Connect with us
SOFTSWISS

Latest News

Popular Gambling App Exposed Millions of Users in Massive Data Leak

Published

on

Popular Gambling App Exposed Millions of Users in Massive Data Leak
Reading Time: 5 minutes

 

Led by Noam Rotem and Ran Locar, vpnMentor’s research team discovered a data breach on casino gambling app Clubillion.

The breach originated in a technical database built on an Elasticsearch engine and was recording the daily activities of millions of Clubillion players around the world.

Aside from leaking activity on the app, the breached database also exposed private user information.

With this information publicly available, Clubillion’s users were vulnerable to fraud and various online attacks with potentially devastating results.

Company Profile

Clubillion is a free online casino game available for iOS and Android, offering players 30+ free slot games. While each app is listed under a different developer – Ouroboros on iOS and T7 Games on Android – these are most likely owned by the same company.

Both versions of Clubillion were released in 2019 and became instant hits. Each is now ranked the #1 ‘social slots’ casino app on Google Play and the App Store, with a 4.8 star on both.

Timeline of Discovery and Owner Reaction

Sometimes, the extent of a data breach and the owner of the database are obvious, and the issue quickly resolved. But rare are these times. Most often, we need days of investigation before we understand what’s at stake or who’s leaking the data.

Understanding a breach and its potential impact takes careful attention and time. We work hard to publish accurate and trustworthy reports, ensuring everybody who reads them understands their seriousness.

Some affected parties deny the facts, disregarding our research, or playing down its impact. So, we need to be thorough and make sure everything we find is correct and accurate.

In this case, the database was built on Elasticsearch and hosted on Amazon Web Services (AWS), with Clubillion’s name on its apps, and links to assets owned by the company.

Once Clubillion was confirmed as the owner of the database, we reached out to the developers. While awaiting a reply, we also contacted AWS with details of the leak. It was closed a few days later.

  • Date discovered: 19th March 2020
  • Date vendors contacted: 23rd March 2020
  • Date of contact with AWS: 31st March 2020
  • Date of Action: Approx. 5th April 2020

Example of Entries in the Database

Clubillion’s exposed database contained technical logs for millions of Clubillion users around the world, on both iOS and Android devices. Every time an individual player took any action on the app, a record was logged. Examples of records include:

  • “enter game”
  • “win”
  • “lose”
  • “update account”
  • “create account”

During our investigation of the database, new entries continued to appear continuously. We estimated an average of approximately 200 million records per day – and sometimes, considerably more.

In total, this amounted to over 50GB of exposed records in the database every single day.

Within many of these records, were various forms of user Personally Identifiable Information (PII) data, including:

  • IP addresses
  • Email addresses
  • Winnings
  • Private messages

This data breach was truly global, with millions of records originating from Clubillion’s daily users all over the world. The following list is just a sample of countries affected, along with the average number of daily users from each country:

  • USA – 10,000+
  • UK – 2,475+
  • France – 1,650+
  • Israel – 408+
  • Germany – 1,582+
  • Spain – 1,026+
  • Italy – 2,407+
  • Netherlands – 622+
  • Australia – 6,251+
  • Canada – 7,792+
  • Brazil – 3,859+
  • Sweden – 191+
  • Russia – 547+

Other countries affected included Uzbekistan, India, Poland, Romania, Vietnam, Lebanon, Indonesia, Philippines, Pakistan, Thailand, Austria, Hungry, and Latvia.

As you can see, on a single day, 10,000s of individual Clubillion players were exposed. Each one of these players could be targeted by malicious hackers for fraud and cyberattacks – along with millions more whose records were also contained in the database.

Data Breach Impact

Studies have shown that free gambling and gaming apps are especially prone to attacks and hacking from cybercriminals. They are routinely targeted for theft of private data and embedding malicious software on users’ devices.

Despite their popularity, gambling and casino apps often lack transparency, and it can be impossible to know what steps they’re taking to prevent cybercriminals successfully targeting their users.

One study of 23,000 free gambling apps found that: 3,200 posed a ‘moderate risk’ to users; 379 had known security vulnerabilities; 52 contained malicious software.

Any of these issues could be exploited to target app users in a wide range of frauds and cyberattacks, and Clubillion is no different.

With the exposed user PII and knowledge of their activity on the app, hackers could create elaborate schemes to defraud users. For example, some entries also included transaction errors for attempted card payments on Clubillion.

With the information in these transaction errors, hackers could target users with phishing campaigns, with the following aims:

  1. Trick them into providing their credit card details
  2. Trick them into providing additional PII to be used against them in further fraud
  3. Clicking a link that embeds malware, spyware, or ransomware onto their device.

If cybercriminals used Clubillion to embed malware or similar onto a user’s phone, they could potentially hack other apps, access files stored on the device, make calls, and send texts from the hacked device. They could even access a user’s phone contacts and steal the PII data of their friends and family.

Worse still, as people across the globe now find themselves under quarantine or self-isolation, as a result of the Coronavirus pandemic, the impact of a leak like this is potentially even more significant.

Clubillion stands to gain many new users, along with regular users playing more frequently. Hackers will be aware of this and looking for opportunities to exploit any vulnerabilities in the data security of such a massively popular app.

Had criminal hackers discovered Clubillion’s database, they could have targeted millions of people around the world, with devastating results.

Impact on Clubillion and it’s Developers

The most immediate risk for Clubillion is the loss of players. Data security is a growing concern for everyone these days, and this leak could turn many players off the app. Clubillion is not unique, and players have plenty of other choices for free gambling apps.

With fewer players, Clubillion will lose advertising revenue and reduced profits.

As many of Clubillion’s players reside within the EU, the app is under the jurisdiction of GDPR. The rules of GDPR also apply to apps, and Clubillion will need to take specific actions to ensure the regulatory body in charge doesn’t reprimand it.

Finally, Clubillion could also potentially be removed from Google Play and the App Store. Both Apple and Google are clamping down on apps that pose a risk to their users, removing apps embedded with malware, and taking data leaks much more seriously.

Each of these outcomes has a different likelihood of happening, but they would all negatively impact Clubillion’s revenue and business.

Advice from the Experts

Clubillion’s developers could have easily avoided this leak if they had taken some basic security measures to protect the database. These include, but are not limited to:

  1. Securing their servers.
  2. Implementing proper access rules.
  3. Never leaving a system that doesn’t require authentication open to the internet.

Any company can replicate the same steps, no matter its size.

For a more in-depth guide on how to protect your business, check out our guide to securing your website and online database from hackers.

For Clubillion Users

If you play on Clubillion and are concerned about how this breach might impact you, contact the app’s developers directly to find out what steps it’s taking to protect your data.

To learn about data vulnerabilities in general, read our complete guide to online privacy.

It shows you the many ways cybercriminals target internet users, and the steps you can take to stay safe.

How and Why We Discovered the Breach

The vpnMentor research team discovered the breach in Clubillion’s database as part of a huge web mapping project. Our researchers use port scanning to examine particular IP blocks and test different systems for weaknesses or vulnerabilities. They examine each weakness for any data being leaked.

Our team was able to access this database because it was completely unsecured and unencrypted. 

Whenever we find a data breach, we use expert techniques to verify the owner of the database, usually a commercial company.

As ethical hackers, we’re obliged to inform a company when we discover flaws in their online security. We reached out to Clubillion’s developers, not only to let them know about the vulnerability but also to suggest ways in which they could make their system secure.

These ethics also mean we carry a responsibility to the public. Clubillion users must be aware of a data breach that exposes so much of their sensitive data.

The purpose of this web mapping project is to help make the internet safer for all users.

 

Source

Continue Reading
Advertisement
Stake.com



Click to comment

Latest News

Win tickets to the BLAST Premier Fall Final: GG.BET is running a MEGA BLAST Competition for fans of СS2

Published

on

Reading Time: 2 minutes

 

From 26 July, all GG.BET users can get involved in the new MEGA BLAST Competition with a €10,000 prize fund. The winner will receive two tickets to the BLAST Premier Fall Final CS2 tournament, taking place from 27-29 September in Copenhagen. To enter, you need to place bets on Counter-Strike 2 matches.

BLAST Premier Fall is a major series of Counter-Strike 2 tournaments which draws in millions of viewers from all over the world every year. The series consists of three stages: Groups, Showdown, and Finals. The Groups stage sees 16 Tier-1 teams duke it out. Only 6 of these can go on to compete in the final, while the rest will battle it out in the Fall Showdown for two additional spots in the final. BLAST Premier Fall Finals will be the concluding stage of the Fall series, and fans can look forward to electrifying action, heart-stopping twists and turns, and an epic $425,000 prize fund.

From 26 July to 4 August, as the Groups stage rages on, GG.BET will be holding its MEGA BLAST Competition. The winner will get their hands on two tickets to attend every day of the BLAST Premier Fall Finals. As well as these tickets, the bookmaker is also giving away a whopping €10,000 prize fund to the top 40 participants in the MEGA BLAST Competition.

How to take part in the MEGA BLAST Competition:

  1. Register an account with GG.BET or log in to an existing account.
  2. Go to the tournament page and press “Participate”.
  3. Place bets on Counter-Strike 2 matches. Every bet you place will earn you a certain number of points, based on the odds.
  4. Rack up points, keep an eye on the leaderboard, and wait for your winnings to roll in.

Bet on your favorites and get ready for some unforgettable fun! Head over to GG.BET right now so you don’t miss your chance to enjoy a festival of Counter-Strike action in Copenhagen.

 

Continue Reading

Latest News

MANCHESTER CITY TO MARK GLOBAL PARTNERSHIP WITH SUPER GROUP-OWNED BETWAY AT THE NEW YORK STOCK EXCHANGE

Published

on

Reading Time: 2 minutes

 

Manchester City has today announced a new multi-year partnership with leading global online betting and gaming brand, Betway.

As part of the club’s pre-season tour of the United States, and to mark this significant deal, leading figures from Manchester City and Super Group will be on-site for the iconic NYSE bell-ringing ceremony later today. Ferran Soriano, CEO of City Football Group, along with Neal Menashe, Super Group CEO, will ring The Opening Bell at 9:30am EDT.

The agreement will see Betway become the club’s Official Global Betting Partner from the start of the 2024/25 season, as Manchester City joins the brand’s extensive sports sponsorship portfolio which includes teams from across the Premier League, La Liga, NBA and more.

Ferran Soriano, City Football Group CEO, said: “We are pleased to announce Betway as our Official Global Betting Partner today. As a globally recognised brand, Betway has a strong pedigree and history of working with high-profile brands within the sports space and we’re excited to work together throughout the partnership.”

Super Group CEO, Neal Menashe, commented: “We are absolutely delighted to become Manchester City’s Official Global Betting Partner. This agreement cements our place in the top tier of Premier League partners, ensuring that our Betway brand reaches fans in all corners of the globe.”

Throughout the duration of the partnership, Manchester City and Betway will collaborate on a number of activations and exclusive content opportunities, in addition to the brand featuring across digital and in-stadia assets.

Manchester City and Betway will also work together to provide all players, coaches, management and staff in-depth, industry leading training on all relevant codes of conduct relating to betting integrity and responsible gambling. This is in addition to the work Manchester City already does to support players and staff in this area.

The Opening Bell ceremony can be viewed live.

 

Continue Reading

Compliance Updates

Acquiring a Curacao Online Gaming License in 2024: Comprehensive Analysis of Financial & Procedural Aspects with Costs & Timelines Detailed

Published

on

Reading Time: 2 minutes

The “Acquiring a Curacao Online Gaming License, 2024: Comprehensive Analysis of Financial & Procedural Aspects with Costs & Timelines Detailed” report has been added to ResearchAndMarkets.com’s offering.

This report includes valuable insights into the financial and procedural aspects, including detailed information on costs and timelines associated with acquiring a Curacao license.

In 2023, Curacao introduced the “Landsverordening op de kansspelen” (Ordinance on Games of Chance) to modernize and regulate gambling legislation. Since March 2020, the Gambling Control Board (GCB) has been authorized to regulate offshore gambling games and oversee the issuance of Curacao licenses. As of 2023, there are 16 companies providing legal services for registration and licensing in the territory of Curacao. The license fee, as per GCB regulations, is 36,000 ANG or 19,800 USD, payable upon license issuance.

Research Timeline and Data Relevance

The research was conducted in two stages. The first stage, studying the regulator and Open Data Search, took place in December 2023. The second stage, writing the report and partially updating the data from the first stage, took place from the end of April to the end of May 2024.

Goals and Objectives

  • Describe the information about the Curacao license and the issuing regulator.
  • Describe the requirements and conditions for obtaining a Curacao license.
  • Describe the costs and timelines for obtaining a Curacao license.
  • Briefly study the market, find and suggest the following lists:
    • Legal companies offering services for company registration and obtaining a Curacao license;
    • Communication agents and integrators working with the Curacao license;
    • Suppliers and vendors working with the Curacao license;
    • Payment systems working with the Curacao license.

Key Topics Covered:

1. Goals and Objectives

2. Research Timeline and Data Relevance

  • Document Markup
  • Raw and Combined Data
  • Terms & Glossary

3. General Information

  • The Regulator
    • Registration of Operators With Sublicense
    • Application for an Online Gaming License

4. Requirements and Conditions for Obtaining a License

License Conditions

  • General Prohibitions
  • Safe and Secure Environment
  • Equipment and Application Software
  • Player Registration
  • Payment Transactions
  • Games
  • Terms of Use
  • Resolution of Complaints
  • Administrative Responsibilities
  • Publicly Available Information
  • Reports
  • Policies and Procedures
  • Suspension and Revocation of License
  • Additional Conditions
  • Supervision

Recommendations or Minimum Requirements for the Business Plan

5. The Cost of the License

6. Decision Term and the Validity of the License

7. Application Method and Forms

8. Contact Information

9. Companies for Registration and Licensing

10. Integration Companies

11. Suppliers and Vendors

12. Payment Systems

13. META

14. Appendix: Terms & Glossary

For more information about this report visit researchandmarkets.com/r/izeo6g

 

Continue Reading
Advertisement
Alpha Affiliates
Advertisement

EveryMatrix

Advertisement

Launch your iGaming business swiftly and effortlessly with our comprehensive turnkey solutions

Advertisement
Stake.com
Advertisement
xbit4.com

Trending (Top 7)

Get it on Google Play

EuropeanGaming.eu is a premier online platform that serves as a leading information hub for the gaming and gambling industry. This industry-centric media outlet reaches over 200,000 readers monthly, providing them with compelling content, the latest news, and deep-dive insights.

Offering comprehensive coverage on all aspects of the gaming sector, EuropeanGaming.eu includes online and land-based gaming, betting, esports, regulatory and compliance updates, and technological advancements. Regular features encompass daily news articles, press releases, exclusive interviews, and insightful event reports.

The platform also hosts industry-relevant virtual meetups and conferences, and provides detailed reports, making it a one-stop resource for anyone seeking information about operators, suppliers, regulators, and professional services in the European gaming market. The portal's primary goal is to keep its extensive reader base updated on the latest happenings, trends, and developments within the gaming and gambling sector, with an emphasis on the European market while also covering pertinent global news. It's an indispensable resource for gaming professionals, operators, and enthusiasts alike.

Contact us: [email protected]

Editorial / PR Submissions: [email protected]

Copyright © 2015 - 2024 - European Gaming is part of HIPTHER. Registered in Romania under Proshirt SRL, Company number: 2134306, EU VAT ID: RO21343605. Office address: Blvd. 1 Decembrie 1918 nr.5, Targu Mures, Romania

We are constantly showing banners about important news regarding events and product launches. Please turn AdBlock off in order to see these areas.