Latest News
Popular Gambling App Exposed Millions of Users in Massive Data Leak
Led by Noam Rotem and Ran Locar, vpnMentor’s research team discovered a data breach on casino gambling app Clubillion.
The breach originated in a technical database built on an Elasticsearch engine and was recording the daily activities of millions of Clubillion players around the world.
Aside from leaking activity on the app, the breached database also exposed private user information.
With this information publicly available, Clubillion’s users were vulnerable to fraud and various online attacks with potentially devastating results.
Company Profile
Clubillion is a free online casino game available for iOS and Android, offering players 30+ free slot games. While each app is listed under a different developer – Ouroboros on iOS and T7 Games on Android – these are most likely owned by the same company.
Both versions of Clubillion were released in 2019 and became instant hits. Each is now ranked the #1 ‘social slots’ casino app on Google Play and the App Store, with a 4.8 star on both.
Timeline of Discovery and Owner Reaction
Sometimes, the extent of a data breach and the owner of the database are obvious, and the issue quickly resolved. But rare are these times. Most often, we need days of investigation before we understand what’s at stake or who’s leaking the data.
Understanding a breach and its potential impact takes careful attention and time. We work hard to publish accurate and trustworthy reports, ensuring everybody who reads them understands their seriousness.
Some affected parties deny the facts, disregarding our research, or playing down its impact. So, we need to be thorough and make sure everything we find is correct and accurate.
In this case, the database was built on Elasticsearch and hosted on Amazon Web Services (AWS), with Clubillion’s name on its apps, and links to assets owned by the company.
Once Clubillion was confirmed as the owner of the database, we reached out to the developers. While awaiting a reply, we also contacted AWS with details of the leak. It was closed a few days later.
- Date discovered: 19th March 2020
- Date vendors contacted: 23rd March 2020
- Date of contact with AWS: 31st March 2020
- Date of Action: Approx. 5th April 2020
Example of Entries in the Database
Clubillion’s exposed database contained technical logs for millions of Clubillion users around the world, on both iOS and Android devices. Every time an individual player took any action on the app, a record was logged. Examples of records include:
- “enter game”
- “win”
- “lose”
- “update account”
- “create account”
During our investigation of the database, new entries continued to appear continuously. We estimated an average of approximately 200 million records per day – and sometimes, considerably more.
In total, this amounted to over 50GB of exposed records in the database every single day.
Within many of these records, were various forms of user Personally Identifiable Information (PII) data, including:
- IP addresses
- Email addresses
- Winnings
- Private messages
This data breach was truly global, with millions of records originating from Clubillion’s daily users all over the world. The following list is just a sample of countries affected, along with the average number of daily users from each country:
- USA – 10,000+
- UK – 2,475+
- France – 1,650+
- Israel – 408+
- Germany – 1,582+
- Spain – 1,026+
- Italy – 2,407+
- Netherlands – 622+
- Australia – 6,251+
- Canada – 7,792+
- Brazil – 3,859+
- Sweden – 191+
- Russia – 547+
Other countries affected included Uzbekistan, India, Poland, Romania, Vietnam, Lebanon, Indonesia, Philippines, Pakistan, Thailand, Austria, Hungry, and Latvia.
As you can see, on a single day, 10,000s of individual Clubillion players were exposed. Each one of these players could be targeted by malicious hackers for fraud and cyberattacks – along with millions more whose records were also contained in the database.
Data Breach Impact
Studies have shown that free gambling and gaming apps are especially prone to attacks and hacking from cybercriminals. They are routinely targeted for theft of private data and embedding malicious software on users’ devices.
Despite their popularity, gambling and casino apps often lack transparency, and it can be impossible to know what steps they’re taking to prevent cybercriminals successfully targeting their users.
One study of 23,000 free gambling apps found that: 3,200 posed a ‘moderate risk’ to users; 379 had known security vulnerabilities; 52 contained malicious software.
Any of these issues could be exploited to target app users in a wide range of frauds and cyberattacks, and Clubillion is no different.
With the exposed user PII and knowledge of their activity on the app, hackers could create elaborate schemes to defraud users. For example, some entries also included transaction errors for attempted card payments on Clubillion.
With the information in these transaction errors, hackers could target users with phishing campaigns, with the following aims:
- Trick them into providing their credit card details
- Trick them into providing additional PII to be used against them in further fraud
- Clicking a link that embeds malware, spyware, or ransomware onto their device.
If cybercriminals used Clubillion to embed malware or similar onto a user’s phone, they could potentially hack other apps, access files stored on the device, make calls, and send texts from the hacked device. They could even access a user’s phone contacts and steal the PII data of their friends and family.
Worse still, as people across the globe now find themselves under quarantine or self-isolation, as a result of the Coronavirus pandemic, the impact of a leak like this is potentially even more significant.
Clubillion stands to gain many new users, along with regular users playing more frequently. Hackers will be aware of this and looking for opportunities to exploit any vulnerabilities in the data security of such a massively popular app.
Had criminal hackers discovered Clubillion’s database, they could have targeted millions of people around the world, with devastating results.
Impact on Clubillion and it’s Developers
The most immediate risk for Clubillion is the loss of players. Data security is a growing concern for everyone these days, and this leak could turn many players off the app. Clubillion is not unique, and players have plenty of other choices for free gambling apps.
With fewer players, Clubillion will lose advertising revenue and reduced profits.
As many of Clubillion’s players reside within the EU, the app is under the jurisdiction of GDPR. The rules of GDPR also apply to apps, and Clubillion will need to take specific actions to ensure the regulatory body in charge doesn’t reprimand it.
Finally, Clubillion could also potentially be removed from Google Play and the App Store. Both Apple and Google are clamping down on apps that pose a risk to their users, removing apps embedded with malware, and taking data leaks much more seriously.
Each of these outcomes has a different likelihood of happening, but they would all negatively impact Clubillion’s revenue and business.
Advice from the Experts
Clubillion’s developers could have easily avoided this leak if they had taken some basic security measures to protect the database. These include, but are not limited to:
- Securing their servers.
- Implementing proper access rules.
- Never leaving a system that doesn’t require authentication open to the internet.
Any company can replicate the same steps, no matter its size.
For a more in-depth guide on how to protect your business, check out our guide to securing your website and online database from hackers.
For Clubillion Users
If you play on Clubillion and are concerned about how this breach might impact you, contact the app’s developers directly to find out what steps it’s taking to protect your data.
To learn about data vulnerabilities in general, read our complete guide to online privacy.
It shows you the many ways cybercriminals target internet users, and the steps you can take to stay safe.
How and Why We Discovered the Breach
The vpnMentor research team discovered the breach in Clubillion’s database as part of a huge web mapping project. Our researchers use port scanning to examine particular IP blocks and test different systems for weaknesses or vulnerabilities. They examine each weakness for any data being leaked.
Our team was able to access this database because it was completely unsecured and unencrypted.
Whenever we find a data breach, we use expert techniques to verify the owner of the database, usually a commercial company.
As ethical hackers, we’re obliged to inform a company when we discover flaws in their online security. We reached out to Clubillion’s developers, not only to let them know about the vulnerability but also to suggest ways in which they could make their system secure.
These ethics also mean we carry a responsibility to the public. Clubillion users must be aware of a data breach that exposes so much of their sensitive data.
The purpose of this web mapping project is to help make the internet safer for all users.
Powered by WPeMatico
Azerlotereya
How Groove Technologies Powered a Landmark Year of Global Expansion
As the iGaming industry enters 2026, award-winning platform and aggregator Groove Technologies is reflecting on a transformative 2025. This landmark year was defined by strategic expansion, technological innovation, and a significant deepening of its global roots, solidifying Groove’s role as a comprehensive growth engine for operators worldwide.
Strategic Leadership and Market Penetration
A key catalyst for this growth was the appointment of Giusy Campo as Business Development Director. With over 15 years of experience (including a notable tenure at GLI), Campo’s mandate was to structure and accelerate the company’s push into complex regulated markets.
The “LATAM Story”: Brazil and Argentina
A headline achievement for the year was securing a license to operate in Brazil as the country launched its regulated market on January 1, 2025. Coupled with established activity in Argentina, this move forms the foundation of Groove’s Latin American strategy.
“Brazil isn’t just another market; it’s a statement of intent,” says Yahale Meltzer, Co-Founder and COO. “With Giusy Campo leading our business development, we are systematically building the partnerships necessary for long-term success in regulated regions.”
Technological Innovation: Groove Command & Instant Tournaments
2025 saw Groove transition from a powerful aggregator to a complete engagement ecosystem with the launch of its proprietary Instant Tournaments tool, integrated directly into the Groove Command (Sinatra) Back Office.
Key Platform Advancements:
-
Self-Service Marketing: Operators can now launch and manage tournaments and Free Round Bonuses (FRB) in minutes without technical intervention.
-
Ecosystem Growth: The platform onboarded 20+ new game providers and 10+ new operator partners in 2025.
-
Vertical Expansion: Significant growth in the Sweepstakes and Crypto gaming sectors, responding to evolving partner demand.
| Metric | 2025 Achievement |
| New Providers | 20+ Added |
| New Operators | 10+ Onboarded |
| Total Game Catalog | 15,000+ Titles |
| Global Presence | 10 Major Events across 4 Continents |
Diversified Partnerships: From Crypto to National Lotteries
Demonstrating the platform’s versatility, Groove secured a landmark partnership with Azerlotereya, the national lottery of Azerbaijan. This collaboration validates the robustness and compliance of Groove’s infrastructure in government-backed, high-stringency environments.
Operational Scale and Global Infrastructure
To support these ambitions, Groove scaled its global support network. The company now maintains offices in Israel, Georgia, and Malta, offering 24/7 multilingual technical and account services.
“Our expansion into sweepstakes and crypto wasn’t opportunistic; it was a response to clear partner demand,” reflects Meltzer. “When an operator in Georgia or a partner in São Paulo has a question, they get an answer from someone who understands their market context, not just their technical issue.”
The post How Groove Technologies Powered a Landmark Year of Global Expansion appeared first on Eastern European Gaming | Global iGaming & Tech Intelligence Hub.
DUPR Ratings
USA Pickleball “Golden Ticket” Returns to Las Vegas: February 2026 at the Plaza
USA Pickleball is heading back to the “Sports and Entertainment Capital of the World” for the USA Pickleball Golden Ticket – Las Vegas, presented by Tommy Bahama.
Taking place from February 18–22, 2026, the event moves to a new iconic home at the Plaza Hotel & Casino in downtown Las Vegas. As a premier qualifying event for the 2026 USA Pickleball National Championships, this tournament offers amateur players their fastest “Path to Nationals.”
The “Golden Ticket” Advantage
In the competitive world of pickleball, a “Golden Ticket” is the ultimate prize for amateur athletes.
-
Priority Registration: Gold medalists in each age and skill bracket receive a Golden Ticket, granting them guaranteed priority registration for the National Championships in November.
-
Tiered Point System (TPS): Participants who do not win gold still earn maximum ranking points toward Nationals eligibility, as Golden Ticket events sit at the highest tier of the sanctioned points system.
-
Official Rankings: As a sanctioned event, results are reported to DUPR, providing athletes with verified skill ratings.
Venue Spotlight: The Plaza Hotel & Casino
The Plaza has established itself as the premier pickleball destination in Las Vegas, boasting more courts than any other hotel-casino resort in the city.
-
16 Tournament-Level Courts: The venue features 12 permanent rooftop courts and a dedicated championship court area that can expand to accommodate large-scale tournament play.
-
Rooftop Experience: Players compete on the Plaza’s fifth-floor pool deck, offering panoramic views of the Las Vegas valley and the historic Fremont Street District.
-
Capacity: The event expects to host over 500 athletes across five days of high-stakes competition.
“This venue allows us to deliver an extraordinary athlete experience, from professional operations to the energy that makes Las Vegas such a special host city,” said Jose Moreno, Chief Marketing Officer of USA Pickleball.
Tournament Registration & Logistics
Registration for the Las Vegas Golden Ticket is currently open, with several key deadlines and costs for participants:
-
Registration Deadline: February 8, 2026.
-
Cost: $95 Registration Fee + $45 Event Fee (Amateurs).
-
Skill Levels: Open to players in skill brackets 3.0 to 5.0, with age divisions ranging from 19 to 80+.
-
Exclusive Rates: A special hotel rate is available at the Plaza using group code SUSAPGT for bookings made by February 2nd.
For more information on Golden Ticket tournaments and the Path to Nationals, visit https://usapickleball.org/goldenticket/.
The post USA Pickleball “Golden Ticket” Returns to Las Vegas: February 2026 at the Plaza appeared first on Eastern European Gaming | Global iGaming & Tech Intelligence Hub.
DUPR Ratings
USA Pickleball Golden Ticket Heads to the Plaza Hotel and Casino in downtown Las Vegas next month
USA Pickleball Golden Ticket Las Vegas presented by Tommy Bahama set for Feb. 18-22
USA Pickleball is returning to Las Vegas next month with the USA Pickleball Golden Ticket – Las Vegas presented by Tommy Bahama, bringing one of the organization’s premier qualifying events back to the city after a highly successful 2024 tournament. The event will take place Feb. 18–22, at the Plaza Hotel and Casino in downtown Las Vegas, offering athletes a new venue and an elevated tournament experience.
Golden Ticket Tournaments are official qualifying events for the USA Pickleball National Championships, the sport’s most prestigious competition. Winners earn a coveted Golden Ticket, securing priority registration to Nationals, while all participants earn points as part of USA Pickleball’s Tiered Point System.
Golden Ticket Tournaments attract top players from across the country, offering a professionally run environment with certified referees, official rules, and first-class venues designed for fair and competitive play. As sanctioned USA Pickleball events, participants earn official DUPR ratings and ranking points, helping athletes track progress and advance competitively.
“We’re excited to bring the Golden Ticket back to Las Vegas and to do it at the Plaza Hotel and Casino, with an expected 500+ athletes,” said Jose Moreno, Chief Marketing Officer of USA Pickleball. “This venue allows us to deliver an extraordinary athlete experience, from professional operations to the energy that makes Las Vegas such a special host city. Golden Ticket tournaments are a vital part of The Path to Nationals, and Las Vegas is the perfect place for players to test themselves, earn their way forward, and compete among the best in the country.”
“With the most pickleball courts of any resort, the Plaza has become the premier destination for pickleball in Las Vegas,” said Jonathan Jossel, CEO of the Plaza Hotel & Casino. “We are excited to host this prestigious tournament and welcome the top USA Pickleball players from across the country to the Plaza. This event will be one not to miss with exciting, competitive matches played on our courts that offer unforgettable views of the Las Vegas valley.”
A special hotel rate at the Plaza is available for tournament participants. Rooms must be reserved online by Feb. 2, with group code SUSAPGT at https://book.passkey.com/go/SUSAPGT. Guests can also make reservations by phone, 1-800-634-6575, Monday through Friday, 8 a.m. to 10 p.m., or Saturday and Sunday, 5 a.m. to 10 p.m.
For more information on Golden Ticket tournaments and the Path to Nationals, visit https://usapickleball.org/goldenticket/.
The post USA Pickleball Golden Ticket Heads to the Plaza Hotel and Casino in downtown Las Vegas next month appeared first on Americas iGaming & Sports Betting News.
-
iGaming News 20263 days agoSpinomenal Rings in 2026 with Japanese-Inspired “Kami Reign Ultra Mode”
-
Hold and3 days agoPragmatic Play Rings in 2026 with Joker’s Jewels Hold & Spin™
-
Five Elements Slot3 days agoPG Soft Concludes 2025 with High-Volatility Launch: Mythical Guardians
-
Latest News3 days agoFrom ‘Mummyverse’ to Crash Games: Belatra Reviews a Landmark 2025
-
Bespoke Gaming Studio3 days agoCreedRoomz and Casumo Forge Strategic Partnership to Elevate Live Casino Experience
-
B2B gaming software3 days agoGamblers Connect and BetOxygen Announce Strategic B2B Partnership
-
Button Blind3 days agoStretch Network Boosts Player Engagement with Year-End Platform Enhancements
-
casino aggregation3 days agoYggdrasil Expands Global Footprint via Strategic Partnership with Vyking



