Connect with us

Latest News

Popular Gambling App Exposed Millions of Users in Massive Data Leak

Published

on

Reading Time: 5 minutes

 

Led by Noam Rotem and Ran Locar, vpnMentor’s research team discovered a data breach on casino gambling app Clubillion.

The breach originated in a technical database built on an Elasticsearch engine and was recording the daily activities of millions of Clubillion players around the world.

Aside from leaking activity on the app, the breached database also exposed private user information.

With this information publicly available, Clubillion’s users were vulnerable to fraud and various online attacks with potentially devastating results.

Company Profile

Clubillion is a free online casino game available for iOS and Android, offering players 30+ free slot games. While each app is listed under a different developer – Ouroboros on iOS and T7 Games on Android – these are most likely owned by the same company.

Both versions of Clubillion were released in 2019 and became instant hits. Each is now ranked the #1 ‘social slots’ casino app on Google Play and the App Store, with a 4.8 star on both.

Timeline of Discovery and Owner Reaction

Sometimes, the extent of a data breach and the owner of the database are obvious, and the issue quickly resolved. But rare are these times. Most often, we need days of investigation before we understand what’s at stake or who’s leaking the data.

Understanding a breach and its potential impact takes careful attention and time. We work hard to publish accurate and trustworthy reports, ensuring everybody who reads them understands their seriousness.

Some affected parties deny the facts, disregarding our research, or playing down its impact. So, we need to be thorough and make sure everything we find is correct and accurate.

In this case, the database was built on Elasticsearch and hosted on Amazon Web Services (AWS), with Clubillion’s name on its apps, and links to assets owned by the company.

Once Clubillion was confirmed as the owner of the database, we reached out to the developers. While awaiting a reply, we also contacted AWS with details of the leak. It was closed a few days later.

  • Date discovered: 19th March 2020
  • Date vendors contacted: 23rd March 2020
  • Date of contact with AWS: 31st March 2020
  • Date of Action: Approx. 5th April 2020

Example of Entries in the Database

Clubillion’s exposed database contained technical logs for millions of Clubillion users around the world, on both iOS and Android devices. Every time an individual player took any action on the app, a record was logged. Examples of records include:

  • “enter game”
  • “win”
  • “lose”
  • “update account”
  • “create account”

During our investigation of the database, new entries continued to appear continuously. We estimated an average of approximately 200 million records per day – and sometimes, considerably more.

In total, this amounted to over 50GB of exposed records in the database every single day.

Within many of these records, were various forms of user Personally Identifiable Information (PII) data, including:

  • IP addresses
  • Email addresses
  • Winnings
  • Private messages

This data breach was truly global, with millions of records originating from Clubillion’s daily users all over the world. The following list is just a sample of countries affected, along with the average number of daily users from each country:

  • USA – 10,000+
  • UK – 2,475+
  • France – 1,650+
  • Israel – 408+
  • Germany – 1,582+
  • Spain – 1,026+
  • Italy – 2,407+
  • Netherlands – 622+
  • Australia – 6,251+
  • Canada – 7,792+
  • Brazil – 3,859+
  • Sweden – 191+
  • Russia – 547+

Other countries affected included Uzbekistan, India, Poland, Romania, Vietnam, Lebanon, Indonesia, Philippines, Pakistan, Thailand, Austria, Hungry, and Latvia.

As you can see, on a single day, 10,000s of individual Clubillion players were exposed. Each one of these players could be targeted by malicious hackers for fraud and cyberattacks – along with millions more whose records were also contained in the database.

Data Breach Impact

Studies have shown that free gambling and gaming apps are especially prone to attacks and hacking from cybercriminals. They are routinely targeted for theft of private data and embedding malicious software on users’ devices.

Despite their popularity, gambling and casino apps often lack transparency, and it can be impossible to know what steps they’re taking to prevent cybercriminals successfully targeting their users.

One study of 23,000 free gambling apps found that: 3,200 posed a ‘moderate risk’ to users; 379 had known security vulnerabilities; 52 contained malicious software.

Any of these issues could be exploited to target app users in a wide range of frauds and cyberattacks, and Clubillion is no different.

With the exposed user PII and knowledge of their activity on the app, hackers could create elaborate schemes to defraud users. For example, some entries also included transaction errors for attempted card payments on Clubillion.

With the information in these transaction errors, hackers could target users with phishing campaigns, with the following aims:

  1. Trick them into providing their credit card details
  2. Trick them into providing additional PII to be used against them in further fraud
  3. Clicking a link that embeds malware, spyware, or ransomware onto their device.

If cybercriminals used Clubillion to embed malware or similar onto a user’s phone, they could potentially hack other apps, access files stored on the device, make calls, and send texts from the hacked device. They could even access a user’s phone contacts and steal the PII data of their friends and family.

Worse still, as people across the globe now find themselves under quarantine or self-isolation, as a result of the Coronavirus pandemic, the impact of a leak like this is potentially even more significant.

Clubillion stands to gain many new users, along with regular users playing more frequently. Hackers will be aware of this and looking for opportunities to exploit any vulnerabilities in the data security of such a massively popular app.

Had criminal hackers discovered Clubillion’s database, they could have targeted millions of people around the world, with devastating results.

Impact on Clubillion and it’s Developers

The most immediate risk for Clubillion is the loss of players. Data security is a growing concern for everyone these days, and this leak could turn many players off the app. Clubillion is not unique, and players have plenty of other choices for free gambling apps.

With fewer players, Clubillion will lose advertising revenue and reduced profits.

As many of Clubillion’s players reside within the EU, the app is under the jurisdiction of GDPR. The rules of GDPR also apply to apps, and Clubillion will need to take specific actions to ensure the regulatory body in charge doesn’t reprimand it.

Finally, Clubillion could also potentially be removed from Google Play and the App Store. Both Apple and Google are clamping down on apps that pose a risk to their users, removing apps embedded with malware, and taking data leaks much more seriously.

Each of these outcomes has a different likelihood of happening, but they would all negatively impact Clubillion’s revenue and business.

Advice from the Experts

Clubillion’s developers could have easily avoided this leak if they had taken some basic security measures to protect the database. These include, but are not limited to:

  1. Securing their servers.
  2. Implementing proper access rules.
  3. Never leaving a system that doesn’t require authentication open to the internet.

Any company can replicate the same steps, no matter its size.

For a more in-depth guide on how to protect your business, check out our guide to securing your website and online database from hackers.

For Clubillion Users

If you play on Clubillion and are concerned about how this breach might impact you, contact the app’s developers directly to find out what steps it’s taking to protect your data.

To learn about data vulnerabilities in general, read our complete guide to online privacy.

It shows you the many ways cybercriminals target internet users, and the steps you can take to stay safe.

How and Why We Discovered the Breach

The vpnMentor research team discovered the breach in Clubillion’s database as part of a huge web mapping project. Our researchers use port scanning to examine particular IP blocks and test different systems for weaknesses or vulnerabilities. They examine each weakness for any data being leaked.

Our team was able to access this database because it was completely unsecured and unencrypted. 

Whenever we find a data breach, we use expert techniques to verify the owner of the database, usually a commercial company.

As ethical hackers, we’re obliged to inform a company when we discover flaws in their online security. We reached out to Clubillion’s developers, not only to let them know about the vulnerability but also to suggest ways in which they could make their system secure.

These ethics also mean we carry a responsibility to the public. Clubillion users must be aware of a data breach that exposes so much of their sensitive data.

The purpose of this web mapping project is to help make the internet safer for all users.

 

Source

Powered by WPeMatico

Continue Reading
Advertisement

Latest News

FairPlay Sports Media and FOX Sports Digital Launch New Betting Hub

Published

on

fairplay-sports-media-and-fox-sports-digital-launch-new-betting-hub

FairPlay’s betting technology and AI-powered predictive content drive deeper fan engagement and deliver media opportunities and revenue

FOX Sports Digital and FairPlay Sports Media, the fan-focused and AI-powered global sports media network, have announced a strategic betting tech, affiliate and sports media agreement.

Under the multi-year agreement, FairPlay will serve as the exclusive sports betting affiliate technology provider of FOX Sports Digital, deploying its market-leading odds components, advanced AI-powered predictive data and analytics, and cutting-edge technology solutions on FOXSports.com and the FOX Sports mobile application.

The new relationship powers the newly released FOX Sports Betting Hub which integrates FairPlay’s innovative sports betting-related content enhanced with bespoke, value-added experiences derived from FairPlay’s deep relationships with global sportsbook operators.

“FOX Sports is one of the largest sports rights holders in the world, with incredible access to live games and global events,” said Stuart Simms, Group CEO of FairPlay Sports Media. “FairPlay is excited to work with the FOX Sports Digital team, and we’re honored to serve their millions of users with more engaging, insightful sports media experiences that have proven to drive loyalty, engagement and deliver on brand differentiation.”

FairPlay’s advanced AI technology and robust odds components are already delivering real-time, data-driven insights to help FOX Sports fans and bettors, while monetization frameworks being deployed create revenue opportunities for operators, sportsbooks and digital media buyers.

The agreement enhances and elevates fan engagement by bringing FairPlay’s betting information technology and AI-powered tools to FOX Sports’ digital platforms. FairPlay’s approach enables FOX Sports digital users and fans to access personalized, data-driven betting analytics that deepen their connection and engagement with sports content. As the sports media and betting landscapes continue to evolve, the FOX Sports and FairPlay agreement delivers pioneering, scalable digital experiences for fans and operators alike.

 

The post FairPlay Sports Media and FOX Sports Digital Launch New Betting Hub appeared first on Gaming and Gambling Industry Newsroom.

Continue Reading

Latest News

Betfred Launches Checkd Dev’s Automated Betting System to Strengthen Football Betting Offering

Published

on

betfred-launches-checkd-dev’s-automated-betting-system-to-strengthen-football-betting-offering

Checkd Dev, part of the award-winning Checkd Group and a leading iGaming technology provider, has signed a multi-year agreement to supply its Automated Betting System (ABS) to UK bookmaker Betfred, introducing new levels of efficiency and engagement to pre-match football accumulator betting.

Through the partnership, Betfred has launched a suite of pre-configured, one-click accumulator bets, powered by Checkd Dev’s ABS technology and seamlessly integrated with Betfred’s proprietary pricing.

The solution enhances the customer betting journey while equipping Betfred’s trading team with a robust backend platform to streamline bet creation, management, and settlement. Customers benefit from football bets that are dynamically assigned probabilities based on historic form, providing greater insight and confidence in their selections.

The launch of ABS reinforces Betfred’s reputation as an industry innovator, offering customers smarter, faster, and more engaging betting experiences.

Checkd Dev has refined its ABS user interface through deployments with multiple tier-one operators. Betfred has further strengthened the proposition by integrating its competitive Acca Flex bonus offer, available from launch. Customers can access additional bonuses if their bet wins, while also benefiting from a money-back guarantee if a single leg loses.

Since its introduction two years ago, Checkd Dev’s ABS has evolved from a statistics-driven tool to increase operator conversion rates into a comprehensive system designed to meet the growing demand for automated, pre-configured betting products, powered by the company’s proprietary BRUNO platform.

This agreement extends Checkd Dev’s recent growth trajectory, following high-profile partnerships with William Hill on a fully automated, stats-powered Bet Builder, and a three-year deal with OpenBet to launch a new Trending BetBuilder to market.

Andrew Grimshaw, Commercial Director at Checkd Dev, commented: “We are delighted to be working with fellow Mancunians Betfred on our Trending Bets product. More and more major bookmakers are recognising the tangible value of our automated betting solutions, and it is especially gratifying to collaborate with a local partner on this launch.”

Mark Hartley, Head of Product at Betfred, added: “Since moving onto our propriety platform, we’ve been able to bring new ideas to market much faster. This partnership with Checkd Dev is a great example, helping us solve a simple problem for football fans: researching and building an accumulator can sometimes feel like hard work!

“With one-click, data-driven selections we’ve made the process quicker and easier, while still giving customers the choice and depth they want. Accas are already one of our most compelling propositions, thanks to our popular promotion Acca Flex, and this launch makes them even more engaging. We’re also looking forward to exploring further opportunities to work with Checkd Dev in the future.”

 

The post Betfred Launches Checkd Dev’s Automated Betting System to Strengthen Football Betting Offering appeared first on Gaming and Gambling Industry Newsroom.

Continue Reading

Latest News

Slotland’s Crown Jewel, Gods of Egypt, Resurrects with Enhanced Features

Published

on

slotland’s-crown-jewel,-gods-of-egypt,-resurrects-with-enhanced-features

Legendary Title Reborn for a New Generation of Fortune Seekers with Freebies and Bonuses until December 28th

Slotland Entertainment has ceremoniously relaunched its legendary title, Gods of Egypt, across its casinos Slotland, Winaday and now including CryptoSlots and CryptoWins. This revered 5×4, 30-payline slot invites players into a grand temple of mythic wealth.

Wager $1.50 to $30 to awaken divine features: Ra’s Sticky Expanding Wilds, Bastet’s gem-triggered Free Spins, and a Pick Me Bonus with layered treasures. For those betting $15 or more, five Pharaoh symbols unlock the progressive jackpot.

Gods of Egypt has always been a crown jewel in our collection,” said Michael Hilary, Manager at Slotland. “This relaunch across our entire empire allows a new generation of players to experience its timeless magic and seek its legendary rewards.”

Framed by the regal visages of Anubis and a jeweled queen, the game creates a ceremonial atmosphere of arcade spectacle. It is a call to modern seekers: enter and claim your ancient riches.

WINADAY CASINO: Available December 19 – 28, 2025

Up to $111 FREEBIE chip

  • For platinum VIPs, $88 for Gold VIPs, $55 for Silver VIPs, $44 for Bronze VIPs, $20 for ALL
  • Redeem: 1x, wager: 29x, max cashout 5x, depositing players only
  • Bonus Code: FREEBIE2025

Up to 155% NEW GAME BONUS

  • For VIPs, 100% for ALL
  • On deposits on $10 – $250
  • Redeem: 2x per day, wager: 29x, valid: Gods of Egypt
  • Bonus code: NEWSLOT

 

CRYPTOSLOTS: Available December 17 – 25, 2025

123% VIP TREASURE MATCH

  • On deposits $50-500
  • Redeem: 1x per day, wager: 35x, valid: Gods of Egypt
  • Bonus code: VIPNEW

77$ DESERT GOLD MATCH

  • On deposits 200 – $400, 65% on $100 – $199, 50% on $10 – $99
  • Redeem: 2x per day, wager: 35x, valid: Gods of Egypt
  • Bonus code: NEWIN

 

The post Slotland’s Crown Jewel, Gods of Egypt, Resurrects with Enhanced Features appeared first on Gaming and Gambling Industry Newsroom.

Continue Reading

Trending

Get it on Google Play

Fresh slot games releases by the top brands of the industry. We provide you with the latest news straight from the entertainment industries.

The platform also hosts industry-relevant webinars, and provides detailed reports, making it a one-stop resource for anyone seeking information about operators, suppliers, regulators, and professional services in the European gaming market. The portal's primary goal is to keep its extensive reader base updated on the latest happenings, trends, and developments within the gaming and gambling sector, with an emphasis on the European market while also covering pertinent global news. It's an indispensable resource for gaming professionals, operators, and enthusiasts alike.

Contact us: [email protected]

Editorial / PR Submissions: [email protected]

Copyright © 2015 - 2024 - Recent Slot Releases is part of HIPTHER Agency. Registered in Romania under Proshirt SRL, Company number: 2134306, EU VAT ID: RO21343605. Office address: Blvd. 1 Decembrie 1918 nr.5, Targu Mures, Romania