Latest News
Popular Gambling App Exposed Millions of Users in Massive Data Leak
Led by Noam Rotem and Ran Locar, vpnMentor’s research team discovered a data breach on casino gambling app Clubillion.
The breach originated in a technical database built on an Elasticsearch engine and was recording the daily activities of millions of Clubillion players around the world.
Aside from leaking activity on the app, the breached database also exposed private user information.
With this information publicly available, Clubillion’s users were vulnerable to fraud and various online attacks with potentially devastating results.
Company Profile
Clubillion is a free online casino game available for iOS and Android, offering players 30+ free slot games. While each app is listed under a different developer – Ouroboros on iOS and T7 Games on Android – these are most likely owned by the same company.
Both versions of Clubillion were released in 2019 and became instant hits. Each is now ranked the #1 ‘social slots’ casino app on Google Play and the App Store, with a 4.8 star on both.
Timeline of Discovery and Owner Reaction
Sometimes, the extent of a data breach and the owner of the database are obvious, and the issue quickly resolved. But rare are these times. Most often, we need days of investigation before we understand what’s at stake or who’s leaking the data.
Understanding a breach and its potential impact takes careful attention and time. We work hard to publish accurate and trustworthy reports, ensuring everybody who reads them understands their seriousness.
Some affected parties deny the facts, disregarding our research, or playing down its impact. So, we need to be thorough and make sure everything we find is correct and accurate.
In this case, the database was built on Elasticsearch and hosted on Amazon Web Services (AWS), with Clubillion’s name on its apps, and links to assets owned by the company.
Once Clubillion was confirmed as the owner of the database, we reached out to the developers. While awaiting a reply, we also contacted AWS with details of the leak. It was closed a few days later.
- Date discovered: 19th March 2020
- Date vendors contacted: 23rd March 2020
- Date of contact with AWS: 31st March 2020
- Date of Action: Approx. 5th April 2020
Example of Entries in the Database
Clubillion’s exposed database contained technical logs for millions of Clubillion users around the world, on both iOS and Android devices. Every time an individual player took any action on the app, a record was logged. Examples of records include:
- “enter game”
- “win”
- “lose”
- “update account”
- “create account”
During our investigation of the database, new entries continued to appear continuously. We estimated an average of approximately 200 million records per day – and sometimes, considerably more.
In total, this amounted to over 50GB of exposed records in the database every single day.
Within many of these records, were various forms of user Personally Identifiable Information (PII) data, including:
- IP addresses
- Email addresses
- Winnings
- Private messages
This data breach was truly global, with millions of records originating from Clubillion’s daily users all over the world. The following list is just a sample of countries affected, along with the average number of daily users from each country:
- USA – 10,000+
- UK – 2,475+
- France – 1,650+
- Israel – 408+
- Germany – 1,582+
- Spain – 1,026+
- Italy – 2,407+
- Netherlands – 622+
- Australia – 6,251+
- Canada – 7,792+
- Brazil – 3,859+
- Sweden – 191+
- Russia – 547+
Other countries affected included Uzbekistan, India, Poland, Romania, Vietnam, Lebanon, Indonesia, Philippines, Pakistan, Thailand, Austria, Hungry, and Latvia.
As you can see, on a single day, 10,000s of individual Clubillion players were exposed. Each one of these players could be targeted by malicious hackers for fraud and cyberattacks – along with millions more whose records were also contained in the database.
Data Breach Impact
Studies have shown that free gambling and gaming apps are especially prone to attacks and hacking from cybercriminals. They are routinely targeted for theft of private data and embedding malicious software on users’ devices.
Despite their popularity, gambling and casino apps often lack transparency, and it can be impossible to know what steps they’re taking to prevent cybercriminals successfully targeting their users.
One study of 23,000 free gambling apps found that: 3,200 posed a ‘moderate risk’ to users; 379 had known security vulnerabilities; 52 contained malicious software.
Any of these issues could be exploited to target app users in a wide range of frauds and cyberattacks, and Clubillion is no different.
With the exposed user PII and knowledge of their activity on the app, hackers could create elaborate schemes to defraud users. For example, some entries also included transaction errors for attempted card payments on Clubillion.
With the information in these transaction errors, hackers could target users with phishing campaigns, with the following aims:
- Trick them into providing their credit card details
- Trick them into providing additional PII to be used against them in further fraud
- Clicking a link that embeds malware, spyware, or ransomware onto their device.
If cybercriminals used Clubillion to embed malware or similar onto a user’s phone, they could potentially hack other apps, access files stored on the device, make calls, and send texts from the hacked device. They could even access a user’s phone contacts and steal the PII data of their friends and family.
Worse still, as people across the globe now find themselves under quarantine or self-isolation, as a result of the Coronavirus pandemic, the impact of a leak like this is potentially even more significant.
Clubillion stands to gain many new users, along with regular users playing more frequently. Hackers will be aware of this and looking for opportunities to exploit any vulnerabilities in the data security of such a massively popular app.
Had criminal hackers discovered Clubillion’s database, they could have targeted millions of people around the world, with devastating results.
Impact on Clubillion and it’s Developers
The most immediate risk for Clubillion is the loss of players. Data security is a growing concern for everyone these days, and this leak could turn many players off the app. Clubillion is not unique, and players have plenty of other choices for free gambling apps.
With fewer players, Clubillion will lose advertising revenue and reduced profits.
As many of Clubillion’s players reside within the EU, the app is under the jurisdiction of GDPR. The rules of GDPR also apply to apps, and Clubillion will need to take specific actions to ensure the regulatory body in charge doesn’t reprimand it.
Finally, Clubillion could also potentially be removed from Google Play and the App Store. Both Apple and Google are clamping down on apps that pose a risk to their users, removing apps embedded with malware, and taking data leaks much more seriously.
Each of these outcomes has a different likelihood of happening, but they would all negatively impact Clubillion’s revenue and business.
Advice from the Experts
Clubillion’s developers could have easily avoided this leak if they had taken some basic security measures to protect the database. These include, but are not limited to:
- Securing their servers.
- Implementing proper access rules.
- Never leaving a system that doesn’t require authentication open to the internet.
Any company can replicate the same steps, no matter its size.
For a more in-depth guide on how to protect your business, check out our guide to securing your website and online database from hackers.
For Clubillion Users
If you play on Clubillion and are concerned about how this breach might impact you, contact the app’s developers directly to find out what steps it’s taking to protect your data.
To learn about data vulnerabilities in general, read our complete guide to online privacy.
It shows you the many ways cybercriminals target internet users, and the steps you can take to stay safe.
How and Why We Discovered the Breach
The vpnMentor research team discovered the breach in Clubillion’s database as part of a huge web mapping project. Our researchers use port scanning to examine particular IP blocks and test different systems for weaknesses or vulnerabilities. They examine each weakness for any data being leaked.
Our team was able to access this database because it was completely unsecured and unencrypted.
Whenever we find a data breach, we use expert techniques to verify the owner of the database, usually a commercial company.
As ethical hackers, we’re obliged to inform a company when we discover flaws in their online security. We reached out to Clubillion’s developers, not only to let them know about the vulnerability but also to suggest ways in which they could make their system secure.
These ethics also mean we carry a responsibility to the public. Clubillion users must be aware of a data breach that exposes so much of their sensitive data.
The purpose of this web mapping project is to help make the internet safer for all users.
Powered by WPeMatico
betting terminals
Meridianbet Completes Fairbet Acquisition, Expanding Malta Retail Gaming Network Under Golden Matrix Group
Meridianbet, a leading global sports betting and gaming operator and a subsidiary of Golden Matrix Group Inc. (NASDAQ: GMGI), has completed the acquisition of Fairbet Ltd., a licensed retail gaming operator in Malta.
The transaction significantly expands Meridianbet’s physical retail footprint in one of Europe’s most tightly regulated gaming jurisdictions.
Fairbet operates under Malta Gaming Authority (MGA) license B2C/195/2011, and the acquisition grants Meridianbet 100% ownership of Fairbet’s retail operations across Malta and Gozo, the archipelago’s second-largest island. The deal expands Meridianbet’s presence beyond its existing locations and further consolidates its position within the Maltese retail gaming market.
As part of the transaction, nine additional retail locations will be integrated into the Meridianbet network, increasing the company’s total number of storefronts in Malta to 20. The enlarged retail estate is expected to operate more than 60 sports betting terminals and over 120 slot machines, significantly boosting Meridianbet’s land-based gaming capacity.
The companies’ previous technology partnership will now transition into full operational integration, with Meridianbet assuming complete operational control of Fairbet’s retail network. All locations will be rebranded under the Meridianbet name, ensuring unified technology, compliance, and customer experience across the portfolio.
Malta’s retail gaming sector is governed by one of the most restrictive regulatory frameworks in Europe, with only three licensed operators permitted to operate retail betting locations: Meridianbet, Izibet (the National Lottery operator), and Fairbet. With Fairbet now wholly owned by Meridianbet, the company effectively controls two of the three retail gaming licenses in the jurisdiction.
The Malta Gaming Authority (MGA) enforces strict licensing criteria, substantial capital requirements, and rigorous compliance standards that create significant barriers to market entry. These conditions limit competition and create long-term scarcity value for licensed operators that meet the regulatory threshold.
“Completing the acquisition of Fairbet strengthens our position in a market where regulatory barriers create inherent scarcity value,” said Zoran Milosevic, CEO of Meridianbet. “This transaction allows us to expand our retail infrastructure in Malta, while our technology now supports the majority of licensed retail gaming in the country. It reflects our disciplined M&A strategy, targeting high-barrier markets where limited licensing creates durable competitive advantages.”
The Fairbet acquisition aligns with Meridianbet’s broader growth strategy, which combines organic expansion with selective mergers and acquisitions in jurisdictions where regulation encourages consolidation. Malta has been a core operational hub for Meridianbet since 2008, with the company ranking among the country’s originally licensed gaming operators during the early development of the MGA framework.
Malta’s gaming industry benefits from a regulatory regime widely regarded as one of Europe’s most credible. The MGA’s oversight framework emphasizes investor protection, technical compliance, and financial stability, positioning Malta-licensed operators for trust and recognition across international markets.
Meridianbet’s expanded retail footprint across Malta and Gozo enhances its ability to serve both local customers and the island nation’s strong tourism sector. According to Malta’s National Statistics Office, tourist arrivals exceeded three million visitors in 2024, reinforcing the strategic value of a broad, well-positioned retail gaming network
The post Meridianbet Completes Fairbet Acquisition, Expanding Malta Retail Gaming Network Under Golden Matrix Group appeared first on Eastern European Gaming | Global iGaming & Tech Intelligence Hub.
Atlaslive
Atlaslive Reaches Final Shortlist for Best Live Platform Provider at SiGMA Eurasia 2026
Atlaslive, a provider of B2B iGaming platform technology, has earned a place on the shortlist for the BEST LIVE PLATFORM PROVIDER 2026 category at the SiGMA Eurasia Awards 2026.
The SiGMA Eurasia Awards spotlight excellence across the iGaming, affiliate, and online entertainment industries, honoring companies and solutions that drive innovation, sustainable growth, and measurable impact. The shortlist is announced as part of the SiGMA Eurasia Summit, taking place February 9–11, 2026, at Dubai Festival City in the United Arab Emirates.
“Platform performance is measured in milliseconds, uptime, and player trust. Being shortlisted in this category reflects the technical discipline and delivery standards our teams bring to operators every day.”
—Anastasiia Poltavets, CMO at Atlaslive
Partners, supporters, and members of the community can participate in the awards process through public voting by submitting their support using the following form:
https://share.hsforms.com/11aCinm5wS92yCSiAtXDGUg3s9oo
Taking place during summit week, the awards ceremonies create a key moment for industry professionals to connect, share insights, and celebrate innovation at one of the year’s most prominent gaming events.
About Atlaslive
Atlaslive delivers flexible, scalable iGaming platform technology to operators in regulated markets. Focused on performance, reliability, and continuous product development, Atlaslive enables sportsbook and casino operations aligned with diverse business models.
This document is provided to you for your information and discussion only. This document was based on public sources of information and was created by the Atlaslive team for marketing usage. It is not a solicitation or an offer to buy or sell any gambling-related product. Nothing in this document constitutes legal or business development advice. This document has been prepared from sources Atlaslive believes to be reliable, but we do not guarantee its accuracy or completeness and do not accept liability for any loss arising from its use. Atlaslive reserves the right to remedy any errors that may be present in this document.
About Atlaslive
Atlaslive is a B2B software development company that specializes in creating a multifunctional and automated platform to optimize the workflow of sports betting and casino operators. Key components of the Atlaslive Platform include Sportsbook, Casino, Risk Management and Anti-Fraud Tools, CRM, Bonus Engine, Business Analytics, Payment Systems, and Retail Module. Follow the company on LinkedIn to stay updated with the latest news in iGaming technology.
The post Atlaslive Reaches Final Shortlist for Best Live Platform Provider at SiGMA Eurasia 2026 appeared first on Eastern European Gaming | Global iGaming & Tech Intelligence Hub.
Atlaslive
Atlaslive Reaches Final Shortlist for Best Live Platform Provider at SiGMA Eurasia 2026
Atlaslive, a provider of B2B iGaming platform technology, has earned a place on the shortlist for the BEST LIVE PLATFORM PROVIDER 2026 category at the SiGMA Eurasia Awards 2026.
The SiGMA Eurasia Awards spotlight excellence across the iGaming, affiliate, and online entertainment industries, honoring companies and solutions that drive innovation, sustainable growth, and measurable impact. The shortlist is announced as part of the SiGMA Eurasia Summit, taking place February 9–11, 2026, at Dubai Festival City in the United Arab Emirates.
“Platform performance is measured in milliseconds, uptime, and player trust. Being shortlisted in this category reflects the technical discipline and delivery standards our teams bring to operators every day.”
—Anastasiia Poltavets, CMO at Atlaslive
Partners, supporters, and members of the community can participate in the awards process through public voting by submitting their support using the following form:
https://share.hsforms.com/11aCinm5wS92yCSiAtXDGUg3s9oo
Taking place during summit week, the awards ceremonies create a key moment for industry professionals to connect, share insights, and celebrate innovation at one of the year’s most prominent gaming events.
About Atlaslive
Atlaslive delivers flexible, scalable iGaming platform technology to operators in regulated markets. Focused on performance, reliability, and continuous product development, Atlaslive enables sportsbook and casino operations aligned with diverse business models.
This document is provided to you for your information and discussion only. This document was based on public sources of information and was created by the Atlaslive team for marketing usage. It is not a solicitation or an offer to buy or sell any gambling-related product. Nothing in this document constitutes legal or business development advice. This document has been prepared from sources Atlaslive believes to be reliable, but we do not guarantee its accuracy or completeness and do not accept liability for any loss arising from its use. Atlaslive reserves the right to remedy any errors that may be present in this document.
About Atlaslive
Atlaslive is a B2B software development company that specializes in creating a multifunctional and automated platform to optimize the workflow of sports betting and casino operators. Key components of the Atlaslive Platform include Sportsbook, Casino, Risk Management and Anti-Fraud Tools, CRM, Bonus Engine, Business Analytics, Payment Systems, and Retail Module. Follow the company on LinkedIn to stay updated with the latest news in iGaming technology.
The post Atlaslive Reaches Final Shortlist for Best Live Platform Provider at SiGMA Eurasia 2026 appeared first on Americas iGaming & Sports Betting News.
-
BetPlay6 days agoBlask Awards 2025: Betano, Caliente, BetPlay, Betsson and others define Latin America’s iGaming landscape
-
Canada6 days agoComeOn Launches New Marketing Campaign in Ontario
-
iGaming6 days agoMajestic Claws Hold & Hit leaps into Spinomenal’s slots portfolio
-
Latest News6 days agoThrillTech partners with Nordplay Group to launch ThrillPots across Nordic-facing casino brands
-
DEGEN Studios6 days agoDEGEN Studios brings Wild West chaos to the reels with Sunset Showdown
-
Brightstar Lottery PLC5 days agoBrightstar Lottery Delivers Industry-Leading Sales Force Automation Solution to Ontario Lottery and Gaming Corporation
-
bingo halls5 days agoBingo Halls and Casinos in Colombia Increased Their Contributions to Healthcare System by 9.3% in 2025
-
Compliance Updates4 days agoFinland Govt Looks at Whether Scratchcards can be Gifted Again



