Latest News
Popular Gambling App Exposed Millions of Users in Massive Data Leak
Led by Noam Rotem and Ran Locar, vpnMentor’s research team discovered a data breach on casino gambling app Clubillion.
The breach originated in a technical database built on an Elasticsearch engine and was recording the daily activities of millions of Clubillion players around the world.
Aside from leaking activity on the app, the breached database also exposed private user information.
With this information publicly available, Clubillion’s users were vulnerable to fraud and various online attacks with potentially devastating results.
Company Profile
Clubillion is a free online casino game available for iOS and Android, offering players 30+ free slot games. While each app is listed under a different developer – Ouroboros on iOS and T7 Games on Android – these are most likely owned by the same company.
Both versions of Clubillion were released in 2019 and became instant hits. Each is now ranked the #1 ‘social slots’ casino app on Google Play and the App Store, with a 4.8 star on both.
Timeline of Discovery and Owner Reaction
Sometimes, the extent of a data breach and the owner of the database are obvious, and the issue quickly resolved. But rare are these times. Most often, we need days of investigation before we understand what’s at stake or who’s leaking the data.
Understanding a breach and its potential impact takes careful attention and time. We work hard to publish accurate and trustworthy reports, ensuring everybody who reads them understands their seriousness.
Some affected parties deny the facts, disregarding our research, or playing down its impact. So, we need to be thorough and make sure everything we find is correct and accurate.
In this case, the database was built on Elasticsearch and hosted on Amazon Web Services (AWS), with Clubillion’s name on its apps, and links to assets owned by the company.
Once Clubillion was confirmed as the owner of the database, we reached out to the developers. While awaiting a reply, we also contacted AWS with details of the leak. It was closed a few days later.
- Date discovered: 19th March 2020
- Date vendors contacted: 23rd March 2020
- Date of contact with AWS: 31st March 2020
- Date of Action: Approx. 5th April 2020
Example of Entries in the Database
Clubillion’s exposed database contained technical logs for millions of Clubillion users around the world, on both iOS and Android devices. Every time an individual player took any action on the app, a record was logged. Examples of records include:
- “enter game”
- “win”
- “lose”
- “update account”
- “create account”
During our investigation of the database, new entries continued to appear continuously. We estimated an average of approximately 200 million records per day – and sometimes, considerably more.
In total, this amounted to over 50GB of exposed records in the database every single day.
Within many of these records, were various forms of user Personally Identifiable Information (PII) data, including:
- IP addresses
- Email addresses
- Winnings
- Private messages
This data breach was truly global, with millions of records originating from Clubillion’s daily users all over the world. The following list is just a sample of countries affected, along with the average number of daily users from each country:
- USA – 10,000+
- UK – 2,475+
- France – 1,650+
- Israel – 408+
- Germany – 1,582+
- Spain – 1,026+
- Italy – 2,407+
- Netherlands – 622+
- Australia – 6,251+
- Canada – 7,792+
- Brazil – 3,859+
- Sweden – 191+
- Russia – 547+
Other countries affected included Uzbekistan, India, Poland, Romania, Vietnam, Lebanon, Indonesia, Philippines, Pakistan, Thailand, Austria, Hungry, and Latvia.
As you can see, on a single day, 10,000s of individual Clubillion players were exposed. Each one of these players could be targeted by malicious hackers for fraud and cyberattacks – along with millions more whose records were also contained in the database.
Data Breach Impact
Studies have shown that free gambling and gaming apps are especially prone to attacks and hacking from cybercriminals. They are routinely targeted for theft of private data and embedding malicious software on users’ devices.
Despite their popularity, gambling and casino apps often lack transparency, and it can be impossible to know what steps they’re taking to prevent cybercriminals successfully targeting their users.
One study of 23,000 free gambling apps found that: 3,200 posed a ‘moderate risk’ to users; 379 had known security vulnerabilities; 52 contained malicious software.
Any of these issues could be exploited to target app users in a wide range of frauds and cyberattacks, and Clubillion is no different.
With the exposed user PII and knowledge of their activity on the app, hackers could create elaborate schemes to defraud users. For example, some entries also included transaction errors for attempted card payments on Clubillion.
With the information in these transaction errors, hackers could target users with phishing campaigns, with the following aims:
- Trick them into providing their credit card details
- Trick them into providing additional PII to be used against them in further fraud
- Clicking a link that embeds malware, spyware, or ransomware onto their device.
If cybercriminals used Clubillion to embed malware or similar onto a user’s phone, they could potentially hack other apps, access files stored on the device, make calls, and send texts from the hacked device. They could even access a user’s phone contacts and steal the PII data of their friends and family.
Worse still, as people across the globe now find themselves under quarantine or self-isolation, as a result of the Coronavirus pandemic, the impact of a leak like this is potentially even more significant.
Clubillion stands to gain many new users, along with regular users playing more frequently. Hackers will be aware of this and looking for opportunities to exploit any vulnerabilities in the data security of such a massively popular app.
Had criminal hackers discovered Clubillion’s database, they could have targeted millions of people around the world, with devastating results.
Impact on Clubillion and it’s Developers
The most immediate risk for Clubillion is the loss of players. Data security is a growing concern for everyone these days, and this leak could turn many players off the app. Clubillion is not unique, and players have plenty of other choices for free gambling apps.
With fewer players, Clubillion will lose advertising revenue and reduced profits.
As many of Clubillion’s players reside within the EU, the app is under the jurisdiction of GDPR. The rules of GDPR also apply to apps, and Clubillion will need to take specific actions to ensure the regulatory body in charge doesn’t reprimand it.
Finally, Clubillion could also potentially be removed from Google Play and the App Store. Both Apple and Google are clamping down on apps that pose a risk to their users, removing apps embedded with malware, and taking data leaks much more seriously.
Each of these outcomes has a different likelihood of happening, but they would all negatively impact Clubillion’s revenue and business.
Advice from the Experts
Clubillion’s developers could have easily avoided this leak if they had taken some basic security measures to protect the database. These include, but are not limited to:
- Securing their servers.
- Implementing proper access rules.
- Never leaving a system that doesn’t require authentication open to the internet.
Any company can replicate the same steps, no matter its size.
For a more in-depth guide on how to protect your business, check out our guide to securing your website and online database from hackers.
For Clubillion Users
If you play on Clubillion and are concerned about how this breach might impact you, contact the app’s developers directly to find out what steps it’s taking to protect your data.
To learn about data vulnerabilities in general, read our complete guide to online privacy.
It shows you the many ways cybercriminals target internet users, and the steps you can take to stay safe.
How and Why We Discovered the Breach
The vpnMentor research team discovered the breach in Clubillion’s database as part of a huge web mapping project. Our researchers use port scanning to examine particular IP blocks and test different systems for weaknesses or vulnerabilities. They examine each weakness for any data being leaked.
Our team was able to access this database because it was completely unsecured and unencrypted.
Whenever we find a data breach, we use expert techniques to verify the owner of the database, usually a commercial company.
As ethical hackers, we’re obliged to inform a company when we discover flaws in their online security. We reached out to Clubillion’s developers, not only to let them know about the vulnerability but also to suggest ways in which they could make their system secure.
These ethics also mean we carry a responsibility to the public. Clubillion users must be aware of a data breach that exposes so much of their sensitive data.
The purpose of this web mapping project is to help make the internet safer for all users.
Powered by WPeMatico
David Mann Chief Commercial Officer at Swintt
Swintt bring players four times the fun in Lucky Fortune Door Wild
Reading Time: 2 minutes
Sought-after software provider’s enhanced Premium release sees players step into the glow of the Far East as wild symbols and Quadspins combine for huge rewards
With Swintt having already opened the way to a world of wonder in the original Lucky Fortune Door, this month the award-winning software provider is back in action again with Lucky Fortune Door Wild – an exciting reboot that gives players even more ways to win!
Like its SwinttPremium predecessor, Lucky Fortune Door Wild is a five-reel slot that can be played with either five or ten paylines. Boasting an engaging Far East theme, the slot combines dragons, yin and yang pendants and coins with new golden ingot wilds that substitute for all other symbols.
The good news for fans of the original game is that the slot’s signature Quadspin mechanic again makes a welcome return. Activated whenever a win of at least 4x the bet is triggered, players will have the choice to either claim their current prize or gamble a portion of it to activate Quadspins.
Should they decide for the latter option, the gameboard will be divided into four separate reel sets to potentially quadruple the prizes on offer – and of course, with substitute wilds now also in play, the chances of players landing the slot’s maximum 6,000x win multiplier will be greatly increased.
As a further incentive, during Quadspins, an extra mystery symbol is also added to the reels. Should any instances of this icon appear on any of the four reel sets, they will be replaced by a random matching symbol to create additional payline wins and generate potentially huge prizes.
On top of this, should players continue to land wins of 4x their bet or greater during Quadspins, they can elect to remain in the feature for longer. With a maximum of 50 Quadspin available per set, the odds of them embarking on a prolonged winning streak are, therefore, much more likely.
To cap it off, all wins in Lucky Fortune Door Wild are paid from both left-to-right and right-to-left, meaning that no matter how aggressively players choose to play, fortune is only ever a spin away.
David Mann, Chief Commercial Officer at Swintt, said: “With Swintt’s signature Quadspin mechanic proving a hugely popular addition to our Premium line-up, we’re delighted to be giving the feature another outing in Lucky Fortune Door Wild. Offering the same great gameplay as the original release but now with added wilds, it’s sure to be a big hit with players and operators alike.”
The post Swintt bring players four times the fun in Lucky Fortune Door Wild appeared first on European Gaming Industry News.
18Peaches
18Peaches’ Squid Gold X2 plunges players into a mystical treasure hunt
Reading Time: 2 minutes
Squid Gold X2 by 18Peaches invites players to dive deep into a world of mystery, magic and forgotten riches. Set within a sacred castle filled with ancient relics and hidden chambers, every spin feels like a step deeper into the unknown. The legendary golden squid is said to guard untold fortunes, and only the bravest adventurers will uncover its secrets.
The journey plays out across a 5×5 grid with 50 paylines, where expanding reels can unlock up to 100 paylines for even greater rewards.
With enchanting artifacts, secret rooms, and the electrifying Squid 500 feature, no spin ever feels ordinary. Add in Free Spins, Wild expansions and instant bonus access via Buy Bonus, and Squid Gold X2 becomes a pulse-raising treasure hunt built for thrill-seekers.
“With Squid Gold X2, our goal was to create a journey where every spin feels like a step closer to unlocking a forgotten legend,” says 18Peaches Chief Strategy Officer Arsen Tadevosyan. “We designed mechanics like Squid 500 and the X2 expanding reels to build momentum, each trigger feels like a gate opening, both visually and emotionally. It’s that feeling of chasing something mythical, where every feature builds anticipation and drives you deeper into the experience.”
“When reels expand, paylines double, and the chamber glows with energy, players feel the story unfolding through mechanics. That flow, the rise in tension, the surge of possibility, is what makes Squid Gold X2 such a captivating adventure.”
As with all 18Peaches’ releases, Squid Gold X2
is bursting with features that keep every moment alive. The highlight is the legendary Squid 500 mechanic.
Whenever a Wild lands and expands, it triggers the sacred Golden Gate, unlocking hidden energy within the castle walls. As the gate opens, the power of the golden squid surges through the reels, doubling your paylines and dramatically boosting winning potential.
There’s also our X2 Mechanic. During bonus rounds, when the Golden Gate rises it reveals additional rows, expanding the grid and transforming 50 paylines into a breathtaking 100-line battlefield of rewards.
Squid Gold X2 is the latest addition to 18Peaches’ fast-growing catalogue of hit titles that continue to resonate with modern players. Recent successes such as Leprechaun Jackpot Collector, Monster Load-Up Hold & Win, and the high-adrenaline Hacker Crash
Jackpot have firmly established the studio as a creator of distinctive, high-engagement experiences.
As with all 18Peaches titles, Squid Gold X2 is built for effortless market deployment. The platform supports Sweepstakes and Free Rounds via API, enabling operators to easily tailor promotional strategies across diverse regulatory environments.
The post 18Peaches’ Squid Gold X2 plunges players into a mystical treasure hunt appeared first on European Gaming Industry News.
Booming Games
Booming Games Takes Players Sky-High with Thunder Eagle Hold and Win Extreme 10,000
Reading Time: < 1 minute
Take to the skies and soar like an eagle, then swoop in and grab big wins by spinning the reels of Thunder Eagle Hold and Win Extreme from Booming Games. This action-packed, feature-filled slot is a wild adventure with a chance to win up to 10,000x.
Thunder Eagle Hold and Win Extreme is a 5×3, 25-fixed payline slot. The winning fun takes off when multiplier prize symbols land in the base game for a chance to trigger the Eagle Bonus feature that awards a spin on the Bonus Wheel, which can award Multiplier prize collect, Mini, Minor or Major Prize Pots or even an instant Hold and Win Extreme Bonus.
Hold and Win Extreme features four 3×5 grids and 3 Respins. Land multiplier prize symbols to unlock the other grids. Completing a grid will award a x2 Win Multiplier to all symbols or landing all 60 positions to complete all found grids award the majestic Grand Prize Pot worth 10,000x!
Play Thunder Eagle Hold and Win Extreme and fly to new heights!
Craig Asling, Director at Booming Games, said: “With Thunder Eagle Hold and Win Extreme, we wanted to take our popular Hold and Win format to new heights, both literally and figuratively. This game delivers an exhilarating experience with powerful visuals, immersive gameplay and incredible win potential up to 10,000x. It’s a perfect example of how Booming Games continues to innovate while keeping players fully engaged.”
The post Booming Games Takes Players Sky-High with Thunder Eagle Hold and Win Extreme 10,000 appeared first on European Gaming Industry News.
-
Latest News6 days agoBoomerang Partners has announced a gift auction at their booth during the upcoming SiGMA Europe 2025 in Rome
-
Asia6 days agoNagaWorld Achieves Exceptional Great Place To Work Certification with Near-Perfect 95% Trust Index Score
-
Affiliate Industry6 days agoMelBet Partners to Bring UFC Champion Kamaru Usman to SiGMA Central Europe
-
Amusnet6 days agoWeek 44/2025 slot games releases
-
Central Europe6 days agoAward-Nominated EGT Digital Brings Sweet Spins, Smart Tech, and New Thrills to SiGMA Central Europe 2025
-
Belgian gaming regulator6 days agoBelgian Regulator Supports New Law for Tougher Player Protection and Increased Oversight
-
AUSTRAC6 days agoAUSTRAC Cracks Down on Cryptolink for Late Reporting
-
Trusted6 days agoTrusted Crypto Casinos of 2025: Jackbit Introduces No-KYC Play, Fast Withdrawals & a New Welcome Bonus for Global Players



