Latest News
Popular Gambling App Exposed Millions of Users in Massive Data Leak
Led by Noam Rotem and Ran Locar, vpnMentor’s research team discovered a data breach on casino gambling app Clubillion.
The breach originated in a technical database built on an Elasticsearch engine and was recording the daily activities of millions of Clubillion players around the world.
Aside from leaking activity on the app, the breached database also exposed private user information.
With this information publicly available, Clubillion’s users were vulnerable to fraud and various online attacks with potentially devastating results.
Company Profile
Clubillion is a free online casino game available for iOS and Android, offering players 30+ free slot games. While each app is listed under a different developer – Ouroboros on iOS and T7 Games on Android – these are most likely owned by the same company.
Both versions of Clubillion were released in 2019 and became instant hits. Each is now ranked the #1 ‘social slots’ casino app on Google Play and the App Store, with a 4.8 star on both.
Timeline of Discovery and Owner Reaction
Sometimes, the extent of a data breach and the owner of the database are obvious, and the issue quickly resolved. But rare are these times. Most often, we need days of investigation before we understand what’s at stake or who’s leaking the data.
Understanding a breach and its potential impact takes careful attention and time. We work hard to publish accurate and trustworthy reports, ensuring everybody who reads them understands their seriousness.
Some affected parties deny the facts, disregarding our research, or playing down its impact. So, we need to be thorough and make sure everything we find is correct and accurate.
In this case, the database was built on Elasticsearch and hosted on Amazon Web Services (AWS), with Clubillion’s name on its apps, and links to assets owned by the company.
Once Clubillion was confirmed as the owner of the database, we reached out to the developers. While awaiting a reply, we also contacted AWS with details of the leak. It was closed a few days later.
- Date discovered: 19th March 2020
- Date vendors contacted: 23rd March 2020
- Date of contact with AWS: 31st March 2020
- Date of Action: Approx. 5th April 2020
Example of Entries in the Database
Clubillion’s exposed database contained technical logs for millions of Clubillion users around the world, on both iOS and Android devices. Every time an individual player took any action on the app, a record was logged. Examples of records include:
- “enter game”
- “win”
- “lose”
- “update account”
- “create account”
During our investigation of the database, new entries continued to appear continuously. We estimated an average of approximately 200 million records per day – and sometimes, considerably more.
In total, this amounted to over 50GB of exposed records in the database every single day.
Within many of these records, were various forms of user Personally Identifiable Information (PII) data, including:
- IP addresses
- Email addresses
- Winnings
- Private messages
This data breach was truly global, with millions of records originating from Clubillion’s daily users all over the world. The following list is just a sample of countries affected, along with the average number of daily users from each country:
- USA – 10,000+
- UK – 2,475+
- France – 1,650+
- Israel – 408+
- Germany – 1,582+
- Spain – 1,026+
- Italy – 2,407+
- Netherlands – 622+
- Australia – 6,251+
- Canada – 7,792+
- Brazil – 3,859+
- Sweden – 191+
- Russia – 547+
Other countries affected included Uzbekistan, India, Poland, Romania, Vietnam, Lebanon, Indonesia, Philippines, Pakistan, Thailand, Austria, Hungry, and Latvia.
As you can see, on a single day, 10,000s of individual Clubillion players were exposed. Each one of these players could be targeted by malicious hackers for fraud and cyberattacks – along with millions more whose records were also contained in the database.
Data Breach Impact
Studies have shown that free gambling and gaming apps are especially prone to attacks and hacking from cybercriminals. They are routinely targeted for theft of private data and embedding malicious software on users’ devices.
Despite their popularity, gambling and casino apps often lack transparency, and it can be impossible to know what steps they’re taking to prevent cybercriminals successfully targeting their users.
One study of 23,000 free gambling apps found that: 3,200 posed a ‘moderate risk’ to users; 379 had known security vulnerabilities; 52 contained malicious software.
Any of these issues could be exploited to target app users in a wide range of frauds and cyberattacks, and Clubillion is no different.
With the exposed user PII and knowledge of their activity on the app, hackers could create elaborate schemes to defraud users. For example, some entries also included transaction errors for attempted card payments on Clubillion.
With the information in these transaction errors, hackers could target users with phishing campaigns, with the following aims:
- Trick them into providing their credit card details
- Trick them into providing additional PII to be used against them in further fraud
- Clicking a link that embeds malware, spyware, or ransomware onto their device.
If cybercriminals used Clubillion to embed malware or similar onto a user’s phone, they could potentially hack other apps, access files stored on the device, make calls, and send texts from the hacked device. They could even access a user’s phone contacts and steal the PII data of their friends and family.
Worse still, as people across the globe now find themselves under quarantine or self-isolation, as a result of the Coronavirus pandemic, the impact of a leak like this is potentially even more significant.
Clubillion stands to gain many new users, along with regular users playing more frequently. Hackers will be aware of this and looking for opportunities to exploit any vulnerabilities in the data security of such a massively popular app.
Had criminal hackers discovered Clubillion’s database, they could have targeted millions of people around the world, with devastating results.
Impact on Clubillion and it’s Developers
The most immediate risk for Clubillion is the loss of players. Data security is a growing concern for everyone these days, and this leak could turn many players off the app. Clubillion is not unique, and players have plenty of other choices for free gambling apps.
With fewer players, Clubillion will lose advertising revenue and reduced profits.
As many of Clubillion’s players reside within the EU, the app is under the jurisdiction of GDPR. The rules of GDPR also apply to apps, and Clubillion will need to take specific actions to ensure the regulatory body in charge doesn’t reprimand it.
Finally, Clubillion could also potentially be removed from Google Play and the App Store. Both Apple and Google are clamping down on apps that pose a risk to their users, removing apps embedded with malware, and taking data leaks much more seriously.
Each of these outcomes has a different likelihood of happening, but they would all negatively impact Clubillion’s revenue and business.
Advice from the Experts
Clubillion’s developers could have easily avoided this leak if they had taken some basic security measures to protect the database. These include, but are not limited to:
- Securing their servers.
- Implementing proper access rules.
- Never leaving a system that doesn’t require authentication open to the internet.
Any company can replicate the same steps, no matter its size.
For a more in-depth guide on how to protect your business, check out our guide to securing your website and online database from hackers.
For Clubillion Users
If you play on Clubillion and are concerned about how this breach might impact you, contact the app’s developers directly to find out what steps it’s taking to protect your data.
To learn about data vulnerabilities in general, read our complete guide to online privacy.
It shows you the many ways cybercriminals target internet users, and the steps you can take to stay safe.
How and Why We Discovered the Breach
The vpnMentor research team discovered the breach in Clubillion’s database as part of a huge web mapping project. Our researchers use port scanning to examine particular IP blocks and test different systems for weaknesses or vulnerabilities. They examine each weakness for any data being leaked.
Our team was able to access this database because it was completely unsecured and unencrypted.
Whenever we find a data breach, we use expert techniques to verify the owner of the database, usually a commercial company.
As ethical hackers, we’re obliged to inform a company when we discover flaws in their online security. We reached out to Clubillion’s developers, not only to let them know about the vulnerability but also to suggest ways in which they could make their system secure.
These ethics also mean we carry a responsibility to the public. Clubillion users must be aware of a data breach that exposes so much of their sensitive data.
The purpose of this web mapping project is to help make the internet safer for all users.
Powered by WPeMatico
1spin4win
1spin4win presents Lucky 1spin4win Hold and Win to mark its 5th anniversary
On May 14, 2026, 1spin4win reached a significant milestone — five years on the iGaming market. The anniversary motto, The Gold Standard of Classic Slots, reflects the studio’s evolution into a recognized name in the classic slot niche, built on years of industry expertise and commitment to delivering authentic gambling experiences.
Today, its portfolio features more than 200 games combining timeless appeal, advanced mathematics, and strong performance. In 2025, 1spin4win achieved a 52.06% increase in bet count and a 56.62% rise in GGR compared to 2024. This growth has helped the provider earn the trust of over 1,000 global operators, including leading brands such as SOFTSWISS, EveryMatrix, Alea, SoftGaming, Digitain, and BetConstruct.
As part of the milestone celebration, 1spin4win introduces Lucky 1spin4win Hold and Win, a special slot highlighting the studio’s landmark titles and renowned characters. Alongside traditional fruit, bells, and sevens, the colorful 3×3 grid features Wild symbols shaped as red bezel-set diamonds. When activated, they illuminate the “5 Years” sign, reinforcing the game’s anniversary theme.
The celebratory atmosphere continues through the slot’s rewarding features. Landing nine identical symbols doubles the win, while three or more Coins trigger the exciting Hold and Win Bonus round. With three starting respins, players get the chance to claim two festive Jackpots — the x100 Minipot Coin and the x1000 Megapot.
To mark the 5-year anniversary, 1spin4win is also launching special promotional campaigns in collaboration with Olymp and Selector. To give players additional opportunities to join the celebration, the partners will distribute exclusive promo codes, which will also be available to the registered users of the provider’s Players Room platform.
Olga Hlukhovskaya, Business Development Director at 1spin4win, commented, “Five years in the industry is an important testament to how far 1spin4win has come. Since 2021, we’ve grown into an acknowledged iGaming brand trusted by top global companies. Looking ahead, we plan to keep expanding across African and Latin American markets, deepen our relationships with regional operators, and further strengthen our presence in Europe. For us, this anniversary is not only about celebrating past achievements, but also about building the next stage of 1spin4win’s journey.
Olga Bogdanova, Art Director at 1spin4win, shared, “Lucky 1spin4win Hold and Win is dedicated to the 1spin4win 5th anniversary in the casino industry. The game’s design brings together iconic characters and signature symbols from our previous releases, well-known to both our players and partners. The result is a vibrant product featuring engaging Hold and Win mechanics and the recognizable 1spin4win classic style. We invite everyone to join the celebration of our anniversary, test their luck in the slot, compete for festive jackpots, and revisit their favorite 1spin4win games!”
About 1spin4win
1spin4win is an established game provider founded in May 2021 by ambitious developers with over 15 years of experience in the gambling industry. Since its inception, the company has expanded its portfolio to include over 200 classic online slots, all characterized by quality mathematics, transparent mechanics, and well-balanced gameplay — key factors that drive strong player retention. The studio aims to release an average of four new games each month in 2026 and offers effective promotional tools for casino operators to help them enhance player loyalty.
The post 1spin4win presents Lucky 1spin4win Hold and Win to mark its 5th anniversary appeared first on Eastern European Gaming | Global iGaming & Tech Intelligence Hub.
Games
Stake releases Zoo casino game: a fast, multiplayer Stake Original where players bet on the wild side
A new live-round Stake Original where every player bets on the same outcome – six animals, a 20-tile track, three results per round, and wins up to 1,000x in play.
Stake, the world’s largest online casino and sportsbook, has today launched its Zoo casino game, a new multiplayer Stake Original that brings every player into the same live round to bet on six animals across a 20-tile track. Available worldwide on Stake, Zoo is the latest title to join the growing Stake Originals collection.
Zoo takes the shared-round excitement that has made games like Crash a Stake Originals staple and pairs it with simpler, more visual decision-making. Each round, six animals – Lion, Cheetah, Elephant, Crocodile, Rhino, and Penguin – appear on a 20-tile circular track, with each animal showing up a different number of times to create clear volatility tiers and payout differences across the board. Players have ten seconds to back one or more animals before the track spins up and locks in three result tiles in the center of the screen.
Zoo launches with a 98% RTP, a top multiplier of 1,000x per round, and full auto bet controls that let players preset their wager amount, number of rounds, and chosen animals. Designed as a simpler, more visual evolution of popular casino games like Roulette and Sic Bo, Zoo strips back the complexity without compromising on depth. The rarer the animal, the bigger the reward – Lion and Cheetah each appear only once on the track, Elephant and Crocodile twice, Rhino four times, and Penguin ten, giving players a clear read on the risk and payout of every play. With three result tiles drawn each round, players win based on how many times their chosen animal lands across all three.
“Zoo is exactly the kind of game we want Stake Originals to be known for – fast, simple to pick up, and genuinely fun to play in an online setting filled with other players. There’s real tension in watching the three tiles land for the whole table at once, and we think players are going to find their favourite animals pretty quickly,” said Stake’s Chief Marketing Officer, Akhil Sarin.
Zoo joins a growing line-up of in-house multiplayer game creations on Stake Casino, with the goal of keeping every Stake Original easy to learn, quick to play, and a little bit different from anything else in the iGaming industry.
About Stake
Stake is the world’s largest online casino and sportsbook, attracting over 100 million monthly visits across its global domains – more than any other iGaming platform on earth. Founded in 2017, Stake attracts over 80 million monthly visits and processes more than 100 billion bets per year. Stake is renowned for its innovation in crypto wagering and its growing expansion into regulated local-currency gaming markets, including Italy, Denmark, Brazil, Colombia, and Peru. The brand boasts an extensive global sponsorship portfolio including Drake, X Games, Everton Football Club, and the UFC.
Contact
Stake.com
The post Stake releases Zoo casino game: a fast, multiplayer Stake Original where players bet on the wild side appeared first on Eastern European Gaming | Global iGaming & Tech Intelligence Hub.
Games
Stake releases Zoo casino game: a fast, multiplayer Stake Original where players bet on the wild side
A new live-round Stake Original where every player bets on the same outcome – six animals, a 20-tile track, three results per round, and wins up to 1,000x in play.
Stake, the world’s largest online casino and sportsbook, has today launched its Zoo casino game, a new multiplayer Stake Original that brings every player into the same live round to bet on six animals across a 20-tile track. Available worldwide on Stake, Zoo is the latest title to join the growing Stake Originals collection.
Zoo takes the shared-round excitement that has made games like Crash a Stake Originals staple and pairs it with simpler, more visual decision-making. Each round, six animals – Lion, Cheetah, Elephant, Crocodile, Rhino, and Penguin – appear on a 20-tile circular track, with each animal showing up a different number of times to create clear volatility tiers and payout differences across the board. Players have ten seconds to back one or more animals before the track spins up and locks in three result tiles in the center of the screen.
Zoo launches with a 98% RTP, a top multiplier of 1,000x per round, and full auto bet controls that let players preset their wager amount, number of rounds, and chosen animals. Designed as a simpler, more visual evolution of popular casino games like Roulette and Sic Bo, Zoo strips back the complexity without compromising on depth. The rarer the animal, the bigger the reward – Lion and Cheetah each appear only once on the track, Elephant and Crocodile twice, Rhino four times, and Penguin ten, giving players a clear read on the risk and payout of every play. With three result tiles drawn each round, players win based on how many times their chosen animal lands across all three.
“Zoo is exactly the kind of game we want Stake Originals to be known for – fast, simple to pick up, and genuinely fun to play in an online setting filled with other players. There’s real tension in watching the three tiles land for the whole table at once, and we think players are going to find their favourite animals pretty quickly,” said Stake’s Chief Marketing Officer, Akhil Sarin.
Zoo joins a growing line-up of in-house multiplayer game creations on Stake Casino, with the goal of keeping every Stake Original easy to learn, quick to play, and a little bit different from anything else in the iGaming industry.
About Stake
Stake is the world’s largest online casino and sportsbook, attracting over 100 million monthly visits across its global domains – more than any other iGaming platform on earth. Founded in 2017, Stake attracts over 80 million monthly visits and processes more than 100 billion bets per year. Stake is renowned for its innovation in crypto wagering and its growing expansion into regulated local-currency gaming markets, including Italy, Denmark, Brazil, Colombia, and Peru. The brand boasts an extensive global sponsorship portfolio including Drake, X Games, Everton Football Club, and the UFC.
Contact
Stake.com
The post Stake releases Zoo casino game: a fast, multiplayer Stake Original where players bet on the wild side appeared first on Americas iGaming & Sports Betting News.
-
AGCO6 days agoAGCO Takes Enforcement Action Against Two Companies for Allowing Their Games on Unregulated Gaming Websites
-
Apple5 days agoIBJR hails App Store approval as a milestone in the fight against illegal betting in Brazil
-
AB Trav och Galopp6 days agoRichard Woodbridge Elected to ATG Board of Directors
-
Caleta Gaming6 days agoCaleta Gaming launches Cluster Cup high-volatility football-themed slot
-
apuestas deportivas5 days ago¿Por qué Pix es central en la lucha contra el mercado ilegal de apuestas?
-
game release6 days agoSpinomenal adds Desperado Drifter Hold & Hit 3×3 to slot portfolio
-
Brazil5 days agoEsportes da Sorte campaign celebrates fans’ resilience in support of Brazil
-
Africa5 days agoBroadway Platform Partners with Ghanaian Operator Afrinova



