the world, on both iOS and Android devices. Every time an individual player took any action on the app, a record was logged. Examples of records include:

  • “enter game”
  • “win”
  • “lose”
  • “update account”
  • “create account”

During our investigation of the database, new entries continued to appear continuously. We estimated an average of approximately 200 million records per day – and sometimes, considerably more.

In total, this amounted to over 50GB of exposed records in the database every single day.

Within many of these records, were various forms of user Personally Identifiable Information (PII) data, including:

Advertisement
  • IP addresses
  • Email addresses
  • Winnings
  • Private messages

This data breach was truly global, with millions of records originating from Clubillion’s daily users all over the world. The following list is just a sample of countries affected, along with the average number of daily users from each country:

  • USA – 10,000+
  • UK – 2,475+
  • France – 1,650+
  • Israel – 408+
  • Germany – 1,582+
  • Spain – 1,026+
  • Italy – 2,407+
  • Netherlands – 622+
  • Australia – 6,251+
  • Canada – 7,792+
  • Brazil – 3,859+
  • Sweden – 191+
  • Russia – 547+

Other countries affected included Uzbekistan, India, Poland, Romania, Vietnam, Lebanon, Indonesia, Philippines, Pakistan, Thailand, Austria, Hungry, and Latvia.

As you can see, on a single day, 10,000s of individual Clubillion players were exposed. Each one of these players could be targeted by malicious hackers for fraud and cyberattacks – along with millions more whose records were also contained in the database.

Data Breach Impact

Studies have shown that free gambling and gaming apps are especially prone to attacks and hacking from cybercriminals. They are routinely targeted for theft of private data and embedding malicious software on users’ devices.

Despite their popularity, gambling and casino apps often lack transparency, and it can be impossible to know what steps they’re taking to prevent cybercriminals successfully targeting their users.

One study of 23,000 free gambling apps found that: 3,200 posed a ‘moderate risk’ to users; 379 had known security vulnerabilities; 52 contained malicious software.

Any of these issues could be exploited to target app users in a wide range of frauds and cyberattacks, and Clubillion is no different.

Advertisement

With the exposed user PII and knowledge of their activity on the app, hackers could create elaborate schemes to defraud users. For example, some entries also included transaction errors for attempted card payments on Clubillion.

With the information in these transaction errors, hackers could target users with phishing campaigns, with the following aims:

  1. Trick them into providing their credit card details
  2. Trick them into providing additional PII to be used against them in further fraud
  3. Clicking a link that embeds malware, spyware, or ransomware onto their device.

If cybercriminals used Clubillion to embed malware or similar onto a user’s phone, they could potentially hack other apps, access files stored on the device, make calls, and send texts from the hacked device. They could even access a user’s phone contacts and steal the PII data of their friends and family.

Worse still, as people across the globe now find themselves under quarantine or self-isolation, as a result of the Coronavirus pandemic, the impact of a leak like this is potentially even more significant.

Clubillion stands to gain many new users, along with regular users playing more frequently. Hackers will be aware of this and looking for opportunities to exploit any vulnerabilities in the data security of such a massively popular app.

Had criminal hackers discovered Clubillion’s database, they could have targeted millions of people around the world, with devastating results.

Advertisement

Impact on Clubillion and it’s Developers

The most immediate risk for Clubillion is the loss of players. Data security is a growing concern for everyone these days, and this leak could turn many players off the app. Clubillion is not unique, and players have plenty of other choices for free gambling apps.

With fewer players, Clubillion will lose advertising revenue and reduced profits.

As many of Clubillion’s players reside within the EU, the app is under the jurisdiction of GDPR. The rules of GDPR also apply to apps, and Clubillion will need to take specific actions to ensure the regulatory body in charge doesn’t reprimand it.

Finally, Clubillion could also potentially be removed from Google Play and the App Store. Both Apple and Google are clamping down on apps that pose a risk to their users, removing apps embedded with malware, and taking data leaks much more seriously.

Each of these outcomes has a different likelihood of happening, but they would all negatively impact Clubillion’s revenue and business.

Advertisement

Advice from the Experts

Clubillion’s developers could have easily avoided this leak if they had taken some basic security measures to protect the database. These include, but are not limited to:

  1. Securing their servers.
  2. Implementing proper access rules.
  3. Never leaving a system that doesn’t require authentication open to the internet.

Any company can replicate the same steps, no matter its size.

For a more in-depth guide on how to protect your business, check out our guide to securing your website and online database from hackers.

For Clubillion Users

If you play on Clubillion and are concerned about how this breach might impact you, contact the app’s developers directly to find out what steps it’s taking to protect your data.

To learn about data vulnerabilities in general, read our complete guide to online privacy.

It shows you the many ways cybercriminals target internet users, and the steps you can take to stay safe.

Advertisement

How and Why We Discovered the Breach

The vpnMentor research team discovered the breach in Clubillion’s database as part of a huge web mapping project. Our researchers use port scanning to examine particular IP blocks and test different systems for weaknesses or vulnerabilities. They examine each weakness for any data being leaked.

Our team was able to access this database because it was completely unsecured and unencrypted. 

Whenever we find a data breach, we use expert techniques to verify the owner of the database, usually a commercial company.

As ethical hackers, we’re obliged to inform a company when we discover flaws in their online security. We reached out to Clubillion’s developers, not only to let them know about the vulnerability but also to suggest ways in which they could make their system secure.

These ethics also mean we carry a responsibility to the public. Clubillion users must be aware of a data breach that exposes so much of their sensitive data.

Advertisement

The purpose of this web mapping project is to help make the internet safer for all users.

 

Source

Continue Reading
Advertisement

Latest News

SIS and Premier Greyhound Racing reveal improved greyhound race time schedule

Published

on

sis-and-premier-greyhound-racing-reveal-improved-greyhound-race-time-schedule
Reading Time: 2 minutes

Sports Information Services (SIS), the leading multi-content supplier of 24/7 live betting services, and Premier Greyhound Racing (PGR), the media rights company supplier of greyhound racing to the betting industry and direct to viewers, have collaborated to offer a revised race time schedule starting from 20 May.

Designed to protect the long-term future of UK greyhound racing, the new schedule will see morning fixtures start slightly later – moving from 10.47 to 11.01 and 10.54 to 11.09. Additionally, there will also be a slightly later start time for some evening fixtures aimed at a retail audience, with the first evening fixture now starting at 18.08.

Commenting on the improved schedule, Terry Mahoney, Head of Business Development at ARC, said: “The new race times will help make it easier for customers to navigate busy racing schedules as well as improving operations trackside. We will continue to listen, monitor, and adapt schedules where and when needed as we move forward to deliver the best service possible for betting operators as well as punters.”

Paul Witten, Managing Director at SIS, added: “We are passionate about delivering a greyhound racing service that benefits all of the sport’s stakeholders. Together with Premier Greyhound Raxing, we have introduced a revised racing schedule that benefits operators and their customers.

Advertisement

“Our approach to greyhound racing is grounded in sustainability and flexibility. This collaboration with fellow service providers allows everyone to enjoy all the high-quality action produced on a daily basis from tracks across the UK and Ireland.”

SIS has long-term agreements in place with bet365, William Hill, Paddy Power and Betfred to deliver its greyhound content across UK and Irish retail and digital channels. SIS also promotes this content across dozens of leading international operators, as well as through SISRacing.tv.

PGR offers greyhound action, cards, video replays, results, news and info on greyhounds.attheraces.com, and regular live broadcasts on Sky Sports Racing. Premier Greyhound Racing is a joint venture between Arena Racing (ARC) and Entain, the global sports betting, gaming and interactive entertainment group. Between them, the two companies own nine of the 20 licensed British greyhound tracks and ARC manage the media rights for five independent tracks.

The post SIS and Premier Greyhound Racing reveal improved greyhound race time schedule appeared first on European Gaming Industry News.

Advertisement
Continue Reading

Latest News

The Importance of Data Quality Review Checks in the Gaming Industry

Published

on

the-importance-of-data-quality-review-checks-in-the-gaming-industry
Reading Time: 3 minutes

 

By Lorenzo Nardini, Head of Technical Compliance and Maths Services

In the dynamic world of online gaming, data plays a pivotal role. Databases containing personal and financial information, often referred to as “Safe” databases, serve as the backbone of any gaming platform.

In this short article, I focus on control databases (CDBs) – that is how Safe databases are referred to in the Dutch landscape – and why it is important to ensure their completeness, accuracy, and consistency through continuous data quality review. In any case, the topics here covered apply to most regulated markets.

Advertisement

Control databases contain critical information related to player accounts, financial transactions, game rules, and security protocols. Essentially, they ensure the smooth functioning of the entire gaming ecosystem. It is no wonder that the Dutch regulator (KSA) enforces specific technical regulations on them and often perform audits on these systems that can result also in fines in cases errors are detected.

Data quality review checks

Data quality review checks play a pivotal role in maintaining the integrity of control databases, ensuring continuous compliance. Here are some key reasons why they are essential:

  1. Accuracy and Consistency: Control databases handle vast amounts of data, including player profiles, game logs, and financial records. Ensuring accurate and consistent data is crucial for fair gameplay, financial transparency, and regulatory compliance.
  2. Player Experience: Imagine a player losing progress due to a database glitch or loss of connectivity. Such incidents can lead to frustration and loss of trust. Data quality checks ensure that the control database is correctly functional, and the information therein contained can be used to handle such incomplete games, enhancing the overall player experience.
  3. Regulatory Compliance: Gaming companies must adhere to strict regulations regarding data privacy, security, and fairness. Regular reviews ensure compliance with industry standards and legal requirements.

Most importantly, regular reviews can help gaming companies reducing the risk of an unsuccessful audit that could typically lead to a fine and negative PR.

Ideally, data quality reviews should be ongoing. Real-time monitoring is crucial for identifying issues promptly. Additionally, scheduled audits—monthly or quarterly—help catch any long-term discrepancies or trends.

Key areas of data quality reviews

Advertisement

When performing checks on the quality of CDBs, the following are the main areas to consider:

  1. Data Completeness: Ensure that all necessary fields are populated correctly. Missing or incomplete data can lead to errors downstream.
  2. Data Accuracy: Cross-check data against reliable sources. For example, player balances should match financial records.
  3. Data Consistency: Verify consistency across different databases and systems. Inconsistencies can cause confusion and operational inefficiencies.

Starting from the specific Dutch case and then expanding to other markets, here at ComplianceOne Group we have developed a data quality review service using our experience in dealing with this form of analysis. Leveraging feedback obtained directly from regulators, we created a testing procedure that performs the following:

  1. Tests on triggering reports from staging environment. We access the client’s staging environment with test accounts and perform actions that are aimed at triggering specific reports in the control database. We then check that these have been correctly generated and that they contain all necessary information, checking their accuracy against the back-office.
  2. Data quality tests on production environment. We download a large number of reports directly from production and run a battery of tests that we have designed and that is tailored specifically at checking completeness and consistency of the information contained in the control database.

All findings are promptly reported to the client and, if needed, we can assist with solving any issues found.

Conclusion

When I started being exposed to control databases, I understood that for many this is a very technical area and that maintaining this environment functioning correctly can be quite cumbersome. Nevertheless, a commitment to data quality is a necessary for ensuring continuous compliance of gaming platforms. If you are interested in running regular data quality reviews, or even just a one-time overall check, contact me and I will be happy to assist!

 

The post The Importance of Data Quality Review Checks in the Gaming Industry appeared first on European Gaming Industry News.

Advertisement
Continue Reading

Latest News

7777 gaming signs a strategic iLottery content deal with Scientific Games

Published

on

7777-gaming-signs-a-strategic-ilottery-content-deal-with-scientific-games
Reading Time: 2 minutes

 

7777 gaming, a leading provider of digital gaming solutions, has announced a significant strategic partnership with Scientific Games a global leader in retail and digital lottery games, technology, analytics and services, to deliver digital lottery games through the SG Content Hub Partner Program.

The SG Content Hub Partner Program is a unique platform and game content partnership program featuring an expanding, highly curated selection of iLottery games from best-in-class, game studios worldwide in a variety of play styles appealing to all player types in multiple languages, as well as access to select licensed properties from the largest licensed brands portfolio in the lottery industry. Scientific Games currently serves 150 lotteries in 50 countries.

 

Advertisement

Elena Shaterova, Chief Commercial Officer at 7777 gaming, expressed enthusiasm about the partnership: “Partnering with Scientific Games represents a significant milestone for 7777 gaming, solidifying our position as a global leader in digital lottery solutions. Through this collaboration, we are poised to deliver unparalleled gaming experiences to players worldwide, driving innovation and growth in the lottery industry.”

 

Steve Hickson, VP of Digital Games at Scientific Games commented: “We are delighted to welcome yet another top-class lottery game studio to the SG Content Hub Partner Program. The addition of 7777 gaming and their fantastic games aligns perfectly with our goal to make a variety of digital lottery content available to existing and new Scientific Games customers. Our SG Content Hub Partner Program is developing at pace as we continue to provide our customers with frictionless access to the very best content in the industry.”

The SG Content Hub Partner Program offers a one-stop solution for accessing multiple iLottery game studios, seamlessly integrating with a lottery’s existing gaming systems and iLottery technology. It streamlines operations, simplifies tech integrations, and enhances data analytics to drive game development and iLottery portfolio management.

7777 gaming is renowned for its ability to deliver high-quality iLottery games tailored to the unique requirements of different lotteries. The company ensures that its game content meets stringent government regulations and operators’ expectations for customization. With custom-made lottery concepts, 7777 gaming guarantees enhanced player satisfaction and fosters a deeper sense of connection and loyalty to the brand.

Advertisement

 

The post 7777 gaming signs a strategic iLottery content deal with Scientific Games appeared first on European Gaming Industry News.

Continue Reading

Trending

Get it on Google Play

Offering comprehensive coverage on all aspects of the gaming sector, our daily posts include online and land-based gaming, betting, esports, regulatory and compliance updates, and technological advancements. Regular features encompass daily news articles, press releases, exclusive interviews, and insightful event reports.

The platform also hosts industry-relevant webinars, and provides detailed reports, making it a one-stop resource for anyone seeking information about operators, suppliers, regulators, and professional services in the European gaming market. The portal's primary goal is to keep its extensive reader base updated on the latest happenings, trends, and developments within the gaming and gambling sector, with an emphasis on the European market while also covering pertinent global news. It's an indispensable resource for gaming professionals, operators, and enthusiasts alike.

Contact us: [email protected]

Editorial / PR Submissions: [email protected]

Copyright © 2015 - 2024 - Gaming News Room is part of HIPTHER Agency. Registered in Romania under Proshirt SRL, Company number: 2134306, EU VAT ID: RO21343605. Office address: Blvd. 1 Decembrie 1918 nr.5, Targu Mures, Romania