Connect with us
SOFTSWISS

Latest News

Popular Gambling App Exposed Millions of Users in Massive Data Leak

Published

on

Popular Gambling App Exposed Millions of Users in Massive Data Leak
Reading Time: 5 minutes

 

Led by Noam Rotem and Ran Locar, vpnMentor’s research team discovered a data breach on casino gambling app Clubillion.

The breach originated in a technical database built on an Elasticsearch engine and was recording the daily activities of millions of Clubillion players around the world.

Aside from leaking activity on the app, the breached database also exposed private user information.

With this information publicly available, Clubillion’s users were vulnerable to fraud and various online attacks with potentially devastating results.

Company Profile

Clubillion is a free online casino game available for iOS and Android, offering players 30+ free slot games. While each app is listed under a different developer – Ouroboros on iOS and T7 Games on Android – these are most likely owned by the same company.

Both versions of Clubillion were released in 2019 and became instant hits. Each is now ranked the #1 ‘social slots’ casino app on Google Play and the App Store, with a 4.8 star on both.

Timeline of Discovery and Owner Reaction

Sometimes, the extent of a data breach and the owner of the database are obvious, and the issue quickly resolved. But rare are these times. Most often, we need days of investigation before we understand what’s at stake or who’s leaking the data.

Understanding a breach and its potential impact takes careful attention and time. We work hard to publish accurate and trustworthy reports, ensuring everybody who reads them understands their seriousness.

Some affected parties deny the facts, disregarding our research, or playing down its impact. So, we need to be thorough and make sure everything we find is correct and accurate.

In this case, the database was built on Elasticsearch and hosted on Amazon Web Services (AWS), with Clubillion’s name on its apps, and links to assets owned by the company.

Once Clubillion was confirmed as the owner of the database, we reached out to the developers. While awaiting a reply, we also contacted AWS with details of the leak. It was closed a few days later.

  • Date discovered: 19th March 2020
  • Date vendors contacted: 23rd March 2020
  • Date of contact with AWS: 31st March 2020
  • Date of Action: Approx. 5th April 2020

Example of Entries in the Database

Clubillion’s exposed database contained technical logs for millions of Clubillion users around the world, on both iOS and Android devices. Every time an individual player took any action on the app, a record was logged. Examples of records include:

  • “enter game”
  • “win”
  • “lose”
  • “update account”
  • “create account”

During our investigation of the database, new entries continued to appear continuously. We estimated an average of approximately 200 million records per day – and sometimes, considerably more.

In total, this amounted to over 50GB of exposed records in the database every single day.

Within many of these records, were various forms of user Personally Identifiable Information (PII) data, including:

  • IP addresses
  • Email addresses
  • Winnings
  • Private messages

This data breach was truly global, with millions of records originating from Clubillion’s daily users all over the world. The following list is just a sample of countries affected, along with the average number of daily users from each country:

  • USA – 10,000+
  • UK – 2,475+
  • France – 1,650+
  • Israel – 408+
  • Germany – 1,582+
  • Spain – 1,026+
  • Italy – 2,407+
  • Netherlands – 622+
  • Australia – 6,251+
  • Canada – 7,792+
  • Brazil – 3,859+
  • Sweden – 191+
  • Russia – 547+

Other countries affected included Uzbekistan, India, Poland, Romania, Vietnam, Lebanon, Indonesia, Philippines, Pakistan, Thailand, Austria, Hungry, and Latvia.

As you can see, on a single day, 10,000s of individual Clubillion players were exposed. Each one of these players could be targeted by malicious hackers for fraud and cyberattacks – along with millions more whose records were also contained in the database.

Data Breach Impact

Studies have shown that free gambling and gaming apps are especially prone to attacks and hacking from cybercriminals. They are routinely targeted for theft of private data and embedding malicious software on users’ devices.

Despite their popularity, gambling and casino apps often lack transparency, and it can be impossible to know what steps they’re taking to prevent cybercriminals successfully targeting their users.

One study of 23,000 free gambling apps found that: 3,200 posed a ‘moderate risk’ to users; 379 had known security vulnerabilities; 52 contained malicious software.

Any of these issues could be exploited to target app users in a wide range of frauds and cyberattacks, and Clubillion is no different.

With the exposed user PII and knowledge of their activity on the app, hackers could create elaborate schemes to defraud users. For example, some entries also included transaction errors for attempted card payments on Clubillion.

With the information in these transaction errors, hackers could target users with phishing campaigns, with the following aims:

  1. Trick them into providing their credit card details
  2. Trick them into providing additional PII to be used against them in further fraud
  3. Clicking a link that embeds malware, spyware, or ransomware onto their device.

If cybercriminals used Clubillion to embed malware or similar onto a user’s phone, they could potentially hack other apps, access files stored on the device, make calls, and send texts from the hacked device. They could even access a user’s phone contacts and steal the PII data of their friends and family.

Worse still, as people across the globe now find themselves under quarantine or self-isolation, as a result of the Coronavirus pandemic, the impact of a leak like this is potentially even more significant.

Clubillion stands to gain many new users, along with regular users playing more frequently. Hackers will be aware of this and looking for opportunities to exploit any vulnerabilities in the data security of such a massively popular app.

Had criminal hackers discovered Clubillion’s database, they could have targeted millions of people around the world, with devastating results.

Impact on Clubillion and it’s Developers

The most immediate risk for Clubillion is the loss of players. Data security is a growing concern for everyone these days, and this leak could turn many players off the app. Clubillion is not unique, and players have plenty of other choices for free gambling apps.

With fewer players, Clubillion will lose advertising revenue and reduced profits.

As many of Clubillion’s players reside within the EU, the app is under the jurisdiction of GDPR. The rules of GDPR also apply to apps, and Clubillion will need to take specific actions to ensure the regulatory body in charge doesn’t reprimand it.

Finally, Clubillion could also potentially be removed from Google Play and the App Store. Both Apple and Google are clamping down on apps that pose a risk to their users, removing apps embedded with malware, and taking data leaks much more seriously.

Each of these outcomes has a different likelihood of happening, but they would all negatively impact Clubillion’s revenue and business.

Advice from the Experts

Clubillion’s developers could have easily avoided this leak if they had taken some basic security measures to protect the database. These include, but are not limited to:

  1. Securing their servers.
  2. Implementing proper access rules.
  3. Never leaving a system that doesn’t require authentication open to the internet.

Any company can replicate the same steps, no matter its size.

For a more in-depth guide on how to protect your business, check out our guide to securing your website and online database from hackers.

For Clubillion Users

If you play on Clubillion and are concerned about how this breach might impact you, contact the app’s developers directly to find out what steps it’s taking to protect your data.

To learn about data vulnerabilities in general, read our complete guide to online privacy.

It shows you the many ways cybercriminals target internet users, and the steps you can take to stay safe.

How and Why We Discovered the Breach

The vpnMentor research team discovered the breach in Clubillion’s database as part of a huge web mapping project. Our researchers use port scanning to examine particular IP blocks and test different systems for weaknesses or vulnerabilities. They examine each weakness for any data being leaked.

Our team was able to access this database because it was completely unsecured and unencrypted. 

Whenever we find a data breach, we use expert techniques to verify the owner of the database, usually a commercial company.

As ethical hackers, we’re obliged to inform a company when we discover flaws in their online security. We reached out to Clubillion’s developers, not only to let them know about the vulnerability but also to suggest ways in which they could make their system secure.

These ethics also mean we carry a responsibility to the public. Clubillion users must be aware of a data breach that exposes so much of their sensitive data.

The purpose of this web mapping project is to help make the internet safer for all users.

 

Source

Continue Reading
Advertisement




MARE BALTICUM Gaming & TECH Summit 2024

Click to comment

Latest News

BOS agrees with KV’s/KO’s advertising assessment of “Trisskrapet” in TV4

Published

on

Reading Time: < 1 minute

The Swedish Trade Association for Online Gambling (BOS) agrees with the Swedish Consumer Agency’s (KV) and the Consumer Ombudsman’s (KO) assessment that the daily scratch card commercial “Trisskrapet” in TV4 is an advertising feature, and thus not an editorial feature. BOS welcomes that KO is now ending that part of the process.

If Svenska Spel does not stop the advertising elements, BOS looks forward to KV following up on its earlier call to Svenska Spel to comply with the provisions on advertising identification and broadcaster declaration in section 9 of the Marketing Act and the information obligation in ch. 15. Section 3 of the Gambling Act with information on the 18-year-old age limit and where to turn in case of gambling problems.

– The Swedish gambling market must be characterized by a high level of consumer protection. A cornerstone of good consumer protection is that people are clear about what constitutes gambling advertising, i.e. that they are not tricked into thinking that an advertising feature would instead be an editorial feature. The daily “Trisskrapet” on TV4 has been anything but clear on that point, and we welcome that KO now finally establishes that the features constitute advertising and nothing else, says Gustaf Hoffstedt.

– Now it remains for Svenska Spel to introduce the mandatory consumer protection labelling of Trisskrapet. Since the company has not shown any excessive eagerness to introduce this voluntarily, KO should ensure that this happens as soon as possible. Every day and every “Trisskrapet” that does not contain the mandatory consumer protection label is another lost day for a safe and secure gambling market, Gustaf Hoffstedt concludes.

Continue Reading

Balkans

Expanse Studios Launches in Bulgaria with Inbet

Published

on

Reading Time: < 1 minute

 

Expanse Studios, a leader in online gaming innovation, has secured a Bulgarian iGaming license and is now live on Inbet’s website. This expansion brings Expanse Studios’ popular game offerings including turn-based strategies gamified for iGaming, classic slots, traditional card games and the highly-acclaimed ones like Titan Roulette, Clown Fever Deluxe, Wild Icy Fruits, White Wild Whale and Joker Poker to Bulgarian players.

Diverse Gaming Portfolio Now Available to Bulgarian Players

With the Bulgarian market entry, Expanse Studios introduces a versatile gaming experience to Inbet’s platform. The offerings include a dynamic range of games tailored to diverse player preferences:

  • Turn-based strategy games: Leveraging gamification, these games transform traditional strategy gameplay into engaging iGaming experiences, suitable for both novice and experienced players.
  • Classic slots: Players will enjoy a variety of themed slots that combine traditional gameplay with modern graphics and sound.
  • Traditional card games: A selection of popular card games offer something for every card game enthusiast.
  • Titan Roulette: This standout feature, known for its immersive experience and innovative design, continues to be a favorite among roulette players.

Commitment to Quality and Compliance

Expanse Studios not only cultivates a diverse gaming library but also adheres to stringent regulatory standards to ensure a secure and fair gaming environment. The acquisition of the Bulgarian iGaming license is a testament to Expanse Studios’ commitment to compliance and excellence in the gaming industry.

The partnership between Expanse Studios and Inbet marks a significant milestone in Expanse Studios’ expansion efforts. By combining Expanse Studios’ innovative gaming solutions with Inbet’s established market presence, both entities are set to offer a superior gaming experience to players in Bulgaria and potentially beyond. As Expanse Studios continues to develop and release new games monthly, Bulgarian players can look forward to a continually evolving and enriching gaming landscape.

Continue Reading

Latest News

Week 17/2024 slot games releases

Published

on

Week 17/2024 slot games releases
Reading Time: 5 minutes

 

Here are this weeks latest slots releases compiled by European Gaming

Belatra Games, the specialist online slots developer, is on point with its latest sharply designed game, Golden øks. This Norse-inspired adventure carries on from the popular Axe of Fortune title that hit the market at the turn of the year. Golden øks is set against a 5×3 layout and is brought to life with a powerful soundtrack to heighten the atmosphere.

Belatra grows games portfolio with Golden øks title

Endorphina, has announced the release of its brand-new title, Jolly Queen, which will join its portfolio on April 27th. Jolly Queen is a 5-reel, 5-row fruit slot with 50 fixed paylines, introducing players to the lifestyle of the nobles. On top of the aristocratic ambiance, Jolly Queen provides players with Free Games, allowing them to master the reels.

Endorphina releases its newest title - Jolly Queen!

Evoplay has released Candy Craze, a vibrant slot stacked with features and modifiers, including the powerful Gum Drop Multiplier which boosts win potential. Set amidst the backdrop of sumptuous sweets within a cloudy landscape, the 5×5 cascading reels title gives players a sugary rush when the Gum Drop Multiplier activates, revealing a mystery value at the end of each winning spin up to x100, enhancing the chance for wins during the main game and Free Spins.

Yggdrasil, a leading iGaming publisher, has revived the gold rush in a jackpot-filled game that embodies the spirit of old west prospecting in Gold Frontier Jackpots FastPot5™. Fans of lower volatility slots with straightforward mechanics that get fortune seekers right to the heart of the action are tasked with gathering keys to enter the treasure bonus game.

Relax Gaming is offering players some opulence in its latest release Sultan Spins. This high volatility slot sees its gold-trimmed reels set against a sprawling desert metropolis. Players have the chance to rack up riches via an entertaining free spins feature and lucrative local jackpot.

Greentube has introduced its latest title in the popular Diamond Link ™ series, Diamond Link ™: Mighty Dwarves Inc. Set deep in underground mines, this adventurous 5×3 slot is packed with innovative features for ample chance to win across its 25 paylines when players spin the reels adorned with hammers, hard hats and laser symbols.

Get your eyes ready because it’s time to take a trip to the pet centre to meet the ugliest, quirkiest, wildest-looking pets you’ve ever seen in the brand new slot, Fugly Pets, from Stakelogic. Fugly Pets takes players to a banged-up old pet store to explore its collection of weird and charming, downright ugly pets. Meet a scruffy parrot, a catnip crazed kitty, and an unfortunate-looking little dog.

 

 

Load your tackle box, bait your hook and get ready to reel in the catch of the day in Fishin’ The Biggest from Apparat Gaming, the in-demand German software provider’s latest splash hit slot that sees players trawl the sea for free spins and massively multiplied prizes. Played over five reels, three rows and ten fixed paylines, Fishin’ The Biggest is a highly-volatile title with an outdoor angling theme.

Thunderkick has announced the launch of Midas Golden Touch 2, the highly-anticipated sequel to the acclaimed 2019 original. This latest release invites players to rediscover an enchanted realm where everything King Midas touches turns to gold. The 3×5 video slot boasts 15 paylines and showcases Thunderkick’s signature high-quality design and innovative features.

Belatra Games, the specialist online slots developer, has served up another classic with its tasty Chef’s Sticky Fruits slot. This latest release from Belatra’s studio  is a vibrant and juicy addition to its renowned catalogue of slots. It’s a 5×4 slot game bursting with colour that’s heightened with an upbeat, retro soundtrack that perfectly captures the essence of fun at the heart of every play.

Belatra serves up tasty Chef’s Sticky Fruits slot

3 Oaks Gaming has launched 3 China Pots: Hold and Win, the first time the company has integrated the popular 3 Pots mechanic within a Far East-themed title. The latest instalment from 3 Oaks to incorporate the 3 Pots functionality sees players transported to the allure of the Orient, where the Extra, Double and Multi modifiers influence the Bonus Game once activated.

3 Oaks Gaming presents a feature-rich trip to the Far East in 3 China Pots: Hold and Win

Pragmatic Play has unleashed roaming wild re-spins and random guaranteed wins in Release the Bison. Symbols of the American frontier abound in this 5×4 slot, where hitting four or more rampaging bison triggers the wild re-spin feature, during which all wilds roam the reels to boost win potential.

Blueprint Gaming’s latest slot release tasks players to look for the leprechaun’s pot of gold under the water rather than at the end of the rainbow in Plenty O’ Fish, a 6×4 hybrid of sea creatures and shimmering rewards. Players must look to unlock a tackle box of treasure with a jaunty leprechaun being the key to wins, lurking behind a dynamically coloured underwater background that changes when the bonus game is triggered.

Booming Games has launched its latest sweet sensation to its collection of engaging slot games – Fruit Heaven Hold and Win™. This is a deliciously designed 5×3 slot game with 25 paylines, which promises players an exciting experience full of fantastic fruity features and Stacked Wilds.

Wazdan is multiplying jackpots in the follow-up to its top-performing game Mighty Wild™: Panther Grand Gold Edition. Venturing to the depths of the jungle where a black panther rules the reels on a 5×3 gameboard, the new edition provides even larger win potential. With the increased value of the Cash symbols and Cash Infinity™ symbols, there is also a more lucrative Grand Jackpot of 1500x the base bet.

Continue Reading
Advertisement
Alpha Affiliates
Advertisement

EveryMatrix

Advertisement

SaaS-builder for partner program development and performance marketing optimization

Advertisement

Launch your iGaming business swiftly and effortlessly with our comprehensive turnkey solutions

Advertisement

LEADING AFFILIATE MARKETING SHOW

Trending (Top 7)

Get it on Google Play

EuropeanGaming.eu is a premier online platform that serves as a leading information hub for the gaming and gambling industry. This industry-centric media outlet reaches over 200,000 readers monthly, providing them with compelling content, the latest news, and deep-dive insights.

Offering comprehensive coverage on all aspects of the gaming sector, EuropeanGaming.eu includes online and land-based gaming, betting, esports, regulatory and compliance updates, and technological advancements. Regular features encompass daily news articles, press releases, exclusive interviews, and insightful event reports.

The platform also hosts industry-relevant virtual meetups and conferences, and provides detailed reports, making it a one-stop resource for anyone seeking information about operators, suppliers, regulators, and professional services in the European gaming market. The portal's primary goal is to keep its extensive reader base updated on the latest happenings, trends, and developments within the gaming and gambling sector, with an emphasis on the European market while also covering pertinent global news. It's an indispensable resource for gaming professionals, operators, and enthusiasts alike.

Contact us: [email protected]

Editorial / PR Submissions: [email protected]

Copyright © 2015 - 2024 - European Gaming is part of HIPTHER. Registered in Romania under Proshirt SRL, Company number: 2134306, EU VAT ID: RO21343605. Office address: Blvd. 1 Decembrie 1918 nr.5, Targu Mures, Romania

We are constantly showing banners about important news regarding events and product launches. Please turn AdBlock off in order to see these areas.