Connect with us

Latest News

Popular Gambling App Exposed Millions of Users in Massive Data Leak

Published

on

Reading Time: 5 minutes

 

Led by Noam Rotem and Ran Locar, vpnMentor’s research team discovered a data breach on casino gambling app Clubillion.

The breach originated in a technical database built on an Elasticsearch engine and was recording the daily activities of millions of Clubillion players around the world.

Aside from leaking activity on the app, the breached database also exposed private user information.

With this information publicly available, Clubillion’s users were vulnerable to fraud and various online attacks with potentially devastating results.

Company Profile

Clubillion is a free online casino game available for iOS and Android, offering players 30+ free slot games. While each app is listed under a different developer – Ouroboros on iOS and T7 Games on Android – these are most likely owned by the same company.

Both versions of Clubillion were released in 2019 and became instant hits. Each is now ranked the #1 ‘social slots’ casino app on Google Play and the App Store, with a 4.8 star on both.

Timeline of Discovery and Owner Reaction

Sometimes, the extent of a data breach and the owner of the database are obvious, and the issue quickly resolved. But rare are these times. Most often, we need days of investigation before we understand what’s at stake or who’s leaking the data.

Understanding a breach and its potential impact takes careful attention and time. We work hard to publish accurate and trustworthy reports, ensuring everybody who reads them understands their seriousness.

Some affected parties deny the facts, disregarding our research, or playing down its impact. So, we need to be thorough and make sure everything we find is correct and accurate.

In this case, the database was built on Elasticsearch and hosted on Amazon Web Services (AWS), with Clubillion’s name on its apps, and links to assets owned by the company.

Once Clubillion was confirmed as the owner of the database, we reached out to the developers. While awaiting a reply, we also contacted AWS with details of the leak. It was closed a few days later.

  • Date discovered: 19th March 2020
  • Date vendors contacted: 23rd March 2020
  • Date of contact with AWS: 31st March 2020
  • Date of Action: Approx. 5th April 2020

Example of Entries in the Database

Clubillion’s exposed database contained technical logs for millions of Clubillion users around the world, on both iOS and Android devices. Every time an individual player took any action on the app, a record was logged. Examples of records include:

  • “enter game”
  • “win”
  • “lose”
  • “update account”
  • “create account”

During our investigation of the database, new entries continued to appear continuously. We estimated an average of approximately 200 million records per day – and sometimes, considerably more.

In total, this amounted to over 50GB of exposed records in the database every single day.

Within many of these records, were various forms of user Personally Identifiable Information (PII) data, including:

  • IP addresses
  • Email addresses
  • Winnings
  • Private messages

This data breach was truly global, with millions of records originating from Clubillion’s daily users all over the world. The following list is just a sample of countries affected, along with the average number of daily users from each country:

  • USA – 10,000+
  • UK – 2,475+
  • France – 1,650+
  • Israel – 408+
  • Germany – 1,582+
  • Spain – 1,026+
  • Italy – 2,407+
  • Netherlands – 622+
  • Australia – 6,251+
  • Canada – 7,792+
  • Brazil – 3,859+
  • Sweden – 191+
  • Russia – 547+

Other countries affected included Uzbekistan, India, Poland, Romania, Vietnam, Lebanon, Indonesia, Philippines, Pakistan, Thailand, Austria, Hungry, and Latvia.

As you can see, on a single day, 10,000s of individual Clubillion players were exposed. Each one of these players could be targeted by malicious hackers for fraud and cyberattacks – along with millions more whose records were also contained in the database.

Data Breach Impact

Studies have shown that free gambling and gaming apps are especially prone to attacks and hacking from cybercriminals. They are routinely targeted for theft of private data and embedding malicious software on users’ devices.

Despite their popularity, gambling and casino apps often lack transparency, and it can be impossible to know what steps they’re taking to prevent cybercriminals successfully targeting their users.

One study of 23,000 free gambling apps found that: 3,200 posed a ‘moderate risk’ to users; 379 had known security vulnerabilities; 52 contained malicious software.

Any of these issues could be exploited to target app users in a wide range of frauds and cyberattacks, and Clubillion is no different.

With the exposed user PII and knowledge of their activity on the app, hackers could create elaborate schemes to defraud users. For example, some entries also included transaction errors for attempted card payments on Clubillion.

With the information in these transaction errors, hackers could target users with phishing campaigns, with the following aims:

  1. Trick them into providing their credit card details
  2. Trick them into providing additional PII to be used against them in further fraud
  3. Clicking a link that embeds malware, spyware, or ransomware onto their device.

If cybercriminals used Clubillion to embed malware or similar onto a user’s phone, they could potentially hack other apps, access files stored on the device, make calls, and send texts from the hacked device. They could even access a user’s phone contacts and steal the PII data of their friends and family.

Worse still, as people across the globe now find themselves under quarantine or self-isolation, as a result of the Coronavirus pandemic, the impact of a leak like this is potentially even more significant.

Clubillion stands to gain many new users, along with regular users playing more frequently. Hackers will be aware of this and looking for opportunities to exploit any vulnerabilities in the data security of such a massively popular app.

Had criminal hackers discovered Clubillion’s database, they could have targeted millions of people around the world, with devastating results.

Impact on Clubillion and it’s Developers

The most immediate risk for Clubillion is the loss of players. Data security is a growing concern for everyone these days, and this leak could turn many players off the app. Clubillion is not unique, and players have plenty of other choices for free gambling apps.

With fewer players, Clubillion will lose advertising revenue and reduced profits.

As many of Clubillion’s players reside within the EU, the app is under the jurisdiction of GDPR. The rules of GDPR also apply to apps, and Clubillion will need to take specific actions to ensure the regulatory body in charge doesn’t reprimand it.

Finally, Clubillion could also potentially be removed from Google Play and the App Store. Both Apple and Google are clamping down on apps that pose a risk to their users, removing apps embedded with malware, and taking data leaks much more seriously.

Each of these outcomes has a different likelihood of happening, but they would all negatively impact Clubillion’s revenue and business.

Advice from the Experts

Clubillion’s developers could have easily avoided this leak if they had taken some basic security measures to protect the database. These include, but are not limited to:

  1. Securing their servers.
  2. Implementing proper access rules.
  3. Never leaving a system that doesn’t require authentication open to the internet.

Any company can replicate the same steps, no matter its size.

For a more in-depth guide on how to protect your business, check out our guide to securing your website and online database from hackers.

For Clubillion Users

If you play on Clubillion and are concerned about how this breach might impact you, contact the app’s developers directly to find out what steps it’s taking to protect your data.

To learn about data vulnerabilities in general, read our complete guide to online privacy.

It shows you the many ways cybercriminals target internet users, and the steps you can take to stay safe.

How and Why We Discovered the Breach

The vpnMentor research team discovered the breach in Clubillion’s database as part of a huge web mapping project. Our researchers use port scanning to examine particular IP blocks and test different systems for weaknesses or vulnerabilities. They examine each weakness for any data being leaked.

Our team was able to access this database because it was completely unsecured and unencrypted. 

Whenever we find a data breach, we use expert techniques to verify the owner of the database, usually a commercial company.

As ethical hackers, we’re obliged to inform a company when we discover flaws in their online security. We reached out to Clubillion’s developers, not only to let them know about the vulnerability but also to suggest ways in which they could make their system secure.

These ethics also mean we carry a responsibility to the public. Clubillion users must be aware of a data breach that exposes so much of their sensitive data.

The purpose of this web mapping project is to help make the internet safer for all users.

 

Source

Powered by WPeMatico

Continue Reading
Advertisement

BetMGM

BetMGM and FashionTV Gaming Group Bring Luxury Lifestyle to North American iGaming

Published

on

betmgm-and-fashiontv-gaming-group-bring-luxury-lifestyle-to-north-american-igaming

BetMGM, a leading iGaming and sports betting operator, has officially partnered with FashionTV Gaming Group to launch a curated portfolio of luxury-branded games. This strategic collaboration marks the entry of FashionTV’s iconic aesthetic into the North American iGaming market, exclusively through BetMGM’s platforms.

The partnership merges FashionTV’s global prestige in the worlds of fashion and high-society entertainment with BetMGM’s award-winning digital casino infrastructure.

Immersive Luxury Table Games

The initial rollout features two high-gloss table games designed to provide players with an “immersive, lifestyle-driven” experience that mirrors the sophistication of the FashionTV brand.

  • FashionTV Blackjack: A premium take on the casino classic, featuring refined visual assets and high-end production values.

  • FashionTV Roulette: A sleek, stylized version of the iconic wheel, bringing a “fashion-forward” energy to every spin.

The titles are currently live in Michigan, New Jersey, and Pennsylvania, with a wider rollout planned for all jurisdictions where BetMGM Casino is active.

Strategic Vision and 2026 Roadmap

For BetMGM, the partnership is part of a broader “branded content” strategy that includes previous successes with major TV and movie franchises.

“At BetMGM, we have redefined what it means to deliver entertainment in iGaming,” said Oliver Bartlett, VP of Gaming at BetMGM. “By partnering with FashionTV Gaming Group, we’re creating experiences that go beyond gameplay and connect players to the brands they love.”

Moshe Cohen, Founder & President of FashionTV Gaming Group, added: “BetMGM’s leadership and scale make them the perfect partner to transform our vision into a North American success story.”

Looking ahead, BetMGM has confirmed that additional FashionTV-branded titles—including slots and potentially live dealer variants—will be released throughout 2026 as part of an expanding content pipeline.

The post BetMGM and FashionTV Gaming Group Bring Luxury Lifestyle to North American iGaming appeared first on Eastern European Gaming | Global iGaming & Tech Intelligence Hub.

Continue Reading

Brazil Betting Law

2026 iGaming Regulatory Roadmap: Key Compliance Deadlines

Published

on

2026-igaming-regulatory-roadmap:-key-compliance-deadlines

As the industry gathers for ICE Barcelona 2026, the regulatory landscape has shifted into a high-execution phase. The following roadmap outlines the critical compliance dates for three of the most influential markets currently undergoing major transitions: the United Kingdom, Brazil, and the Philippines.

Date Jurisdiction Regulatory Milestone Action Required for Operators/Suppliers
Jan 19, 2026 United Kingdom LCCP Social Responsibility Code 5.1.1 Update Ban on Mixed-Product Incentives: Offers like “Bet £10, get 20 free spins” are now prohibited. Wagering Caps: Bonus wagering is capped at a maximum of 10x.
Jan 19-21, 2026 Global / EMEA ICE Barcelona 2026 Flagship event for showcasing 2026 compliance technology and real-time auditing solutions.
Mar 19, 2026 United Kingdom LCCP Condition 15.2.1 Reporting Key Event Reporting: Threshold for reporting operator status/shareholder changes raised from 3% to 5%. All loans must be reported regardless of written agreements.
Mar 31, 2026 Philippines PAGCOR B2B Accreditation Deadline Final Compliance Date: All B2B providers (studios, aggregators, affiliates) must be accredited. Unaccredited foreign content will be blocked from licensed platforms.
Apr 6, 2026 United Kingdom DMCC Act 2024 Alignment Fair & Transparent Terms: Consumer Protection regulations replaced by the Digital Markets, Competition and Consumers Act 2024. Terms must align with new definitions of “misleading actions.”
June 30, 2026 United Kingdom RTS 12 (Financial Limits) Technical changes to Remote Technical Standards (RTS) regarding how customers set and view financial limits on their accounts.
H2 2026 Brazil Betting Deposit Tax Vote Proposed 15% tax on gambling deposits is expected to return to the Senate for a final vote after being pushed back in late 2025.

Regional Deep Dive: Strategic Compliance

1. United Kingdom: The “Safety & Simplicity” Era

The UKGC’s January 19th update is the most immediate challenge for marketing teams. By decoupling sports betting from casino bonuses, the regulator aims to reduce “cross-product friction” that could lead to unintended gambling harm.

  • Strategy: Pivot toward product-specific loyalty programs (e.g., “Bet £10 on Football, Get a £5 Free Bet”) to maintain compliance while driving retention.

2. Brazil: Sustaining the .bet.br Ecosystem

Following the January 1, 2025 launch of the regulated market, 2026 is about operational maturity. The focus has shifted to the mandatory use of the .bet.br domain and rigorous AML/KYC reporting to the Secretariat of Awards and Betting (SPA).

  • Strategy: Ensure all advertising features the mandatory license logo and that all protagonists in marketing materials are visibly over 21 years of age.

3. Philippines: The B2B Supply Chain Lockdown

PAGCOR’s new framework is a move to professionalize the region, mirroring the supplier-licensing models seen in Ontario and Malta.

  • Strategy: Foreign studios that missed the December 2025 “early bird” three-year accreditation window must expedite their applications before March 31st to avoid a total blackout on Filipino-facing sites.

The post 2026 iGaming Regulatory Roadmap: Key Compliance Deadlines appeared first on Eastern European Gaming | Global iGaming & Tech Intelligence Hub.

Continue Reading

AI in Gambling

2026 iGaming Outlook: Regulation, AI Personalization, and the Return of “Originals”

Published

on

2026-igaming-outlook:-regulation,-ai-personalization,-and-the-return-of-“originals”

The iGaming industry has officially entered a new era of discipline. As we move through the first quarter of 2026, the “wild west” growth of previous years has been replaced by a focus on sustainability, hyper-localization, and AI-driven player protection. From the finalization of the PROGA framework in India to the massive turnover records set by World Pool, the market is no longer just growing—it is maturing.

The Rise of “Explainable AI” in Player Retention

In 2026, AI has moved beyond simple game recommendations. Leading operators are now utilizing “Explainable AI” (XAI) to bridge the gap between engagement and compliance. Unlike traditional “black box” algorithms, XAI allows operators to understand why a player is being flagged for risky behavior or why a specific loyalty nudge was triggered.

This transparency is critical for maintaining trust in highly regulated markets like the UK and Ontario, where the UKGC’s 2026 Social Responsibility updates now demand more rigorous evidence of proactive player interaction.

“Originals” and the Rebirth of Video Poker

While high-volatility slots like Joker’s Jewels Hold & Spin™ continue to dominate headlines, a significant shift is occurring in the “non-slots” vertical.

  • The PowerPoker™ Revolution: Strategic partnerships, such as the recent QTech Games and Speedy Tomatoes deal, are revitalizing video poker. By adding features like “Swap-A-Card,” these games are capturing high-value player segments who prioritize skill and strategy.

  • Branded Originals: Platforms like MINT are proving that “Originals” (Mines, Crash, and Plinko) are no longer secondary products. Fully brandable house games are now a core foundation for crypto-first and Web3 operators, driving session frequency through provably fair mechanics.

Brazil and Ontario: The Battle for Market Supremacy

The geographic focus for 2026 remains firmly on Brazil and Ontario.

  • Brazil’s Advertising Evolution: With the newly regulated market in full swing, groups like Esportes Gaming Brasil joining IAB Brasil signal a shift toward responsible communication. Advertising is now a tool for helping consumers identify licensed platforms, moving away from aggressive acquisition tactics.

  • Ontario’s Content War: The region has become North America’s most dynamic hub. Agreements like the Peter & Sons and Casino Time deal highlight the demand for “indie-inspired” content that stands out in a saturated market.

Conclusion: The “Champion Mindset” for 2026

Success this year isn’t about volume; it’s about coherence. As highlighted by GR8 Tech’s “Champions Club” initiative for ICE Barcelona, the operators winning in 2026 are those who treat technology as a performance ecosystem. By aligning real-time data with compliant storytelling, brands are finding that “trust” is the most valuable currency in the modern iGaming world.

The post 2026 iGaming Outlook: Regulation, AI Personalization, and the Return of “Originals” appeared first on Eastern European Gaming | Global iGaming & Tech Intelligence Hub.

Continue Reading

Trending

Get it on Google Play

Fresh slot games releases by the top brands of the industry. We provide you with the latest news straight from the entertainment industries.

The platform also hosts industry-relevant webinars, and provides detailed reports, making it a one-stop resource for anyone seeking information about operators, suppliers, regulators, and professional services in the European gaming market. The portal's primary goal is to keep its extensive reader base updated on the latest happenings, trends, and developments within the gaming and gambling sector, with an emphasis on the European market while also covering pertinent global news. It's an indispensable resource for gaming professionals, operators, and enthusiasts alike.

Contact us: [email protected]

Editorial / PR Submissions: [email protected]

Copyright © 2015 - 2024 - Recent Slot Releases is part of HIPTHER Agency. Registered in Romania under Proshirt SRL, Company number: 2134306, EU VAT ID: RO21343605. Office address: Blvd. 1 Decembrie 1918 nr.5, Targu Mures, Romania