Industry News
MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability
Attackers could exploit the SQL Injection flaw to compromise the game’s database and steal user data.
The CyberNews.com Investigation team discovered a critical vulnerability in Street Mobster, a browser-based massively multiplayer online game created by Bulgarian development company BigMage Studios.
Street Mobster is a free to play, browser-based online game in the mafia empire genre where players manage a fictional criminal enterprise. The game boasts a 1.9+ million player base and stores a user record database that can be accessed by threat actors by committing an SQL Injection (SQLi) attack on the game’s website.
Other games created by BigMage Studios are also potentially vulnerable to the same type of attack, which means that there is a possibility that even more users might be at risk.
The records that can be compromised by exploiting the SQLi vulnerability in Street Mobster potentially include the players’ usernames, email addresses, and passwords, as well as other game-related data that is stored on the database.
Fortunately, after we reported the vulnerability to BigMage Studios, CERT Bulgaria, and the Bulgarian data protection authority, the issue has been fixed by the developers and the user database is no longer accessible to potential attackers.
What is SQL Injection?
First found back in 1998, SQLi is deemed by the Open Web Application Security Project (OWASP) as the number one web application security risk.
Even though this vulnerability is relatively easy to fix, researchers found that 8% of websites and web applications are still vulnerable to SQLi attacks in 2020. Which, from a security perspective, is inexcusable. So much so, in fact, that UK internet service provider TalkTalk was hit with a record £400,000 fine over succumbing to a cyberattack that involved SQLi.
The vulnerability works by injecting an unexpected payload (a piece of code) into the input box on the website or in its URL address. Instead of reading the text as part of the URL, the website’s server reads the attacker’s payload as code and then proceeds to execute the attacker’s command or output data that would otherwise be inaccessible to unauthorized parties. Attackers can exploit SQLi even further by uploading pieces of code or even malware to the vulnerable server.
The fact that Street Mobster is susceptible to SQLi attacks clearly shows the disappointing and dangerous neglect of basic security practices on the part of the developers at BigMage Studios.
How we found this vulnerability
Our security team identified an SQL Injection vulnerability on the Street Mobster website and were able to confirm the vulnerability by performing a simple command injection test on the website URL. The CyberNews team did not extract any data from the vulnerable Street Mobster database.
What’s the impact of the vulnerability?
The data in the vulnerable Street Mobster database can be used in a variety of ways against the players whose information was exposed:
By injecting malicious payloads on Street Mobster’s server, attackers can potentially gain access to said server, where they can install malware on the game’s website and cause harm to the visitors – from using the players’ devices to mine cryptocurrency to redirecting them to other malicious websites, installing malware, and more.
The 1.9 million user credentials stored on the database can net the attackers user email addresses and passwords, which they can potentially use for credential stuffing attacks to hack the players’ accounts on other gaming platforms like Steam or other online services.
Because Street Mobster is a free-to-play game that incorporates microtransactions, bad actors could also make a lot of money from selling hacked player accounts on gray market websites.
What to do if you’ve been affected?
If you have a Street Mobster account, make sure to change your password immediately and make it as complex as possible. If you’ve been using your Street Mobster password on any other websites or services, change that password as well. This will prevent potential attackers from accessing your accounts on these websites in case they try to reuse your password for credential stuffing attacks.
However, it’s ultimately up to BigMage Studios to completely secure your Street Mobster account against attacks like SQLi.
Disclosure and lack of communication from BigMage Studios
Following our vulnerability disclosure guidelines, we notified the BigMage Studios about the leak on August 31, 2020. However, we received no reply. Our follow-up emails were left unanswered as well.
We then reached out to CERT Bulgaria on September 11 in order to help secure the website. CERT contacted the BigMage Studios and informed the company about the misconfiguration.
Throughout the disclosure process, BigMage Studios stayed radio silent and refused to get in touch with CyberNews.com. Due to this reason, we also notified the Bulgarian data protection agency about the incident on October 9 in the hopes that the agency would be able to pressure the company into fixing the issue.
Eventually, however, BigMage Studios appear to have fixed the SLQi vulnerability on streetmobster.com, without informing either CyberNews.com or CERT Bulgaria about that fact.
Powered by WPeMatico
Casino Content
ICONIC21 launches Football Cup-branded casino games and debut network tournament
ICONIC21 has rolled out three limited-edition Football Cup-branded casino games and launched its first network tournament, ICONIC Showdown Football Cup, running from 9th of July to 19th of July.
The new titles are Football Cup Roulette, Football Cup Blackjack 360, and Football Cup Gravity Blackjack. ICONIC21 said the releases showcase different customisation approaches, including green screen production for the roulette environment and an updated visual rebrand for its RNG blackjack table.
For Football Cup Gravity Blackjack, ICONIC21 said it used its latest LED technology and applied the Gravity Series multiplier mechanic, with a custom felt, a football gate, and bespoke 3D-printed decorations.
Alongside the three new games, ICONIC21 pointed to its previously launched slot Soccer World Championship, plus The Kickoff and Top Card, which it said received football-season branding and UI/UX updates.
The ICONIC Showdown Football Cup tournament covers 11 games in total and is positioned around the quarter finals, semi-finals and final period. ICONIC21 said 1,000 winners will share a €50,000 prize pool, and operators can enroll via their account manager or by contacting the company directly.
Edvardas Sadovskis, Chief Product Officer at ICONIC21, said:
“What I’m most proud of with this project is the turnaround. We built three fully branded, technically distinct games, enhanced existing ones with promotional branding, and launched our first-ever network tournament around them, all timed to coincide with peak player interest and traffic.
That kind of speed doesn’t happen by accident, it reflects how this team works. ICONIC Showdown is a meaningful first step for us as a provider, and launching it during the Football Cup, with this much energy around the game, feels like the right way to do it. We’re genuinely excited to see how the leaderboard shapes up and even more excited for the finals.”
The post ICONIC21 launches Football Cup-branded casino games and debut network tournament appeared first on EE Gaming | Global iGaming & Tech Intelligence Hub.
Brand Ambassador
Ronaldinho visits CreedRoomz Yerevan studio to front Marble Cup and Kickoff Roulette
CreedRoomz has brought footballer Ronaldinho to its headquarters in Yerevan, where the company filmed an “exclusive interview” with the former player in connection with two new live casino game shows, Marble Cup and Kickoff Roulette. CreedRoomz said Ronaldinho is the global ambassador for both titles.
In the interview, Ronaldinho said: “For me, it’s a great joy to be a part of this partnership. Since arriving here at the office, everyone has treated me with great affection. I already feel at home, very happy.” Asked to choose between the two games, he added: “Honestly, it’s difficult to choose one, both are wonderful, I loved them, so it’s very difficult to choose one, I think everyone will really like them, I think the whole world will really enjoy them.”
Ronaldinho also described his first impressions of the studio and gameplay: “I was surprised and very happy, everything is very beautiful, everything is very innovative, so I believe that’s why everyone will really like them, so I’m looking forward to everyone starting to enjoy them a lot.”
On why CreedRoomz expects the titles to gain traction, he said: “These are different games. I think that will attract attention, the fact that football is a global passion also helps, so I believe everyone will like it for those reasons.. and for the innovation of everything that is happening.”
CreedRoomz linked the interview to upcoming “World Cup and R10 Tournaments,” with Ronaldinho closing by telling fans: “A message of gratitude for the continued affection. I’m very happy and excited. for the next competitions for the next games, the games are all ready, I hope everyone enjoys them and everyone be very happy and have good times together.”
The post Ronaldinho visits CreedRoomz Yerevan studio to front Marble Cup and Kickoff Roulette appeared first on EE Gaming | Global iGaming & Tech Intelligence Hub.
Gamification
Soft2Bet launches MEGA Shoot World Cup gamification engine
Soft2Bet has launched MEGA Shoot, a football-themed gamification engine designed around the 2026 FIFA World Cup, aimed at helping sportsbook operators retain players during the tournament.
The product will be deployed across selected Soft2Bet brands including Betinia, Swiper, Campobet, ToonieBet and Elabet, with availability spanning markets including Denmark, Greece, Mexico, New Jersey, Ontario, Romania, and the rest of Canada, according to the company.
MEGA Shoot uses a player-versus-player best-of-five penalty shootout format. Players alternate between striker and goalkeeper, with the striker selecting where to shoot and the goalkeeper selecting where to defend. Each round resolves as a goal or a save before roles switch.
Soft2Bet said early internal results show 31.9% engagement among active players across selected brands, with 71.2% of MEGA Shoot players going on to play a second match. The company also claims a 13.5% player retention uplift.
Yoel Zuckerberg, Chief Product Officer at Soft2Bet, said: “The World Cup runs from 11 June to 19 July, so retention has to work across the full tournament calendar. MEGA Shoot gives operators a football game that players can understand quickly, with head-to-head competition tied to the sport they already follow. With almost 32% engagement among active players and about 71% converting into a second match, the early data shows how tournament-led gamification can strengthen sportsbook engagement during major football events.”
The post Soft2Bet launches MEGA Shoot World Cup gamification engine appeared first on EE Gaming | Global iGaming & Tech Intelligence Hub.
-
América Latina7 days agoLas diferencias locales de Argentina representan tanto un desafío como una oportunidad para el sector del iGaming
-
Gmonitor.ai7 days agoGmonitor llega a Latinoamérica: la plataforma de inteligencia de mercado para operadores debuta en seis mercados regulados
-
Latest News7 days agoSportradar Report | World Cup 2026: Opportunities for the Latin American Sports Betting Market
-
Baltics6 days agoDigitain Named Best Sportsbook Provider at HIPTHER Baltic & Nordics Gaming Awards 2026
-
DBET6 days agoHockeyAllsvenskan names DBET main partner in three-year deal from 2026/27
-
Blazing Flower6 days agoCT Interactive Strengthens its Presence in Romania with Newly Certified Games
-
Bigger Piggy Bank Super Wheel7 days agoInspired rolls out Bigger Piggy Bank Super Wheel and Cops ‘n’ Robbers Smash ‘N’ Grab
-
Asia6 days agoS8UL’s League of Legends roster qualifies to represent India at Asian Games 2026



