Connect with us

Latest News

Popular Gambling App Exposed Millions of Users in Massive Data Leak

Published

on

Reading Time: 5 minutes

 

Led by Noam Rotem and Ran Locar, vpnMentor’s research team discovered a data breach on casino gambling app Clubillion.

The breach originated in a technical database built on an Elasticsearch engine and was recording the daily activities of millions of Clubillion players around the world.

Aside from leaking activity on the app, the breached database also exposed private user information.

Advertisement
Prague Gaming & TECH Summit 2025 (25-26 March)

With this information publicly available, Clubillion’s users were vulnerable to fraud and various online attacks with potentially devastating results.

Company Profile

Clubillion is a free online casino game available for iOS and Android, offering players 30+ free slot games. While each app is listed under a different developer – Ouroboros on iOS and T7 Games on Android – these are most likely owned by the same company.

Both versions of Clubillion were released in 2019 and became instant hits. Each is now ranked the #1 ‘social slots’ casino app on Google Play and the App Store, with a 4.8 star on both.

Timeline of Discovery and Owner Reaction

Sometimes, the extent of a data breach and the owner of the database are obvious, and the issue quickly resolved. But rare are these times. Most often, we need days of investigation before we understand what’s at stake or who’s leaking the data.

Understanding a breach and its potential impact takes careful attention and time. We work hard to publish accurate and trustworthy reports, ensuring everybody who reads them understands their seriousness.

Advertisement
Prague Gaming & TECH Summit 2025 (25-26 March)

Some affected parties deny the facts, disregarding our research, or playing down its impact. So, we need to be thorough and make sure everything we find is correct and accurate.

In this case, the database was built on Elasticsearch and hosted on Amazon Web Services (AWS), with Clubillion’s name on its apps, and links to assets owned by the company.

Once Clubillion was confirmed as the owner of the database, we reached out to the developers. While awaiting a reply, we also contacted AWS with details of the leak. It was closed a few days later.

  • Date discovered: 19th March 2020
  • Date vendors contacted: 23rd March 2020
  • Date of contact with AWS: 31st March 2020
  • Date of Action: Approx. 5th April 2020

Example of Entries in the Database

Clubillion’s exposed database contained technical logs for millions of Clubillion users around the world, on both iOS and Android devices. Every time an individual player took any action on the app, a record was logged. Examples of records include:

  • “enter game”
  • “win”
  • “lose”
  • “update account”
  • “create account”

During our investigation of the database, new entries continued to appear continuously. We estimated an average of approximately 200 million records per day – and sometimes, considerably more.

In total, this amounted to over 50GB of exposed records in the database every single day.

Within many of these records, were various forms of user Personally Identifiable Information (PII) data, including:

Advertisement
Prague Gaming & TECH Summit 2025 (25-26 March)
  • IP addresses
  • Email addresses
  • Winnings
  • Private messages

This data breach was truly global, with millions of records originating from Clubillion’s daily users all over the world. The following list is just a sample of countries affected, along with the average number of daily users from each country:

  • USA – 10,000+
  • UK – 2,475+
  • France – 1,650+
  • Israel – 408+
  • Germany – 1,582+
  • Spain – 1,026+
  • Italy – 2,407+
  • Netherlands – 622+
  • Australia – 6,251+
  • Canada – 7,792+
  • Brazil – 3,859+
  • Sweden – 191+
  • Russia – 547+

Other countries affected included Uzbekistan, India, Poland, Romania, Vietnam, Lebanon, Indonesia, Philippines, Pakistan, Thailand, Austria, Hungry, and Latvia.

As you can see, on a single day, 10,000s of individual Clubillion players were exposed. Each one of these players could be targeted by malicious hackers for fraud and cyberattacks – along with millions more whose records were also contained in the database.

Data Breach Impact

Studies have shown that free gambling and gaming apps are especially prone to attacks and hacking from cybercriminals. They are routinely targeted for theft of private data and embedding malicious software on users’ devices.

Despite their popularity, gambling and casino apps often lack transparency, and it can be impossible to know what steps they’re taking to prevent cybercriminals successfully targeting their users.

One study of 23,000 free gambling apps found that: 3,200 posed a ‘moderate risk’ to users; 379 had known security vulnerabilities; 52 contained malicious software.

Any of these issues could be exploited to target app users in a wide range of frauds and cyberattacks, and Clubillion is no different.

Advertisement
Prague Gaming & TECH Summit 2025 (25-26 March)

With the exposed user PII and knowledge of their activity on the app, hackers could create elaborate schemes to defraud users. For example, some entries also included transaction errors for attempted card payments on Clubillion.

With the information in these transaction errors, hackers could target users with phishing campaigns, with the following aims:

  1. Trick them into providing their credit card details
  2. Trick them into providing additional PII to be used against them in further fraud
  3. Clicking a link that embeds malware, spyware, or ransomware onto their device.

If cybercriminals used Clubillion to embed malware or similar onto a user’s phone, they could potentially hack other apps, access files stored on the device, make calls, and send texts from the hacked device. They could even access a user’s phone contacts and steal the PII data of their friends and family.

Worse still, as people across the globe now find themselves under quarantine or self-isolation, as a result of the Coronavirus pandemic, the impact of a leak like this is potentially even more significant.

Clubillion stands to gain many new users, along with regular users playing more frequently. Hackers will be aware of this and looking for opportunities to exploit any vulnerabilities in the data security of such a massively popular app.

Had criminal hackers discovered Clubillion’s database, they could have targeted millions of people around the world, with devastating results.

Advertisement
Prague Gaming & TECH Summit 2025 (25-26 March)

Impact on Clubillion and it’s Developers

The most immediate risk for Clubillion is the loss of players. Data security is a growing concern for everyone these days, and this leak could turn many players off the app. Clubillion is not unique, and players have plenty of other choices for free gambling apps.

With fewer players, Clubillion will lose advertising revenue and reduced profits.

As many of Clubillion’s players reside within the EU, the app is under the jurisdiction of GDPR. The rules of GDPR also apply to apps, and Clubillion will need to take specific actions to ensure the regulatory body in charge doesn’t reprimand it.

Finally, Clubillion could also potentially be removed from Google Play and the App Store. Both Apple and Google are clamping down on apps that pose a risk to their users, removing apps embedded with malware, and taking data leaks much more seriously.

Each of these outcomes has a different likelihood of happening, but they would all negatively impact Clubillion’s revenue and business.

Advertisement
Prague Gaming & TECH Summit 2025 (25-26 March)

Advice from the Experts

Clubillion’s developers could have easily avoided this leak if they had taken some basic security measures to protect the database. These include, but are not limited to:

  1. Securing their servers.
  2. Implementing proper access rules.
  3. Never leaving a system that doesn’t require authentication open to the internet.

Any company can replicate the same steps, no matter its size.

For a more in-depth guide on how to protect your business, check out our guide to securing your website and online database from hackers.

For Clubillion Users

If you play on Clubillion and are concerned about how this breach might impact you, contact the app’s developers directly to find out what steps it’s taking to protect your data.

To learn about data vulnerabilities in general, read our complete guide to online privacy.

It shows you the many ways cybercriminals target internet users, and the steps you can take to stay safe.

Advertisement
Prague Gaming & TECH Summit 2025 (25-26 March)

How and Why We Discovered the Breach

The vpnMentor research team discovered the breach in Clubillion’s database as part of a huge web mapping project. Our researchers use port scanning to examine particular IP blocks and test different systems for weaknesses or vulnerabilities. They examine each weakness for any data being leaked.

Our team was able to access this database because it was completely unsecured and unencrypted. 

Whenever we find a data breach, we use expert techniques to verify the owner of the database, usually a commercial company.

As ethical hackers, we’re obliged to inform a company when we discover flaws in their online security. We reached out to Clubillion’s developers, not only to let them know about the vulnerability but also to suggest ways in which they could make their system secure.

These ethics also mean we carry a responsibility to the public. Clubillion users must be aware of a data breach that exposes so much of their sensitive data.

Advertisement
Prague Gaming & TECH Summit 2025 (25-26 March)

The purpose of this web mapping project is to help make the internet safer for all users.

 

Source

Continue Reading
Advertisement

Latest News

Game On! Win Acer’s New RTX 50 Series Laptop + PC Game Pass

Published

on

Reading Time: 3 minutes

 

Acer UK Levels Up the Game: Win a Brand-New NVIDIA GeForce RTX 50 Series Gaming Laptop and Unleash Hundreds of Titles with Included PC Game Pass!

Acer UK is thrilled to announce an electrifying competition giving gamers the chance to win a state-of-the-art Predator or Nitro laptop, powered by the brand-new NVIDIA GeForce RTX 50 Series GPUs! This grand giveaway celebrates the highly anticipated arrival of Acer’s latest gaming powerhouses and highlights the incredible value of PC Game Pass, now included with all new Nitro and Predator devices.

Enter the Competition Here: gleam.io/PQDpw/50-series-laptop-and-pc-game-pass-competition

The gaming landscape is constantly evolving, and Acer is at the forefront, delivering cutting-edge technology designed to immerse players in unparalleled virtual worlds. The new Predator Helios Neo 16 AI laptop, featuring the formidable NVIDIA GeForce RTX 50 Series GPUs, is now available at leading retailers including Amazon, Box, and Currys. For those seeking even more power, Acer’s official store is now stocking models with the groundbreaking RTX 5070 Ti and RTX 5080, offering next-generation performance and AI capabilities for the most demanding games and creative tasks.

Advertisement
Prague Gaming & TECH Summit 2025 (25-26 March)

But the excitement doesn’t stop there. Every new Nitro and Predator device now comes with PC Game Pass included, ensuring that gamers have immediate access to a vast library of hundreds of high-quality titles from the moment they unbox their new machine. No more waiting, no more separate purchases – just plug in and play!

To amplify the buzz, this competition will be supported by renowned gaming influencers Two Angry Gamers and Frankie Ward. Their extensive reach and passionate communities will help spread the word, giving more gamers the chance to win and experience Acer’s cutting-edge hardware paired with an incredible game library.

“We are incredibly excited to bring the power of the NVIDIA GeForce RTX 50 Series to our Predator and Nitro laptop lines,” says Mike Newson, Gaming Notebook Business Manager at Acer UK. “These new machines, especially the Predator Helios 18 AI and the Predator Triton 14 AI, represent a significant leap in gaming performance and AI integration. By bundling PC Game Pass and collaborating with beloved gaming personalities like Two Angry Gamers and Frankie Ward, we’re not just offering powerful hardware; we’re providing an instant gateway to an endless world of gaming entertainment and ensuring our message reaches the heart of the gaming community. It’s about delivering the complete, immersive experience our users deserve.”

PC Game Pass: Your Ultimate Gaming Library Just Got Bigger!

Microsoft’s PC Game Pass continues to grow, offering an incredible selection of games for every taste. Recent exciting additions that gamers can dive into include:

Advertisement
Prague Gaming & TECH Summit 2025 (25-26 March)
  • FBC: Firebreak – A cooperative first-person shooter available day one on Game Pass!
  • Rematch – A thrilling third-person, team-based football game.
  • Warcraft I: Remastered, Warcraft II: Remastered, and Warcraft III: Reforged – Relive the epic beginnings of the legendary Warcraft universe.
  • Call of Duty: WWII – Experience intense historical combat.
  • Looking ahead, July brings even more to the service with Little Nightmares II and Rise of the Tomb Raider returning to the library.

 

With new titles added regularly, PC Game Pass ensures there’s always something fresh and exciting to explore on your new Acer gaming laptop.

Don’t miss your chance to win the ultimate gaming upgrade! Enter the competition today and prepare to experience gaming like never before with Acer’s new NVIDIA GeForce RTX 50 Series laptops and PC Game Pass.

Availability: The new Predator Helios Neo 16 AI laptop with NVIDIA GeForce RTX 50 Series is available now at Amazon, Box, and Currys. Models featuring the RTX 5070 Ti and RTX 5080 are available directly from the Acer Store.

Social Media: #Acer #Predator #Nitro #RTX50Series #PCGamePass #GamingLaptop #Competition #Giveaway #TwoAngryGamers #FrankieWard

 

Advertisement
Prague Gaming & TECH Summit 2025 (25-26 March)

The post Game On! Win Acer’s New RTX 50 Series Laptop + PC Game Pass appeared first on European Gaming Industry News.

Continue Reading

Latest News

iGB L!VE confirm London iGaming Week program

Published

on

Reading Time: 2 minutes

 

Clarion Gaming has announced details of London iGaming Week,  a program of immersive curated events, seminars and parties centred around iGB L!VE and taking place at iconic London venues.

Confirming the programme, Naomi Barton, Global Portfolio Director responsible for iGB L!VE said: “London iGaming Week is an amazing opportunity for the global iGaming industry to come together for a week of connection, innovation, and celebration.

“Running 1 July – 4 July it features social events such as the iGB Affiliate Awards, the EGR B2B Awards, Welcome Drinks in Canary Wharf, and the Legends by Fire and ICE celebration.

“It also includes unique opportunities to network and learn at the iGB Start-Up Accelerator, the Affiliate and Operator Mixer and Technology in Gaming, the inaugural conference for senior technology professionals sponsored by Pretty Technical on Tuesday 1 July.

Advertisement
Prague Gaming & TECH Summit 2025 (25-26 March)

She added: “An initiative that we are extremely excited about is our deeper partnership with LatAm Media Group which will see us stage the first ever London LMG Futbol Experience. Taking place on Friday 4th July, the live-streamed 6-a-side football tournament will be played on a state-of-the-art 5G pitch with games officiated by fully qualified referees.

“Delivering a mixture of competition and camaraderie it’s a fantastic milestone which will build on iGB L!VE’s reputation for running the most popular business, networking and social iGaming events of the year.”

London iGaming Week represents a high profile addition to what will be the biggest edition of iGB L!VE  on record. The first show to take place in London following its relocation from Amsterdam it will provide attendees with access to over 22,000sqm of product innovation and inspiration.

Connecting igaming operators, affiliates, tech vendors and game providers,  iGB L!VE will welcome a projected 15,000 iGaming and affiliate pioneers helping businesses throughout the ecosystem to navigate the iGaming landscape, provide networking opportunities, showcase cutting-edge innovations and share crucial market knowledge.

For more information and to register for iGB L!VE, 2 – 3 JULY 2025, ExCeL London: igblive.com

Advertisement
Prague Gaming & TECH Summit 2025 (25-26 March)

 

The post iGB L!VE confirm London iGaming Week program appeared first on European Gaming Industry News.

Continue Reading

Latest News

Female Protea Team for the Counter Strike 2 esports title to do battle against Namibia – AEC25

Published

on

Female Protea Team for the Counter Strike 2 esports title to do battle against Namibia - AEC25
Reading Time: < 1 minute

 

Mind Sports South Africa’s Protea Female CS2 team, led by captain Jess Greeff and featuring Avonique van Rooyen,  dominated IESF’s AEC24, and emerged undefeated, and punched their ticket to the world stage. The female Protea Team for the Counter Strike 2 Esports Title are trailblazers in female esports and are already making their mark internationally.

To qualify for IESF’s World Esports Championships 2025 (WEC25), South Africa’s Female Protea Team for the Counter Strike 2 Esports Title will be taking on Namibia at15H00 on 21 June 2025.

South Africa’s Female Protea Team for the Counter Strike 2 Esports Title has never lost to Namibia, and both MSSA and the team are confident that the result will be the same as all previous encounters.

The team has shown a few changes from 2024. Jessica Greeff remains the captain, and Avonique van Rooyen and Megan van der Westhuizen too stay on the team with their vast international experience. The two new additions are Kiera McCullum and Kalee Ludick who further add to the team.

Advertisement
Prague Gaming & TECH Summit 2025 (25-26 March)

MSSA is of the belief that the 2025 Female Protea Team for the Counter Strike 2 Esports Title is the strongest female Counter Strike 2 team to ever represent South Africa.

The full team to represent South Africa at15H00 on 21 June 2025 is:

Name Club Nick Province
Jessica Eleez Greeff (Capt.) ZAG Academy heartjess KwaZulu Natal
Avonique van Rooyen ZAG Academy avo Gauteng
Kiera McCallum ZAG Academy queen KwaZulu Natal
Megan van der Westhuizen ZAG Academy m3gz Gauteng
Kalee Ludick ZAG Academy creative Gauteng

The post Female Protea Team for the Counter Strike 2 esports title to do battle against Namibia – AEC25 appeared first on European Gaming Industry News.

Continue Reading

Trending

Offering comprehensive coverage on all aspects of the gaming sector, our daily posts include online and land-based gaming, betting, esports, regulatory and compliance updates, and technological advancements. Regular features encompass daily news articles, press releases, exclusive interviews, and insightful event reports.

The platform also hosts industry-relevant webinars, and provides detailed reports, making it a one-stop resource for anyone seeking information about operators, suppliers, regulators, and professional services in the European gaming market. The portal's primary goal is to keep its extensive reader base updated on the latest happenings, trends, and developments within the gaming and gambling sector, with an emphasis on the European market while also covering pertinent global news. It's an indispensable resource for gaming professionals, operators, and enthusiasts alike.

Contact us: [email protected]

Editorial / PR Submissions: [email protected]

Copyright © 2015 - 2024 - Gaming News Room is part of HIPTHER Agency. Registered in Romania under Proshirt SRL, Company number: 2134306, EU VAT ID: RO21343605. Office address: Blvd. 1 Decembrie 1918 nr.5, Targu Mures, Romania