Latest News
Popular Gambling App Exposed Millions of Users in Massive Data Leak
Led by Noam Rotem and Ran Locar, vpnMentor’s research team discovered a data breach on casino gambling app Clubillion.
The breach originated in a technical database built on an Elasticsearch engine and was recording the daily activities of millions of Clubillion players around the world.
Aside from leaking activity on the app, the breached database also exposed private user information.
With this information publicly available, Clubillion’s users were vulnerable to fraud and various online attacks with potentially devastating results.
Company Profile
Clubillion is a free online casino game available for iOS and Android, offering players 30+ free slot games. While each app is listed under a different developer – Ouroboros on iOS and T7 Games on Android – these are most likely owned by the same company.
Both versions of Clubillion were released in 2019 and became instant hits. Each is now ranked the #1 ‘social slots’ casino app on Google Play and the App Store, with a 4.8 star on both.
Timeline of Discovery and Owner Reaction
Sometimes, the extent of a data breach and the owner of the database are obvious, and the issue quickly resolved. But rare are these times. Most often, we need days of investigation before we understand what’s at stake or who’s leaking the data.
Understanding a breach and its potential impact takes careful attention and time. We work hard to publish accurate and trustworthy reports, ensuring everybody who reads them understands their seriousness.
Some affected parties deny the facts, disregarding our research, or playing down its impact. So, we need to be thorough and make sure everything we find is correct and accurate.
In this case, the database was built on Elasticsearch and hosted on Amazon Web Services (AWS), with Clubillion’s name on its apps, and links to assets owned by the company.
Once Clubillion was confirmed as the owner of the database, we reached out to the developers. While awaiting a reply, we also contacted AWS with details of the leak. It was closed a few days later.
- Date discovered: 19th March 2020
- Date vendors contacted: 23rd March 2020
- Date of contact with AWS: 31st March 2020
- Date of Action: Approx. 5th April 2020
Example of Entries in the Database
Clubillion’s exposed database contained technical logs for millions of Clubillion users around the world, on both iOS and Android devices. Every time an individual player took any action on the app, a record was logged. Examples of records include:
- “enter game”
- “win”
- “lose”
- “update account”
- “create account”
During our investigation of the database, new entries continued to appear continuously. We estimated an average of approximately 200 million records per day – and sometimes, considerably more.
In total, this amounted to over 50GB of exposed records in the database every single day.
Within many of these records, were various forms of user Personally Identifiable Information (PII) data, including:
- IP addresses
- Email addresses
- Winnings
- Private messages
This data breach was truly global, with millions of records originating from Clubillion’s daily users all over the world. The following list is just a sample of countries affected, along with the average number of daily users from each country:
- USA – 10,000+
- UK – 2,475+
- France – 1,650+
- Israel – 408+
- Germany – 1,582+
- Spain – 1,026+
- Italy – 2,407+
- Netherlands – 622+
- Australia – 6,251+
- Canada – 7,792+
- Brazil – 3,859+
- Sweden – 191+
- Russia – 547+
Other countries affected included Uzbekistan, India, Poland, Romania, Vietnam, Lebanon, Indonesia, Philippines, Pakistan, Thailand, Austria, Hungry, and Latvia.
As you can see, on a single day, 10,000s of individual Clubillion players were exposed. Each one of these players could be targeted by malicious hackers for fraud and cyberattacks – along with millions more whose records were also contained in the database.
Data Breach Impact
Studies have shown that free gambling and gaming apps are especially prone to attacks and hacking from cybercriminals. They are routinely targeted for theft of private data and embedding malicious software on users’ devices.
Despite their popularity, gambling and casino apps often lack transparency, and it can be impossible to know what steps they’re taking to prevent cybercriminals successfully targeting their users.
One study of 23,000 free gambling apps found that: 3,200 posed a ‘moderate risk’ to users; 379 had known security vulnerabilities; 52 contained malicious software.
Any of these issues could be exploited to target app users in a wide range of frauds and cyberattacks, and Clubillion is no different.
With the exposed user PII and knowledge of their activity on the app, hackers could create elaborate schemes to defraud users. For example, some entries also included transaction errors for attempted card payments on Clubillion.
With the information in these transaction errors, hackers could target users with phishing campaigns, with the following aims:
- Trick them into providing their credit card details
- Trick them into providing additional PII to be used against them in further fraud
- Clicking a link that embeds malware, spyware, or ransomware onto their device.
If cybercriminals used Clubillion to embed malware or similar onto a user’s phone, they could potentially hack other apps, access files stored on the device, make calls, and send texts from the hacked device. They could even access a user’s phone contacts and steal the PII data of their friends and family.
Worse still, as people across the globe now find themselves under quarantine or self-isolation, as a result of the Coronavirus pandemic, the impact of a leak like this is potentially even more significant.
Clubillion stands to gain many new users, along with regular users playing more frequently. Hackers will be aware of this and looking for opportunities to exploit any vulnerabilities in the data security of such a massively popular app.
Had criminal hackers discovered Clubillion’s database, they could have targeted millions of people around the world, with devastating results.
Impact on Clubillion and it’s Developers
The most immediate risk for Clubillion is the loss of players. Data security is a growing concern for everyone these days, and this leak could turn many players off the app. Clubillion is not unique, and players have plenty of other choices for free gambling apps.
With fewer players, Clubillion will lose advertising revenue and reduced profits.
As many of Clubillion’s players reside within the EU, the app is under the jurisdiction of GDPR. The rules of GDPR also apply to apps, and Clubillion will need to take specific actions to ensure the regulatory body in charge doesn’t reprimand it.
Finally, Clubillion could also potentially be removed from Google Play and the App Store. Both Apple and Google are clamping down on apps that pose a risk to their users, removing apps embedded with malware, and taking data leaks much more seriously.
Each of these outcomes has a different likelihood of happening, but they would all negatively impact Clubillion’s revenue and business.
Advice from the Experts
Clubillion’s developers could have easily avoided this leak if they had taken some basic security measures to protect the database. These include, but are not limited to:
- Securing their servers.
- Implementing proper access rules.
- Never leaving a system that doesn’t require authentication open to the internet.
Any company can replicate the same steps, no matter its size.
For a more in-depth guide on how to protect your business, check out our guide to securing your website and online database from hackers.
For Clubillion Users
If you play on Clubillion and are concerned about how this breach might impact you, contact the app’s developers directly to find out what steps it’s taking to protect your data.
To learn about data vulnerabilities in general, read our complete guide to online privacy.
It shows you the many ways cybercriminals target internet users, and the steps you can take to stay safe.
How and Why We Discovered the Breach
The vpnMentor research team discovered the breach in Clubillion’s database as part of a huge web mapping project. Our researchers use port scanning to examine particular IP blocks and test different systems for weaknesses or vulnerabilities. They examine each weakness for any data being leaked.
Our team was able to access this database because it was completely unsecured and unencrypted.
Whenever we find a data breach, we use expert techniques to verify the owner of the database, usually a commercial company.
As ethical hackers, we’re obliged to inform a company when we discover flaws in their online security. We reached out to Clubillion’s developers, not only to let them know about the vulnerability but also to suggest ways in which they could make their system secure.
These ethics also mean we carry a responsibility to the public. Clubillion users must be aware of a data breach that exposes so much of their sensitive data.
The purpose of this web mapping project is to help make the internet safer for all users.
Powered by WPeMatico
Latest News
From Vision to Execution. Inside Game Creation: Interview with Will and Ray at DreamPlay
In recent years, the iGaming industry has been evolving at an exceptional pace, driven by technological advancements, innovative mechanics, and a deeper understanding of player psychology. Behind every successful slot or casual title stands a team of specialists who transform concepts into polished, engaging experiences enjoyed by players worldwide.
To shed light on how this creative and highly technical process unfolds within DreamPlay, we spoke with Game Producer Ray and Game Designer Will. They shared their insights into modern game development, the principles that guide their decisions, and the factors that shape the creation of new titles in a rapidly changing market.
Q1. Core Elements of Player Perception
Which elements of game design — from mathematical logic to gameplay pace — most often have a decisive influence on a player’s perception of the game?
Will:
It’s all important. The rhythm and potential in the Math balance, the way mechanics are designed and interact with each other, symbols looking and animating in an appealing way, to both avoiding there being repetitive sounds that annoy Players and sounds that celebrate their highs. They all contribute to the overall Player experience.
As a Game Designer, the biggest priority I have is the Player experience, and to achieve that we make sure everyone who contributes to the game is working toward the same goal and supporting every element regardless of the department; for example, ensuring the sound design hypes up the big moments in the Math model or making sure the art and animation properly communicate how the mechanics function.
Q2. Differentiating Similar Slots
In your experience, what makes the difference in production dynamics between slots with similar mechanics? Which development parameters are most critical for the final result?
Ray:
Even when two slots share similar features or math models, the theme, the way the gameplay is presented, and the pacing make a huge difference in how the final product feels. Players can sense a well-balanced math model without needing to understand the technical details — they just feel rewarded for playing, and they understand what the game is trying to offer them.
For us, creating a great player experience is the real differentiator. It’s what separates our games from competitors, even when the mechanics look similar on paper.
Q3. Emotional Triggers in Game Design
In your experience, what design choices have the strongest impact on players’ emotional responses, and how do you approach creating them?
Will:
Some of the strongest emotional responses come from when the Player makes an assumption about the way a feature works, then gets that confirmed with a big win or progression towards something big — the whole potential of the game opens up to them. That’s when the imagination takes over with questions like “What if this mechanic works with that one? That could be huge.” It cements that desire to fully explore the game and everything it has to offer.
Q4. Late-Stage Adjustments in Development
When you have to tweak a game in the later stages of development, what factors usually cause the changes?
Will:
Usually, it’s a complex UI element for an equally complex mechanic; elements like that often need many iterations to make sure we’re communicating to the Player in a way that makes sense to them. One of the biggest barriers preventing Players from enjoying the game is their understanding of it, so effective communication is incredibly important.
It’s never a waste of time to break down that barrier as much as possible so the games can be experienced in their full form.
Q5. Underrated Stages of Slot Development
In your opinion, which stage of slot creation is most often underestimated, even though it affects the integrity of the final product?
Ray:
I think the most underestimated stage is actually the final stretch — the polish and QA phase. This is where we identify small improvements that make the game feel tight, consistent, and enjoyable, and it’s also where we make sure everything meets our quality standards and jurisdictional requirements.
It’s easy to overlook how important this stage is, but it’s often what determines whether the final product feels truly finished.
Q6. A Benchmark Project for the Team
Which project in your practice has become a benchmark for you in production, and what has it taught the team in terms of development efficiency and quality?
Ray:
DreamPlay is still a new company, and we’re all learning how to work together and build our own production rhythm. One project that really stands out for us is Moon Joker. It came together in a way that showed what we’re capable of when every department is aligned.
We had a strong concept; we kept things simple and classic, but we still found room to innovate. Art, design, math, audio, and engineering all pushed in the same direction, and you’ll be able to see that in the final product. It’s a great example of what our team can achieve when everything clicks.
Discover more from DreamPlay:
Danny Gordon Director of Games at DEGEN Studios
DEGEN’s Creative Charge: Danny Gordon on Disruption, Player-First Design and the Future of High-Voltage iGaming Content
Reading Time: 3 minutes
Introduction
DEGEN Studios has quickly carved out a reputation as one of the sector’s boldest emerging forces, delivering high-volatility content designed for players who want every spin to feel alive. As the studio prepares for its next phase of accelerated growth, European Gaming sat down with newly appointed Director of Games, Danny Gordon, to explore his journey through some of the industry’s most influential creative environments and understand why DEGEN’s vision resonates so strongly with him.
With close to ten years across Microgaming, Entain and Four Leaf Gaming, Danny brings a rare blend of analytical expertise, product design insight, and a creative instinct shaped by building successful in-house studios from the ground up. In this exclusive interview, he shares what drew him to DEGEN, how he defines player-first development in a crowded market, and why the biggest opportunities now lie in high-energy content that is unafraid to take risks.
First of all, can you introduce yourself and tell us about your background?
Danny Gordon, and I’ve been working in iGaming for the best part of a decade now. I started my career at Microgaming, working as a publisher and moved onto a business analyst.
In 2020, I made the move to Entain, where I initially worked as a Games Designer. This really allowed me to explore the creative side to slot games. I then created the newest in-house studio Vertical Games in 2022 initially as a label to break the mould of in house content, which evolved to a fully funded in house studio.
There, I worked alongside an amazing team and created a range of innovative slot games that I’m really proud of. After two years in the role, I became Director of Games at Four Leaf Gaming, further mastering my craft before joining DEGEN.
What was it that attracted you to DEGEN Studios?
The energy. DEGEN is a brand with a clear mission: disruption. The company’s approach to gaming is bold and innovative, and I can’t wait to start bouncing ideas off with the team.
I believe the company want to do something totally different, and on a professional level, this presents an exciting challenge for me. Creative freedom is essential in my role, and DEGEN is a brand that will allow my creativity to flourish.
How would you describe your approach to game development?
Player-first.
My approach to game development has always been player-first and DEGEN’s for players, by players philosophy really resonated with me, it was created by gamers who live and breathe this world, and that perspective shapes every slot we make. We design from the inside out, asking: how does it feel, how does it hit, what makes it unforgettable?
I also believe collaboration is key. The best ideas can come from anywhere, and my job is to create a space where those ideas can grow and evolve into something special. There’s no hierarchy at DEGEN, we’re a team with a shared vision and a shared passion for making games that genuinely excite people.
What’s your take on the current state of iGaming, and where do you see the biggest opportunities for innovation?
There’s a lot of great work happening across iGaming, but I think there’s still a real gap when it comes to truly high-volatility, high-energy content. Many studios are focusing on what’s proven to work, which makes sense commercially, but it leaves room for innovation. Players today want experiences that feel different, games that take risks and deliver real adrenaline.
That’s where DEGEN stands out. We’re focused on exploring mechanics and themes that break routine. For us, innovation means making every spin feel alive – unpredictable, bold, and built around the player’s excitement. That’s the space I see as the biggest opportunity right now.
What can we expect from DEGEN in the coming months?
While I can’t reveal any specific details, let me just say that you can expect DEGEN to turn up the volume even louder with their next few releases. DEGEN’s original slate of titles has already been a huge hit, but these are only a taste of what the studio is capable of.
Our focus is on continuing to evolve and deliver experiences that truly engage players. The next wave of games builds on everything we’ve learned so far – deeper concepts, bolder ideas, and afresh energy running through each release. For DEGEN Studios, this is only the start.
I’m equally as excited about what we can deliver from a product roadmap POV as much as the content roadmap and all I can say is watch this space!
Looking further ahead, where do you see DEGEN Studios positioned in the market five years from now?
I want DEGEN to be a name people instantly associate with innovation, disruption, and quality. We have a clear roadmap to success, and we are not wasting any time in implementing it. Whenever a new DEGEN game is released, it should feel like an event.
We are already building a loyal player base that will undoubtedly play its part in helping us build our future, and we cannot wait to see what the coming years bring.
The post DEGEN’s Creative Charge: Danny Gordon on Disruption, Player-First Design and the Future of High-Voltage iGaming Content appeared first on European Gaming Industry News.
B2B Marketing Team of the Year
Inside the Mind of an Industry Leader: SOFTSWISS CMO Valentina Bagniya on Team Building, Creativity, and Global Growth
Reading Time: 6 minutes
This year marked significant progress for the SOFTSWISS marketing function – new initiatives, new markets, and recognition through four major marketing awards, including Marketer of the Year and B2B Marketing Team of the Year. To better understand your path as a leader, let’s go back to where it all began. What brought you into marketing, and what ultimately inspired your move into iGaming?
Oh, this question takes me way back. I grew up in a family where both of my parents studied in the Faculty of Philosophy. So, when it came time for me to choose a university and a field of study, their academic background definitely played a role – it stayed with me and influenced my thinking. That’s why I also decided to apply to the Faculty of Philosophy.
But I never really saw myself as a philosopher. One of the departments within the faculty was quite new – it had only been established a few years earlier. It was called ‘Information and Communication’. When I read the programme description and visited the university for the open day, I realised that the department was closely connected to advertising, marketing, and PR. And that sparked a huge interest in me. I thought, “This is great – I should give it a try!” Back then, I honestly thought marketing was mostly about creating commercials. That was the image I had.
So that’s how I ended up studying at the Faculty of Philosophy, in the Information and Communication department – and that’s where I got my first real introduction to marketing. Though in reality, I didn’t go into pure marketing right after graduation. My first job was actually in analytics. I worked as an analyst first in a consulting company, and then at British American Tobacco.
To be honest, I think that was probably the best possible starting point for someone entering the marketing field. Understanding the value of data and analytics is absolutely critical and fosters strategic thinking. Many people, even those working in the industry, still see marketing primarily as something purely creative and imaginative. But to create truly impactful campaigns, you have to work precisely with numbers, data, and research. You must think about the strategy based on the data first, and only after that, think about the bright execution.
So,I could say my parents led me into marketing.
Leading a marketing team of more than 70 people at SOFTSWISS requires a thoughtful approach to talent management. What qualities do you prioritise when shaping a team of this scale?
Let’s probably start with the basics.
At the foundation of any strong team are professionals who are capable of doing their jobs well. That’s why it’s important for me to make sure that the people I bring onto the team possess the necessary hard skills in their respective fields.
However, even more important to me are personal traits and qualities. There are a few things I pay particular attention to.
First and foremost – responsibility: the ability to take ownership of one’s actions, decisions, and their consequences, and to understand how those decisions affect the company, our clients, and the team as a whole.
Second – ambition. To me, being ambitious means not settling for the safe or easy route. It’s about setting bold goals and having the drive to achieve them. I truly believe that ambitious people drive progress – they push themselves and others forward, helping the company grow and achieve meaningful results.
Closely related to this is a results-oriented mindset. It’s easy to fall into a routine of just completing tasks, forgetting that each task exists to serve a bigger purpose: to create an impact for the business. A bold, creative campaign might look great on the surface, but what really matters is whether it delivered business results and made a tangible difference. So I would even rephrase that: it’s not just about focusing on results – it’s about understanding what those results mean for the business and aligning your actions with that.
When we talk about building a team, I also consider collaboration and team cohesion. In a large team, it’s critical to understand that there aren’t just “my” goals or “someone else’s” goals – there are our goals. Supporting one another and working as a unified whole is essential. Team members who are engaged and involved contribute to high performance and shared success.
I also value qualities like curiosity, because without the desire to learn, ask questions, and explore new ideas, it’s hard to grow. I look for creativity, the ability to go beyond the obvious, to bring fresh perspectives and non-standard solutions. And finally, I’d add proactiveness and courage, which in many ways go hand in hand with ambition. These are the key qualities I look for when I’m building a team.
What inspires you?
What inspires me?
I’d probably name two things. The first is the people I work with. This includes my leaders, those who set ambitious goals, grant their trust and support in the process of achieving them, and give me space to evolve. And of course, it’s my team, the people I work with every single day. Watching how they overcome challenges and grow beyond what they thought was possible is incredibly energising. Sometimes they don’t even believe they can do something – and then they face their fears, push through, and deliver amazing results. That kind of transformation truly inspires me.
Second – I’m naturally a goal-driven person. I’m deeply inspired by achievement – both my team’s and my own. iGaming is an industry where you see the impact almost immediately – the feedback loop is fast, the competition strong, and the bar always rising. That energy is inspiring.
So yes – it’s the people and the results we achieve together that inspire me the most.
Let’s talk about a couple of projects/work you are proud of. What makes them special to you?
Well, I’d say the one I’m most proud of is the team I’ve built from scratch at the company where I currently work. This team played a key role in helping me elevate SOFTSWISS from a local brand to the international stage, turning it into one of the most respected and influential names in the iGaming industry.
When it comes to marketing campaigns that stand out and make me proud, one in particular comes to mind: our “Bringing the Heat” campaign. It was a game-changer – it challenged the more traditional approach in B2B iGaming marketing and helped SOFTSWISS take the lead.
The campaign received multiple awards, and its strength came from two factors. First, we used an unconventional creative approach – something you’d typically see in FMCG or emotional consumer brands, not in B2B tech. It was bold, vivid, and emotionally engaging.
Second, the channel mix we used was truly unique for the B2B space. Instead of relying solely on traditional digital channels, direct mail, and sales outreach, we took into account the unique character of the Maltese market, where the campaign was launched. Given that a significant portion of the population in Malta works in iGaming, we decided to go much broader – incorporating out-of-home advertising, radio, and even BTL activations.
The result? A significant boost in brand awareness and – just as importantly – in actual business results. Today, this campaign is seen as a benchmark in B2B marketing within iGaming, and we’ve already noticed other companies following the same path.
What advice would you give to people starting out in the industry today?
I have a pretty long list, but it’s doable, believe me.
- Develop strategic thinking and the ability to think big.
- Enhance your emotional intelligence to establish effective relationships with key stakeholders and empower your team.
- Be proactive and persistent – this will help you achieve the hardest goals.
- Develop adaptability and the ability to pivot and navigate uncertainty when the context changes.
- Be technology and analytics-savvy.
- Learn from everything and everywhere, especially from mistakes, whether your own or others’, as this is about creating and cultivating a growth mindset.
- Attend industry events, learn how different markets work.
- And don’t underestimate the importance of understanding compliance and regulations. They shape how marketing can and should function in iGaming.
What challenges and opportunities do you see for marketing teams in iGaming going forward?
Marketing today faces a paradoxical situation: we’ve never had more tools, channels, and data – and yet never faced more complexity in connecting meaningfully with people.
The biggest challenge? Consistency.
The pace of change tempts teams to chase everything – every trend, every new platform, every buzzword.
But the brands that win will be the ones that simplify. That stands for something clear, consistent, and relevant across markets and generations. Focus and consistency are the new superpowers.
Another challenge is trust.
Consumers and customers are more sceptical than ever, especially in iGaming. One misstep can become global in minutes. So building brand trust is not a campaign – it’s a discipline. And it must be rooted in real action: in how we show up, the values we live by, and the impact we create.
The opportunity?
To continue with the classic way of marketing, where strategy comes first. Marketing teams that combine creativity, empathy, and strategic focus with smart use of technology won’t just adapt – they’ll lead.
The post Inside the Mind of an Industry Leader: SOFTSWISS CMO Valentina Bagniya on Team Building, Creativity, and Global Growth appeared first on European Gaming Industry News.
-
Balkans7 days agoCT Gaming Shortlisted in Three Categories at BEGE Awards 2025
-
2025 Global Regulatory Awards7 days agoVixio Announces Winners for the 2025 Global Regulatory Awards
-
Booming Games7 days agoHo-Ho-Hold onto Your Wins! Booming Games Takes Festive Fun to the Next Level with Santa in Vegas!
-
Betclic7 days agoBetclic Becomes the First French Operator to Earn RG Check Certification
-
BGaming6 days agoWeek 47/2025 slot games releases
-
Australia6 days agoVGCCC: EGM Application Improvements Consultation
-
CT Interactive7 days agoCT Interactive Expands in Romania with New Game Launch on Maxbet.ro
-
Anthony Dalla-Giacoma7 days agoSwintt serve up a new holiday slot with all the trimmings in Extra Win X Thanksgiving



