Connect with us
MARE BALTICUM Gaming & TECH Summit 2024

Latest News

Popular Gambling App Exposed Millions of Users in Massive Data Leak

Published

on

Reading Time: 5 minutes

 

Led by Noam Rotem and Ran Locar, vpnMentor’s research team discovered a data breach on casino gambling app Clubillion.

The breach originated in a technical database built on an Elasticsearch engine and was recording the daily activities of millions of Clubillion players around the world.

Aside from leaking activity on the app, the breached database also exposed private user information.

Advertisement

With this information publicly available, Clubillion’s users were vulnerable to fraud and various online attacks with potentially devastating results.

Company Profile

Clubillion is a free online casino game available for iOS and Android, offering players 30+ free slot games. While each app is listed under a different developer – Ouroboros on iOS and T7 Games on Android – these are most likely owned by the same company.

Both versions of Clubillion were released in 2019 and became instant hits. Each is now ranked the #1 ‘social slots’ casino app on Google Play and the App Store, with a 4.8 star on both.

Timeline of Discovery and Owner Reaction

Sometimes, the extent of a data breach and the owner of the database are obvious, and the issue quickly resolved. But rare are these times. Most often, we need days of investigation before we understand what’s at stake or who’s leaking the data.

Understanding a breach and its potential impact takes careful attention and time. We work hard to publish accurate and trustworthy reports, ensuring everybody who reads them understands their seriousness.

Advertisement

Some affected parties deny the facts, disregarding our research, or playing down its impact. So, we need to be thorough and make sure everything we find is correct and accurate.

In this case, the database was built on Elasticsearch and hosted on Amazon Web Services (AWS), with Clubillion’s name on its apps, and links to assets owned by the company.

Once Clubillion was confirmed as the owner of the database, we reached out to the developers. While awaiting a reply, we also contacted AWS with details of the leak. It was closed a few days later.

  • Date discovered: 19th March 2020
  • Date vendors contacted: 23rd March 2020
  • Date of contact with AWS: 31st March 2020
  • Date of Action: Approx. 5th April 2020

Example of Entries in the Database

Clubillion’s exposed database contained technical logs for millions of Clubillion users around the world, on both iOS and Android devices. Every time an individual player took any action on the app, a record was logged. Examples of records include:

  • “enter game”
  • “win”
  • “lose”
  • “update account”
  • “create account”

During our investigation of the database, new entries continued to appear continuously. We estimated an average of approximately 200 million records per day – and sometimes, considerably more.

In total, this amounted to over 50GB of exposed records in the database every single day.

Within many of these records, were various forms of user Personally Identifiable Information (PII) data, including:

Advertisement
  • IP addresses
  • Email addresses
  • Winnings
  • Private messages

This data breach was truly global, with millions of records originating from Clubillion’s daily users all over the world. The following list is just a sample of countries affected, along with the average number of daily users from each country:

  • USA – 10,000+
  • UK – 2,475+
  • France – 1,650+
  • Israel – 408+
  • Germany – 1,582+
  • Spain – 1,026+
  • Italy – 2,407+
  • Netherlands – 622+
  • Australia – 6,251+
  • Canada – 7,792+
  • Brazil – 3,859+
  • Sweden – 191+
  • Russia – 547+

Other countries affected included Uzbekistan, India, Poland, Romania, Vietnam, Lebanon, Indonesia, Philippines, Pakistan, Thailand, Austria, Hungry, and Latvia.

As you can see, on a single day, 10,000s of individual Clubillion players were exposed. Each one of these players could be targeted by malicious hackers for fraud and cyberattacks – along with millions more whose records were also contained in the database.

Data Breach Impact

Studies have shown that free gambling and gaming apps are especially prone to attacks and hacking from cybercriminals. They are routinely targeted for theft of private data and embedding malicious software on users’ devices.

Despite their popularity, gambling and casino apps often lack transparency, and it can be impossible to know what steps they’re taking to prevent cybercriminals successfully targeting their users.

One study of 23,000 free gambling apps found that: 3,200 posed a ‘moderate risk’ to users; 379 had known security vulnerabilities; 52 contained malicious software.

Any of these issues could be exploited to target app users in a wide range of frauds and cyberattacks, and Clubillion is no different.

Advertisement

With the exposed user PII and knowledge of their activity on the app, hackers could create elaborate schemes to defraud users. For example, some entries also included transaction errors for attempted card payments on Clubillion.

With the information in these transaction errors, hackers could target users with phishing campaigns, with the following aims:

  1. Trick them into providing their credit card details
  2. Trick them into providing additional PII to be used against them in further fraud
  3. Clicking a link that embeds malware, spyware, or ransomware onto their device.

If cybercriminals used Clubillion to embed malware or similar onto a user’s phone, they could potentially hack other apps, access files stored on the device, make calls, and send texts from the hacked device. They could even access a user’s phone contacts and steal the PII data of their friends and family.

Worse still, as people across the globe now find themselves under quarantine or self-isolation, as a result of the Coronavirus pandemic, the impact of a leak like this is potentially even more significant.

Clubillion stands to gain many new users, along with regular users playing more frequently. Hackers will be aware of this and looking for opportunities to exploit any vulnerabilities in the data security of such a massively popular app.

Had criminal hackers discovered Clubillion’s database, they could have targeted millions of people around the world, with devastating results.

Advertisement

Impact on Clubillion and it’s Developers

The most immediate risk for Clubillion is the loss of players. Data security is a growing concern for everyone these days, and this leak could turn many players off the app. Clubillion is not unique, and players have plenty of other choices for free gambling apps.

With fewer players, Clubillion will lose advertising revenue and reduced profits.

As many of Clubillion’s players reside within the EU, the app is under the jurisdiction of GDPR. The rules of GDPR also apply to apps, and Clubillion will need to take specific actions to ensure the regulatory body in charge doesn’t reprimand it.

Finally, Clubillion could also potentially be removed from Google Play and the App Store. Both Apple and Google are clamping down on apps that pose a risk to their users, removing apps embedded with malware, and taking data leaks much more seriously.

Each of these outcomes has a different likelihood of happening, but they would all negatively impact Clubillion’s revenue and business.

Advertisement

Advice from the Experts

Clubillion’s developers could have easily avoided this leak if they had taken some basic security measures to protect the database. These include, but are not limited to:

  1. Securing their servers.
  2. Implementing proper access rules.
  3. Never leaving a system that doesn’t require authentication open to the internet.

Any company can replicate the same steps, no matter its size.

For a more in-depth guide on how to protect your business, check out our guide to securing your website and online database from hackers.

For Clubillion Users

If you play on Clubillion and are concerned about how this breach might impact you, contact the app’s developers directly to find out what steps it’s taking to protect your data.

To learn about data vulnerabilities in general, read our complete guide to online privacy.

It shows you the many ways cybercriminals target internet users, and the steps you can take to stay safe.

Advertisement

How and Why We Discovered the Breach

The vpnMentor research team discovered the breach in Clubillion’s database as part of a huge web mapping project. Our researchers use port scanning to examine particular IP blocks and test different systems for weaknesses or vulnerabilities. They examine each weakness for any data being leaked.

Our team was able to access this database because it was completely unsecured and unencrypted. 

Whenever we find a data breach, we use expert techniques to verify the owner of the database, usually a commercial company.

As ethical hackers, we’re obliged to inform a company when we discover flaws in their online security. We reached out to Clubillion’s developers, not only to let them know about the vulnerability but also to suggest ways in which they could make their system secure.

These ethics also mean we carry a responsibility to the public. Clubillion users must be aware of a data breach that exposes so much of their sensitive data.

Advertisement

The purpose of this web mapping project is to help make the internet safer for all users.

 

Source

Continue Reading
Advertisement

Latest News

7777 gaming signs a strategic iLottery content deal with Scientific Games

Published

on

7777-gaming-signs-a-strategic-ilottery-content-deal-with-scientific-games
Reading Time: 2 minutes

 

7777 gaming, a leading provider of digital gaming solutions, has announced a significant strategic partnership with Scientific Games a global leader in retail and digital lottery games, technology, analytics and services, to deliver digital lottery games through the SG Content Hub Partner Program.

The SG Content Hub Partner Program is a unique platform and game content partnership program featuring an expanding, highly curated selection of iLottery games from best-in-class, game studios worldwide in a variety of play styles appealing to all player types in multiple languages, as well as access to select licensed properties from the largest licensed brands portfolio in the lottery industry. Scientific Games currently serves 150 lotteries in 50 countries.

 

Advertisement

Elena Shaterova, Chief Commercial Officer at 7777 gaming, expressed enthusiasm about the partnership: “Partnering with Scientific Games represents a significant milestone for 7777 gaming, solidifying our position as a global leader in digital lottery solutions. Through this collaboration, we are poised to deliver unparalleled gaming experiences to players worldwide, driving innovation and growth in the lottery industry.”

 

Steve Hickson, VP of Digital Games at Scientific Games commented: “We are delighted to welcome yet another top-class lottery game studio to the SG Content Hub Partner Program. The addition of 7777 gaming and their fantastic games aligns perfectly with our goal to make a variety of digital lottery content available to existing and new Scientific Games customers. Our SG Content Hub Partner Program is developing at pace as we continue to provide our customers with frictionless access to the very best content in the industry.”

The SG Content Hub Partner Program offers a one-stop solution for accessing multiple iLottery game studios, seamlessly integrating with a lottery’s existing gaming systems and iLottery technology. It streamlines operations, simplifies tech integrations, and enhances data analytics to drive game development and iLottery portfolio management.

7777 gaming is renowned for its ability to deliver high-quality iLottery games tailored to the unique requirements of different lotteries. The company ensures that its game content meets stringent government regulations and operators’ expectations for customization. With custom-made lottery concepts, 7777 gaming guarantees enhanced player satisfaction and fosters a deeper sense of connection and loyalty to the brand.

Advertisement

 

The post 7777 gaming signs a strategic iLottery content deal with Scientific Games appeared first on European Gaming Industry News.

Continue Reading

Latest News

Atlas-IAC’s CEO Maxim Slobodyanyuk Talks Winning Strategies & Vision for Future Growth in the iGaming Sector

Published

on

atlas-iac’s-ceo-maxim-slobodyanyuk-talks-winning-strategies-&-vision-for-future-growth-in-the-igaming-sector
Reading Time: 3 minutes

 

Atlas-IAC, a Next-Generation iGaming platform, has been recognized as the Best Sports Betting Provider Of The Year and Rising Star In Sports Betting Technology  at the Prague Gaming & Tech Awards 2024. The GamingTECH Awards annually  determine industry excellence in Central and Eastern Europe. Maxim Slobodyanyuk, CEO of Atlas-IAC, tells about insights into Atlas-IAC’s innovative solutions that are reshaping the iGaming landscape and the core principles of partnership driving mutual evolution for both Atlas-IAC and its esteemed operators.

 

Congratulations on winning “Best Sports Betting Provider Of The Year” and “Rising Star In Sports Betting Technology” at the GamingTECH CEE Awards 2024! How does Atlas-IAC feel about receiving such prestigious recognition?

We take pride in being acknowledged as the best sports betting provider and the rising star in sports betting technology across Central and Eastern Europe. At the heart of our success lies a team of exceptional visionaries, developers, and business analytics  striving to elevate the industry to new heights of technological innovation and responsible gaming practices.

Advertisement

I’d like to thank our great partners for choosing Atlas-IAC as their technology provider, and for subscribing to our core business principle — to evolve and grow together. Our win is our partners’ win as well.

To be the best sports betting provider entails a weighty responsibility, one we approach with unwavering dedication. These awards serve as a validation of our unwavering commitment to excellence and as a catalyst for renewed determination to shape the future of sports betting technology. We are grateful for recognition and remain resolutely committed to charting new horizons of success alongside our valued partners.

 

Could you provide insights into the strategies that drove Atlas-IAC’s success in the iGaming industry?

At Atlas-IAC, our success strategy revolves around building strong partnerships and establishing a notable presence in the competitive global entertainment technology market. We prioritize automation, which gives us an edge in emerging markets and allows us to onboard partners quickly and streamline operations.

Continuously improving our platform to offer a seamless Sportsbook API experience is a priority. Our aim is to deliver fast performance, smooth betting experiences, real-time risk management, advanced anti-fraud measures, and scalable solutions for partners worldwide.

Advertisement

Staying up-to-date, enhancing our product, analyzing market and partner needs, and proactively responding to them are essential. Being the top technological partner is a strategy that consistently works for us.

 

How does Atlas-IAC’s in-house developed Sportsbook differentiate itself from competitors?

Atlas-IAC’s in-house developed Sportsbook sets us apart because we have full control over its features and can make rapid improvements. Features like Personal Odds Boost and Clever Margin allow for customized experiences tailored to our partners’ needs. We focus on personalization, ensuring the product aligns perfectly with each operator’s requirements. With a skilled team dedicated to our partners’ needs, we can promptly address requests and deliver effective solutions.

 

Atlas-IAC offers one of the most automated Sportsbook available in the market. How does automation enhance the experience for both operators and users?

Our fully automated Sportsbook API is efficient and user-friendly, enhancing engagement and retention. It’s equipped to handle high demand periods effectively and offers tools for precise betting management and reliable results. We can swiftly develop and integrate custom modules for partners, giving us a competitive edge. We prioritize meeting partners’ needs while delivering enjoyable experiences for players, fostering mutual benefit for all involved.

Advertisement

 

What specific features or tools have been well-received by operators in the iGaming industry?

In the realm of iGaming, Atlas-IAC has garnered recognition for its remarkable adaptability and keen responsiveness to the requirements of our partners. Understanding the distinctive needs of each operator, we have crafted a tailored approach to ensure effective solutions.

One specific example of our successful tools is our Cashback feature, which serves as a versatile tool for promoting sporting events and enhancing player entertainment. This feature offers customizable settings based on specific sports, events, odds criteria, and frequency. With such flexibility, operators can effectively incentivize participation and elevate excitement levels among players.

In essence, the suite of features and tools offered by Atlas-IAC not only addresses the diverse needs of operators but also fuels engagement and growth within the iGaming industry.

 

Advertisement

What are Atlas-IAC’s goals for continued innovation and growth in the iGaming sector?

Looking ahead, our primary aim is to continually push the boundaries of innovation while delivering outstanding value to our partners. We remain steadfast in our commitment to leading the charge in the iGaming sector, fostering sustainable growth, and championing responsible gaming practices. Our strategy revolves around staying agile, adapting to emerging trends, and catering to the unique needs of operators worldwide.

The evolving sports betting landscape of 2024 underscores the critical importance of adaptability and innovation. Operators must navigate this dynamic environment marked by technological advancements and regulatory shifts, and Atlas-IAC stands ready to assist them in this endeavor.

In terms of market focus, we are meticulously evaluating opportunities in LATAM, Eastern Europe, South-East Asia, and Africa. These regions offer significant growth potential, and our tailored strategy is geared towards effectively meeting the unique demands of these diverse markets.

The post Atlas-IAC’s CEO Maxim Slobodyanyuk Talks Winning Strategies & Vision for Future Growth in the iGaming Sector appeared first on European Gaming Industry News.

Advertisement
Continue Reading

Latest News

How to avoid failing at affiliate marketing in 2024?

Published

on

how-to-avoid-failing-at-affiliate-marketing-in-2024?

Reading Time: 4 minutes

The evolving landscape of affiliate marketing within the iGaming ecosystem presents both opportunities and challenges due to regulatory shifts. Adapting to these changes is crucial to navigate the dynamic environment effectively. Slotegrator experts exploring strategies to avoid pitfalls globally and adopting adaptable approaches can optimize affiliate marketing amidst evolving regulations.

The iGaming industry has had to focus on a number of changes in the area of affiliate marketing –  as a result of regulatory and advertising changes.

Beyond that, it’s important to keep in mind another important key initiatives that include key components of a successful affiliate program:

  • The quality of the content the affiliate creates.
  • Regulations the affiliate or affiliate program might be subject to.
  • This is especially important if the affiliate expects a commission for every sign-up. If the affiliate is getting paid for every player they send your way, the players need to stay for a while for it to be worth it.
  • An ongoing analysis of the size and quality of traffic the affiliate is delivering you.

To know more about these points you can read an instruction from the Slotegrator Academy by link.

The changes have not only affected the regulatory environment of the iGaming industry, but also affiliate marketing as a result of the general changes. What is important to look out for?

Advertisement


Slotegrator shares some regional specifics of affiliate marketing:

  • Asia is a diverse and dynamic region for affiliate marketing in the iGaming industry. Affiliates operating in Asia have to navigate complex regulatory conditions and varying cultural attitudes. Marketing managers have to employ strategies that prioritize mobile channelization, collaboration with opinion leaders, and compliance with local laws — all of which are essential to success.
  • Affiliate marketing in Africa is still in its early stages but is already showing significant potential. With the increasing availability of the internet and the spread of smartphones, the continent is opening up opportunities for affiliates to reach a fast-growing market. However, factors such as regulatory uncertainty, payment processing difficulties, and the cultural diversity of the region need to be taken into account.
  • In Latin America working with local affiliates who have a deep understanding of the regional market helps to better customize marketing campaigns and achieve higher conversion rates. Given the strict regulation of gambling in some Latin American countries, it is important to comply with local laws and advertising restrictions to avoid negative consequences.
  • Affiliate marketing in Europe is a dynamic and competitive landscape where effective strategies and a professional approach can ensure significant business success and growth in the iGaming sector. One of the important parts of affiliate marketing in Europe is the use of a variety of channels to build audiences. It helps to diversify and increase the flow of traffic to the partner’s site, which helps to increase conversion rates. Careful research of each country’s rules and restrictions is needed regarding the advertising and promotion of gambling.

Alyce Fabel from CasinoRIX, Slotegrator’s media partner, summarizes key aspects for affiliate companies to concentrate on.“As each year passes, affiliates must strive to improve and keep pace with the market. Competition is growing, regulations are evolving, and that brings changes to many regions. We can highlight five key points for affiliate companies to focus on:

  • Continuously search for and acquire new traffic channels. It’s crucial not to focus only on one channel; diversification is necessary. This has been particularly evident in the past year, with significant changes and updates in SEO and mobile traffic (iOS/Android applications).
  • Ensure content quality. As AI tools continue to advance, it’s essential not only to learn to apply them in work but also to differentiate content written by humans from AI-generated content (especially crucial for SEO projects).
  • Configure deep analytics. Constantly work on improving traffic quality and understand where to make enhancements. The standards for traffic quality are rising.
  • Provide added value. It’s time to start developing the product aspect as well, thinking not only as an affiliate but also about providing customers with additional value. This will also help in achieving higher-quality marketing.”

Cultivate relationships with partners. Build strong and lasting relationships, stay informed about all industry changes and news, and keep up with technologies and innovations. This is crucial for achieving high results.

And some words about the affiliate marketing trends as a compass to guide development efforts in this area in the right direction. Khoren Ispiryan, sales manager at Slotegrator, and the speaker of the latest Prague Gaming & TECH Summit ‘24, shares some insights:

  • “The best thing is to include real people in the affiliate marketing. To create an environment where bloggers, streamers and influencers will make a bigger impact on the end user behavior.
  • In 2024, gambling companies will continue to partner with influencers and other internet celebrities. These partnerships will be increasingly effective methods of attracting new audiences, promoting products, and increasing brand awareness.
  • Loyalty programs and other ways of enhancing the user experience will also be essential for the promotion of gambling websites.
  • The development of partner relationship management software will be a major priority. It will help improve usability for affiliate partners and enable better communication between companies and affiliates. For instance, Partnergrator from Slotegrator offers a solution for online gambling platform operators who face difficulties in tracking their affiliate program data. This innovative solution provides the ability to manage and analyze affiliate programs in real-time, using analytics to simplify the decision-making process.”

The post How to avoid failing at affiliate marketing in 2024? appeared first on European Gaming Industry News.

Continue Reading

Trending

Get it on Google Play

Offering comprehensive coverage on all aspects of the gaming sector, our daily posts include online and land-based gaming, betting, esports, regulatory and compliance updates, and technological advancements. Regular features encompass daily news articles, press releases, exclusive interviews, and insightful event reports.

The platform also hosts industry-relevant webinars, and provides detailed reports, making it a one-stop resource for anyone seeking information about operators, suppliers, regulators, and professional services in the European gaming market. The portal's primary goal is to keep its extensive reader base updated on the latest happenings, trends, and developments within the gaming and gambling sector, with an emphasis on the European market while also covering pertinent global news. It's an indispensable resource for gaming professionals, operators, and enthusiasts alike.

Contact us: [email protected]

Editorial / PR Submissions: [email protected]

Copyright © 2015 - 2024 - Gaming News Room is part of HIPTHER Agency. Registered in Romania under Proshirt SRL, Company number: 2134306, EU VAT ID: RO21343605. Office address: Blvd. 1 Decembrie 1918 nr.5, Targu Mures, Romania