Industry News
MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability
Attackers could exploit the SQL Injection flaw to compromise the game’s database and steal user data.
The CyberNews.com Investigation team discovered a critical vulnerability in Street Mobster, a browser-based massively multiplayer online game created by Bulgarian development company BigMage Studios.
Street Mobster is a free to play, browser-based online game in the mafia empire genre where players manage a fictional criminal enterprise. The game boasts a 1.9+ million player base and stores a user record database that can be accessed by threat actors by committing an SQL Injection (SQLi) attack on the game’s website.
Other games created by BigMage Studios are also potentially vulnerable to the same type of attack, which means that there is a possibility that even more users might be at risk.
The records that can be compromised by exploiting the SQLi vulnerability in Street Mobster potentially include the players’ usernames, email addresses, and passwords, as well as other game-related data that is stored on the database.
Fortunately, after we reported the vulnerability to BigMage Studios, CERT Bulgaria, and the Bulgarian data protection authority, the issue has been fixed by the developers and the user database is no longer accessible to potential attackers.
What is SQL Injection?
First found back in 1998, SQLi is deemed by the Open Web Application Security Project (OWASP) as the number one web application security risk.
Even though this vulnerability is relatively easy to fix, researchers found that 8% of websites and web applications are still vulnerable to SQLi attacks in 2020. Which, from a security perspective, is inexcusable. So much so, in fact, that UK internet service provider TalkTalk was hit with a record £400,000 fine over succumbing to a cyberattack that involved SQLi.
The vulnerability works by injecting an unexpected payload (a piece of code) into the input box on the website or in its URL address. Instead of reading the text as part of the URL, the website’s server reads the attacker’s payload as code and then proceeds to execute the attacker’s command or output data that would otherwise be inaccessible to unauthorized parties. Attackers can exploit SQLi even further by uploading pieces of code or even malware to the vulnerable server.
The fact that Street Mobster is susceptible to SQLi attacks clearly shows the disappointing and dangerous neglect of basic security practices on the part of the developers at BigMage Studios.
How we found this vulnerability
Our security team identified an SQL Injection vulnerability on the Street Mobster website and were able to confirm the vulnerability by performing a simple command injection test on the website URL. The CyberNews team did not extract any data from the vulnerable Street Mobster database.
What’s the impact of the vulnerability?
The data in the vulnerable Street Mobster database can be used in a variety of ways against the players whose information was exposed:
By injecting malicious payloads on Street Mobster’s server, attackers can potentially gain access to said server, where they can install malware on the game’s website and cause harm to the visitors – from using the players’ devices to mine cryptocurrency to redirecting them to other malicious websites, installing malware, and more.
The 1.9 million user credentials stored on the database can net the attackers user email addresses and passwords, which they can potentially use for credential stuffing attacks to hack the players’ accounts on other gaming platforms like Steam or other online services.
Because Street Mobster is a free-to-play game that incorporates microtransactions, bad actors could also make a lot of money from selling hacked player accounts on gray market websites.
What to do if you’ve been affected?
If you have a Street Mobster account, make sure to change your password immediately and make it as complex as possible. If you’ve been using your Street Mobster password on any other websites or services, change that password as well. This will prevent potential attackers from accessing your accounts on these websites in case they try to reuse your password for credential stuffing attacks.
However, it’s ultimately up to BigMage Studios to completely secure your Street Mobster account against attacks like SQLi.
Disclosure and lack of communication from BigMage Studios
Following our vulnerability disclosure guidelines, we notified the BigMage Studios about the leak on August 31, 2020. However, we received no reply. Our follow-up emails were left unanswered as well.
We then reached out to CERT Bulgaria on September 11 in order to help secure the website. CERT contacted the BigMage Studios and informed the company about the misconfiguration.
Throughout the disclosure process, BigMage Studios stayed radio silent and refused to get in touch with CyberNews.com. Due to this reason, we also notified the Bulgarian data protection agency about the incident on October 9 in the hopes that the agency would be able to pressure the company into fixing the issue.
Eventually, however, BigMage Studios appear to have fixed the SLQi vulnerability on streetmobster.com, without informing either CyberNews.com or CERT Bulgaria about that fact.
Powered by WPeMatico
Continent 8 Technologies
Continent 8 appoints Cris Kuehl as Chief Data, Information & AI Officer
Continent 8 Technologies, a leading provider of managed IT solutions for the global iGaming and online sports betting industry, has appointed Cris Kuehl as its Chief Data, Information & AI Officer.
Cris brings over 20 years of expertise in AI, analytics, and data strategy, with senior roles including VP of Artificial Intelligence & Data Science at Akkodis and Global Head, CX Analytics & AI at Foundever. His career focuses on helping regulated organisations adopt secure, scalable, and practical AI capabilities.
At Continent 8, Cris will oversee the company’s global data, AI, and information strategy, driving innovation in analytics, automation, cybersecurity, and customer-centric intelligence. He will also shape AI-enabled product development, champion responsible AI practices, and strengthen data governance for the iGaming, tribal, and enterprise sectors.
Michael Tobin, CEO and Founder of Continent 8, said:
“Cris’ expertise across data, AI, and regulated environments is a perfect fit for our organisation. His leadership will help us provide secure, high-performance solutions that deliver measurable value to customers.”
Cris Kuehl added:
“I’m thrilled to join Continent 8 at such a pivotal moment. AI is transforming how organisations operate, collaborate, and protect their data. Continent 8 is uniquely positioned to lead this transformation in the iGaming and online sports betting sector, and I’m excited to drive the next chapter of innovation.”
The post Continent 8 appoints Cris Kuehl as Chief Data, Information & AI Officer appeared first on Eastern European Gaming | Global iGaming & Tech Intelligence Hub.
iGaming
PRAGMATIC PLAY BRINGS LEGENDARY SLOTS IP TO LIVE CASINO WITH GATES OF OLYMPUS ROULETTE
Pragmatic Play, a leading iGaming content supplier, has launched Gates of Olympus Roulette, a live casino experience that merges classic roulette with thrilling slot-action, delivering a game show truly fit for the gods.
Set in a temple-inspired studio with a marble-encased roulette wheel at its centre, the game immerses players in a Grecian fantasy world, complete with striking visuals, dramatic sounds, and charismatic presenters.
Each spin offers the chance to hit a Bonus Number and up to seven Lucky Numbers, carrying multipliers of 50x–250x to boost straight-up bets. The Super Booster feature further amplifies wins by multiplying the Bonus and selected Lucky Numbers 2x–10x, enabling potential payouts of up to 2,500x in the base game and 10,000x in the bonus round.
Landing the Bonus Number triggers the Gates of Olympus bonus game, where Zeus presides over a 6×5 slots grid. Starting with 15 spins, players win whenever 8–12+ matching symbols appear anywhere on the reels. Multipliers up to 500x can strike randomly on any spin or tumble, and three or more scatters award five additional spins.
Following the success of Sweet Bonanza CandyLand, which brought the iconic Sweet Bonanza slot to live casino audiences, Gates of Olympus Roulette underscores Pragmatic Play’s expertise in transforming beloved slot IPs into cross-vertical live experiences. The launch complements recent game show hits like Money Time and Mega Roulette 3000.
Sharon McHugh, Director of Public Relations at Pragmatic Play, said:
“Gates of Olympus Roulette is a spectacular addition to our portfolio, bringing one of our most celebrated IPs into the live casino spotlight. The epic studio design, dynamic roulette-slot fusion, and immersive Grecian theme showcase Pragmatic Play’s commitment to creating truly standout player experiences.”
The post PRAGMATIC PLAY BRINGS LEGENDARY SLOTS IP TO LIVE CASINO WITH GATES OF OLYMPUS ROULETTE appeared first on Eastern European Gaming | Global iGaming & Tech Intelligence Hub.
Industry News
Prime Casino launches ultimate VIP Football Experience
Online casino Prime Casino is giving players the chance to win a once-in-a-lifetime VIP Football Experience in the USA this summer.
Running now until 7 June 2026, new players who deposit a minimum of £10 will receive 155 free spins on Football Cash Collect and can participate in freeroll tournaments and raffles, all leading to the ultimate football prize.
VIP Treatment Stateside
With international football heating up, 48 teams will compete across Canada, Mexico, and the USA. Winners of Prime Casino’s VIP Football Experience will enjoy a guest pass, quarter-final match tickets, VIP hospitality, covered accommodation, and flight contributions.
England, second favourites to replicate their 1966 triumph, face Croatia, Ghana, and Panama in the group stage, with a potential quarter-final against Brazil looming. Scotland will also compete, starting against Haiti before facing Morocco and Brazil.
Play for Prizes
Eligible players can join a series of freeroll tournaments and raffles, featuring prizes including cash, free spins, and the headline VIP Football Experience.
Freeroll Tournament Prizes:
- 1st: VIP Football Experience
- 2nd: £1,500 cash (TV prize)
- 3rd: £1,000 cash (Free Pizza for a Year)
- 4th–100th: 150 free spins
- 101st–200th: 125 free spins
- 201st–300th: 100 free spins
- 301st–400th: 60 free spins
- 401st–500th: 40 free spins
- 501st–600th: 25 free spins
- 601st–650th: 15 free spins
Raffle Prizes:
- 1st: VIP Football Experience
- 2nd: £1,500 cash
- 3rd: £1,000 cash
Full terms and conditions: Prime Casino Football Experience
18+ GambleAware.org
Dom Aldworth, Head of Brand Marketing at Kinetic Digital, said:
“Football remains one of the most exciting engagement drivers for our players. This campaign combines a strong welcome offer with ongoing tournaments and the chance to win a VIP football trip, giving multiple ways to get involved. At Prime Casino, we focus on creating standout experiences that players genuinely value, and this promotion is a perfect example.”
The post Prime Casino launches ultimate VIP Football Experience appeared first on Eastern European Gaming | Global iGaming & Tech Intelligence Hub.
-
Latest News6 days agoELA Games Contributes to Discussions on Scalable iGaming Ecosystems and Studio Innovation at HIPTHER Prague Summit
-
Brazil6 days agoBrazil advances integrity agenda amid strong market growth
-
América Latina7 days agoBiS SiGMA South America by Softswiss reúne autoridades do esporte, mídia e apostas esportivas
-
Behind the Game7 days agoBehind the Game: Retention That Drives Revenue
-
Behind the Game7 days agoBehind the Game: Retention That Drives Revenue
-
affiliate automation6 days agoReferOn Shortlisted for “Best Affiliate Software 2026” at SiGMA Awards South America
-
Game Development7 days agoWeekend Reels: Slot Drops & Trends Shaping the Market
-
BNL3 days agoPaneles SiGMA South America concentran debates claves para Brasil



