Industry News
MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability
Attackers could exploit the SQL Injection flaw to compromise the game’s database and steal user data.
The CyberNews.com Investigation team discovered a critical vulnerability in Street Mobster, a browser-based massively multiplayer online game created by Bulgarian development company BigMage Studios.
Street Mobster is a free to play, browser-based online game in the mafia empire genre where players manage a fictional criminal enterprise. The game boasts a 1.9+ million player base and stores a user record database that can be accessed by threat actors by committing an SQL Injection (SQLi) attack on the game’s website.
Other games created by BigMage Studios are also potentially vulnerable to the same type of attack, which means that there is a possibility that even more users might be at risk.
The records that can be compromised by exploiting the SQLi vulnerability in Street Mobster potentially include the players’ usernames, email addresses, and passwords, as well as other game-related data that is stored on the database.
Fortunately, after we reported the vulnerability to BigMage Studios, CERT Bulgaria, and the Bulgarian data protection authority, the issue has been fixed by the developers and the user database is no longer accessible to potential attackers.
What is SQL Injection?
First found back in 1998, SQLi is deemed by the Open Web Application Security Project (OWASP) as the number one web application security risk.
Even though this vulnerability is relatively easy to fix, researchers found that 8% of websites and web applications are still vulnerable to SQLi attacks in 2020. Which, from a security perspective, is inexcusable. So much so, in fact, that UK internet service provider TalkTalk was hit with a record £400,000 fine over succumbing to a cyberattack that involved SQLi.
The vulnerability works by injecting an unexpected payload (a piece of code) into the input box on the website or in its URL address. Instead of reading the text as part of the URL, the website’s server reads the attacker’s payload as code and then proceeds to execute the attacker’s command or output data that would otherwise be inaccessible to unauthorized parties. Attackers can exploit SQLi even further by uploading pieces of code or even malware to the vulnerable server.
The fact that Street Mobster is susceptible to SQLi attacks clearly shows the disappointing and dangerous neglect of basic security practices on the part of the developers at BigMage Studios.
How we found this vulnerability
Our security team identified an SQL Injection vulnerability on the Street Mobster website and were able to confirm the vulnerability by performing a simple command injection test on the website URL. The CyberNews team did not extract any data from the vulnerable Street Mobster database.
What’s the impact of the vulnerability?
The data in the vulnerable Street Mobster database can be used in a variety of ways against the players whose information was exposed:
By injecting malicious payloads on Street Mobster’s server, attackers can potentially gain access to said server, where they can install malware on the game’s website and cause harm to the visitors – from using the players’ devices to mine cryptocurrency to redirecting them to other malicious websites, installing malware, and more.
The 1.9 million user credentials stored on the database can net the attackers user email addresses and passwords, which they can potentially use for credential stuffing attacks to hack the players’ accounts on other gaming platforms like Steam or other online services.
Because Street Mobster is a free-to-play game that incorporates microtransactions, bad actors could also make a lot of money from selling hacked player accounts on gray market websites.
What to do if you’ve been affected?
If you have a Street Mobster account, make sure to change your password immediately and make it as complex as possible. If you’ve been using your Street Mobster password on any other websites or services, change that password as well. This will prevent potential attackers from accessing your accounts on these websites in case they try to reuse your password for credential stuffing attacks.
However, it’s ultimately up to BigMage Studios to completely secure your Street Mobster account against attacks like SQLi.
Disclosure and lack of communication from BigMage Studios
Following our vulnerability disclosure guidelines, we notified the BigMage Studios about the leak on August 31, 2020. However, we received no reply. Our follow-up emails were left unanswered as well.
We then reached out to CERT Bulgaria on September 11 in order to help secure the website. CERT contacted the BigMage Studios and informed the company about the misconfiguration.
Throughout the disclosure process, BigMage Studios stayed radio silent and refused to get in touch with CyberNews.com. Due to this reason, we also notified the Bulgarian data protection agency about the incident on October 9 in the hopes that the agency would be able to pressure the company into fixing the issue.
Eventually, however, BigMage Studios appear to have fixed the SLQi vulnerability on streetmobster.com, without informing either CyberNews.com or CERT Bulgaria about that fact.
Powered by WPeMatico
Gaming Laboratories International
GLI Promotes Patrick Cottingham to Director of Client Services, North America
Gaming Laboratories International (GLI) has promoted Patrick Cottingham to Director of Client Services, North America. Previously, he served as Senior Manager of Client Services. Prior to commencing his career as an engineer with GLI, he served with the US Air Force.
Cottingham’s dedication to his clients was clearly evident both inside and outside of GLI. He transitioned to the Client Services team where he progressed and built a team laser focused on providing the very best customer service where his and his team’s clients have benefited from his engineering and gaming experience.
Ian Hughes, GLI Chief Revenue Officer, said: “We are thrilled to announce Patrick’s well-deserved promotion to Director of Client Services for North America. Patrick leads a team of dedicated and committed client services representatives who ensure our clients receive the best service during their compliance journey with GLI.”
The post GLI Promotes Patrick Cottingham to Director of Client Services, North America appeared first on Americas iGaming & Sports Betting News.
Blueprintx
Zingo Bingo Launches “Your Era” Nostalgia Series Featuring Kerry Katona and Pat Sharp
Zingo Bingo Launches “Your Era” – A Social-First Nostalgia Series for 2026
Zingo Bingo has officially unveiled Your Era, a new short-form social media content series celebrating iconic throwbacks, shared nostalgia and the cultural moments that defined generations. The series launches in February 2026 and will roll out weekly across TikTok, Instagram, Facebook and YouTube.
Designed to strengthen Zingo Bingo’s identity as a home of nostalgic fun, Your Era focuses on authentic conversation rather than traditional promotional content. The format highlights music, fashion, technology and pop culture milestones that shaped each guest’s personal journey.
Kerry Katona and Pat Sharp Headline Series One
The first confirmed guests include Kerry Katona, singer and media personality best known from Atomic Kitten, and Pat Sharp, the iconic radio and TV presenter associated with classic UK entertainment shows. Additional celebrity names will be revealed throughout the year.
Each episode features five themed nostalgia segments crafted to spark memories, conversation and emotional connections among viewers.
What to Expect from “Your Era”
Every guest takes part in recurring throwback features designed to boost engagement and relatability:
- The Memory Bag – Guests reveal five nostalgic items and share the stories behind them
- Flashback Files – A rapid-fire interview covering music, fashion, tech and cultural trends
- Mixtape Memories – Guests curate throwback tracks for the official Your Era playlist
- Taste of the Past – Sampling retro sweets and snacks while rating nostalgia levels
- Yesterday’s News – A humorous headline-guessing game using real throwback media stories
The series aims to tap into the growing popularity of nostalgia-driven digital content while positioning Zingo Bingo as a community-led entertainment brand.
Built by Kinetic Digital and Blueprintx
Your Era has been developed by Zingo Bingo’s operators, Kinetic Digital, in collaboration with long-term creative partner Blueprintx. Blueprintx has previously supported digital and television campaigns for Kinetic Digital brands including Prime Casino and Slingo.
The production strategy prioritises shareable, short-form content optimised for social discovery and influencer amplification, with episodes distributed across dedicated platform pages as well as guest channels.
A Strategic Play for Community Engagement
Jack Watson, Brand Manager at Zingo Bingo, said the series reflects the brand’s commitment to fun, familiarity and connection.
“Your Era is about celebrating the music we replayed, the fads we cringe at and the memories that still make us smile. It’s designed to bring people together through shared nostalgia while reminding audiences that bingo is about enjoying those moments collectively.”
Series one will feature six guests throughout 2026, with new weekly segments designed to drive audience engagement and repeat viewership.
The post Zingo Bingo Launches “Your Era” Nostalgia Series Featuring Kerry Katona and Pat Sharp appeared first on Eastern European Gaming | Global iGaming & Tech Intelligence Hub.
Industry News
Ex-Paysafe VP Justin Fraser takes chief revenue officer role at Yaspa to drive global growth
Yaspa, the renowned fintech focusing on instant payments and identity solutions, today reveals the appointment of Justin Fraser as its Chief Revenue Officer.
Fraser becomes part of Yaspa’s executive team during a crucial period of global growth. He has more than 20 years of commercial leadership experience in the payments ecosystem, having occupied senior leadership positions at notable industry companies like Cybersource, Visa, and Paysafe.
Having a career centered on maneuvering through intricate payment environments, he offers knowledge in rapidly expanding, regulated sectors such as iGaming, cryptocurrency, and financial technology.
As the new CRO, Fraser will manage Yaspa’s worldwide commercial strategy, concentrating on expanding the company’s Intelligent Payment platform, which integrates open banking with AI-powered customer insights, throughout the UK, Europe, and North America.
Yaspa CEO James Neville said: “We are thrilled to welcome Justin to the team during this period of rapid acceleration. His deep expertise in navigating complex regulatory environments and his proven track record in scaling payment solutions are invaluable assets as we expand our footprint in the US and beyond. Justin’s appointment further strengthens our leadership as we continue to help businesses lower costs, grow revenues, and enhance financial compliance through open banking.”
Justin Fraser said: “Yaspa is at the forefront of the shift toward real-time payments. The company’s unique blend of open banking and AI-verified insights solves genuine friction for merchants, particularly in industries like iGaming. I am excited to join such an innovative team and look forward to driving the next phase of our commercial growth globally.”
Fraser will collaborate closely with the recently strengthened US team, which includes the newly appointed US Sales Lead, Peter Kula, and US Senior Solutions Manager, Jackson Esoda.
This statement comes after a year of significant growth for Yaspa, highlighted by increasing its workforce from 15 to 75 employees and successfully securing a $12 million investment round spearheaded by Discerning Capital. In this timeframe, the firm broadened its international presence with new ventures in Atlanta and Leeds, while winning esteemed honors such as the 2025 Payments Award for Real-Time Payments Innovation and a spot on the CB Insights Top 100 Fintech list.
The post Ex-Paysafe VP Justin Fraser takes chief revenue officer role at Yaspa to drive global growth appeared first on Eastern European Gaming | Global iGaming & Tech Intelligence Hub.
-
Amusnet6 days agoWeek 7/2026 slot games releases
-
Aphrodite’s Kiss6 days agoLove on the Reels: Slotland Introduces “Aphrodite’s Kiss”
-
Brino Games6 days agoQTech Games integrates more creative content from Brino Games
-
Baltics7 days agoEstonia to Reinstate 5.5% Online Gambling Tax From March 1
-
Denmark7 days agoRoyalCasino Partners with ScatterKings for Company’s Danish Launch
-
Booming Games7 days agoTreasure Hunt Revival — Booming Games Launches Gold Gold Gold Hold and Win
-
Bet Rite7 days agoSpintec Expands into Canada with Bet Rite
-
ELA Games7 days agoELA Games Unveils Tea Party of Fortune — A Magical Multiplier Experience



