Industry News
MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability
Attackers could exploit the SQL Injection flaw to compromise the game’s database and steal user data.
The CyberNews.com Investigation team discovered a critical vulnerability in Street Mobster, a browser-based massively multiplayer online game created by Bulgarian development company BigMage Studios.
Street Mobster is a free to play, browser-based online game in the mafia empire genre where players manage a fictional criminal enterprise. The game boasts a 1.9+ million player base and stores a user record database that can be accessed by threat actors by committing an SQL Injection (SQLi) attack on the game’s website.
Other games created by BigMage Studios are also potentially vulnerable to the same type of attack, which means that there is a possibility that even more users might be at risk.
The records that can be compromised by exploiting the SQLi vulnerability in Street Mobster potentially include the players’ usernames, email addresses, and passwords, as well as other game-related data that is stored on the database.
Fortunately, after we reported the vulnerability to BigMage Studios, CERT Bulgaria, and the Bulgarian data protection authority, the issue has been fixed by the developers and the user database is no longer accessible to potential attackers.
What is SQL Injection?
First found back in 1998, SQLi is deemed by the Open Web Application Security Project (OWASP) as the number one web application security risk.
Even though this vulnerability is relatively easy to fix, researchers found that 8% of websites and web applications are still vulnerable to SQLi attacks in 2020. Which, from a security perspective, is inexcusable. So much so, in fact, that UK internet service provider TalkTalk was hit with a record £400,000 fine over succumbing to a cyberattack that involved SQLi.
The vulnerability works by injecting an unexpected payload (a piece of code) into the input box on the website or in its URL address. Instead of reading the text as part of the URL, the website’s server reads the attacker’s payload as code and then proceeds to execute the attacker’s command or output data that would otherwise be inaccessible to unauthorized parties. Attackers can exploit SQLi even further by uploading pieces of code or even malware to the vulnerable server.
The fact that Street Mobster is susceptible to SQLi attacks clearly shows the disappointing and dangerous neglect of basic security practices on the part of the developers at BigMage Studios.
How we found this vulnerability
Our security team identified an SQL Injection vulnerability on the Street Mobster website and were able to confirm the vulnerability by performing a simple command injection test on the website URL. The CyberNews team did not extract any data from the vulnerable Street Mobster database.
What’s the impact of the vulnerability?
The data in the vulnerable Street Mobster database can be used in a variety of ways against the players whose information was exposed:
By injecting malicious payloads on Street Mobster’s server, attackers can potentially gain access to said server, where they can install malware on the game’s website and cause harm to the visitors – from using the players’ devices to mine cryptocurrency to redirecting them to other malicious websites, installing malware, and more.
The 1.9 million user credentials stored on the database can net the attackers user email addresses and passwords, which they can potentially use for credential stuffing attacks to hack the players’ accounts on other gaming platforms like Steam or other online services.
Because Street Mobster is a free-to-play game that incorporates microtransactions, bad actors could also make a lot of money from selling hacked player accounts on gray market websites.
What to do if you’ve been affected?
If you have a Street Mobster account, make sure to change your password immediately and make it as complex as possible. If you’ve been using your Street Mobster password on any other websites or services, change that password as well. This will prevent potential attackers from accessing your accounts on these websites in case they try to reuse your password for credential stuffing attacks.
However, it’s ultimately up to BigMage Studios to completely secure your Street Mobster account against attacks like SQLi.
Disclosure and lack of communication from BigMage Studios
Following our vulnerability disclosure guidelines, we notified the BigMage Studios about the leak on August 31, 2020. However, we received no reply. Our follow-up emails were left unanswered as well.
We then reached out to CERT Bulgaria on September 11 in order to help secure the website. CERT contacted the BigMage Studios and informed the company about the misconfiguration.
Throughout the disclosure process, BigMage Studios stayed radio silent and refused to get in touch with CyberNews.com. Due to this reason, we also notified the Bulgarian data protection agency about the incident on October 9 in the hopes that the agency would be able to pressure the company into fixing the issue.
Eventually, however, BigMage Studios appear to have fixed the SLQi vulnerability on streetmobster.com, without informing either CyberNews.com or CERT Bulgaria about that fact.
Industry News
Amusnet Unveils Live Casino Strategy for 2025

Amusnet’s Live Casino 2025 strategy is to empower operators and differentiate their offerings with bespoke game environments, exciting gameplay and enhanced winning potential through special features and significant multipliers integrated into a variety of new releases planned for the year.
“2025 is shaping up to be an exciting year for our Live Casino division. We are introducing a diverse range of standout games that blend entertainment, technology, and interactivity in new ways,” said Marin Dimitrov, Head of Live Casino.
One of the key highlights is Showtime Roulette 500x, a fresh take on the classic roulette experience.
“What sets Showtime Roulette 500x apart is its unparalleled customization capabilities. Operators can fully tailor the game environment to reflect their brand identity,” Dimitrov said.
This fast-paced European roulette reinvents the classics, featuring a host who presents, entertains and spins the wheel for a seamless, engaging experience. Thanks to advanced chroma technology, operators can uniquely brand the game, showcasing their logo and any bespoke background theme they desire. This creates a tailored and immersive experience that feels truly one of a kind for each operator and their players. Further enhancing player engagement, the thrill of potential rewards is heightened through random multipliers on every spin, with payouts amplified up to 500x, creating a truly exceptional gaming experience that elevates player excitement and satisfaction.
Another highlight of the year is Extra Crown Deluxe Live, which is “inspired by our slot top performer Extra Crown and offers an engaging blend of traditional slot excitement and the dynamic atmosphere of live casinos,” added Dimitrov.
This innovative live slot game retains the charm of the original while introducing upgraded mechanics and captivating gameplay. A dynamic studio setting, complete with a charismatic host, fosters a strong sense of community, bringing players together 24/7 to share in the excitement of every spin. With ten traditional symbols across 5 reels and 20 paylines, players can enjoy this classic slot action enhanced by features like Free Spins (with retrigger potential), Respins with expanding symbols and lucrative Cash Prizes (multipliers). The innovative Dynamic Reel Prizes and real-time Statistics further enhance the immersive gaming experience, topped off by the ever-popular Jackpot Cards bonus game and the chance to multiply wins via the Gamble Feature.
The latest release is Football Thrill, a high-speed live casino game that brings the excitement of football to the casino floor with instant, easy-to-play mechanics. With its simple gameplay and dynamic pacing, this Live Casino addition is designed to captivate both sports fans and casino enthusiasts. Fast, intuitive and built for excitement, this Live Casino game is the perfect addition to any live casino looking to attract players who crave action-packed, easy-to-play games.
Amusnet’s Live Casino strategy for the upcoming year centers on delivering innovative and immersive gaming experiences. This will be achieved through the introduction of enhanced roulette variations featuring captivating gameshow elements and significantly larger multipliers, boosting excitement and winning potential. The company is set to expand its offerings with a diverse selection of card games that blend classic gameplay with modern twists to appeal to both traditional and modern players. Further enhancing player engagement will be the range of interactive wheel-based games and gameshows incorporating thrilling new mechanics.
The post Amusnet Unveils Live Casino Strategy for 2025 appeared first on European Gaming Industry News.
Industry News
Americas Online Gambling Market To Soon Eclipse Europe’s, Finds Vixio Forecasts

- Vixio forecasts that regulated online GGR in North and Latin America will grow at a compound annual rate of 3 percent from US$22.3bn in 2023 to US$56.3bn by 2028, drawing level with regulated European market.
Vixio, a leading provider of regulatory intelligence solutions, ahead of SBC Americas forecasts that the regulated online gambling market in the Americas to be worth US$32.5bn by 2026, compared to US$15.6bn in 2022, more than doubling in size in a period of four years. This growth rate is more than double the equivalent in Europe, with the European regulated online gambling market projected to be worth €37.3bn in 2026, up from just under €30bn in 2022.
By 2028, regulated online gambling markets in the U.S., Canada and Latin American countries are expected to generate US$56.3bn, drawing level with Europe or potentially surpassing it depending on currency fluctuations.
“Prior to 2018, the regulated online gambling market was highly euro-centric but legalization of sports betting and iGaming in various U.S. states as well as the major markets of Ontario and Brazil has coincided with stricter regulations in European countries that has restricted growth in a number of cases,” said James Kilsby, Chief Analyst, Vixio.
Vixio will be showcasing its data forecasting and regulatory intelligence solutions in more detail at the SBC Summit Americas 2026 at stand B175, with additional information in its Latin America Online Outlook report, available at vixio.com/research/latin-america-outlook-2025.
Vixio forecasts that regulated online GGR in North and Latin America will grow at a compound annual rate of 20.3 percent from US$22.3bn in 2023 to US$56.3bn by 2028, drawing level with regulated European market.
Providing further insight into one of the most closely watched online gambling markets globally, Kilsby, Vixio’s award-winning analyst, will be speaking during a panel session titled “Brazil 2025: A Surge in Licensing and Lessons So Far.” James was recently recognized as a Silver Stevie® Award Winner for Thought Leader of the Year in the 2025 American Business Awards®. The panel will take place on Wednesday, May 14, at 11 a.m. in conference room four.
In addition, Vixio has been shortlisted for Compliance Solution of the Year at the 2025 SBC Awards, which will be announced on the second day of the conference.
Visit us at stand B175 at SBC Summit Americas to learn more about how Vixio can help your business navigate the regulatory challenges of the gaming industry.
For more information, or to book a meeting with a Vixio representative at SBC Americas, visit vixio.com.
The post Americas Online Gambling Market To Soon Eclipse Europe’s, Finds Vixio Forecasts appeared first on European Gaming Industry News.
Industry News
CasinoWebScripts Enables Direct Provider Connections and Eliminates the Need for Aggregators

CasinoWebScripts, a leading provider of iGaming software solutions, is drawing attention to a powerful infrastructure model already in use by several clients — one that enables direct integration between online casino operators and game content providers. As the industry evolves, the company is now actively promoting this approach as a smarter alternative to traditional aggregation.
In the conventional model, aggregators act as intermediaries between content providers and casino platforms. While convenient, this structure often limits operators’ control over technical and commercial aspects, introduces latency and adds additional costs. CasinoWebScripts’ model removes the need for an aggregator by enabling operators to connect directly to game providers using a simplified and consistent integration method.
“Our goal is to simplify the way operators work with game studios, regardless of the type of casino they operate — whether it’s real-money, crypto, or social sweepstakes. By providing the tools and infrastructure for direct connections, we empower both sides to negotiate directly, optimize performance, and reduce third-party dependencies,” said Oscar Stevens, Head of Business Development at CasinoWebScripts.
Key Features of the Model Include:
• Direct Integration: Operators connect with game providers through a unified framework, without using an aggregator.
• Faster Load Times and Lower Latency: The streamlined architecture improves game performance and platform responsiveness.
• Independent Commercial Agreements: Operators and providers manage their own contracts, pricing and terms with full autonomy.
• Easy Expansion: The system supports the quick addition of new providers, with minimal integration overhead.
• Technology-Only Role: CasinoWebScripts supplies the infrastructure but does not interfere in commercial relationships.
This infrastructure shift reflects growing demand from operators looking for more autonomy in their business models. It also addresses concerns about transparency and technical bottlenecks that often arise with aggregator-based systems.
“Our platform is designed to serve those who want to scale fast and retain control over their operations. With this model, operators no longer have to compromise on performance or commercial independence,” added Stevens.
The post CasinoWebScripts Enables Direct Provider Connections and Eliminates the Need for Aggregators appeared first on European Gaming Industry News.
-
partnerships4 weeks ago
Octoplay accelerates UK and Irish growth with strategic BoyleSports partnership
-
Latin America4 weeks ago
SOFTSWISS Ignites Brazil with ‘Race Like a Legend’ Experience
-
Asia3 weeks ago
Jetapult Strengthens AI Expertise: Onboards Industry Leaders, Oz Silahtar and Dr. Arjun Jain
-
Balkans4 weeks ago
Playson tightens grip on Croatian market with landmark Hrvatska Lutrija deal
-
Africa4 weeks ago
INCENTIVE GAMES SIGNS EXCLUSIVE DISTRIBUTION DEAL FOR NORTH AMERICA, EUROPE, SOUTH AFRICA AND UK WITH LIGHT & WONDER
-
Press Releases3 weeks ago
Colour the world your way in Supa Crew by Swintt’s Elysium Studios
-
Press Releases2 weeks ago
Swintt stacks up a pyramid of wins in Egypt King Pearl Upgrade
-
Africa2 weeks ago
Association of Gaming Operators in Kenya Announces New Regulations