Latest News
Popular Gambling App Exposed Millions of Users in Massive Data Leak

Led by Noam Rotem and Ran Locar, vpnMentor’s research team discovered a data breach on casino gambling app Clubillion.
The breach originated in a technical database built on an Elasticsearch engine and was recording the daily activities of millions of Clubillion players around the world.
Aside from leaking activity on the app, the breached database also exposed private user information.
With this information publicly available, Clubillion’s users were vulnerable to fraud and various online attacks with potentially devastating results.
Company Profile
Clubillion is a free online casino game available for iOS and Android, offering players 30+ free slot games. While each app is listed under a different developer – Ouroboros on iOS and T7 Games on Android – these are most likely owned by the same company.
Both versions of Clubillion were released in 2019 and became instant hits. Each is now ranked the #1 ‘social slots’ casino app on Google Play and the App Store, with a 4.8 star on both.
Timeline of Discovery and Owner Reaction
Sometimes, the extent of a data breach and the owner of the database are obvious, and the issue quickly resolved. But rare are these times. Most often, we need days of investigation before we understand what’s at stake or who’s leaking the data.
Understanding a breach and its potential impact takes careful attention and time. We work hard to publish accurate and trustworthy reports, ensuring everybody who reads them understands their seriousness.
Some affected parties deny the facts, disregarding our research, or playing down its impact. So, we need to be thorough and make sure everything we find is correct and accurate.
In this case, the database was built on Elasticsearch and hosted on Amazon Web Services (AWS), with Clubillion’s name on its apps, and links to assets owned by the company.
Once Clubillion was confirmed as the owner of the database, we reached out to the developers. While awaiting a reply, we also contacted AWS with details of the leak. It was closed a few days later.
- Date discovered: 19th March 2020
- Date vendors contacted: 23rd March 2020
- Date of contact with AWS: 31st March 2020
- Date of Action: Approx. 5th April 2020
Example of Entries in the Database
Clubillion’s exposed database contained technical logs for millions of Clubillion users around the world, on both iOS and Android devices. Every time an individual player took any action on the app, a record was logged. Examples of records include:
- “enter game”
- “win”
- “lose”
- “update account”
- “create account”
During our investigation of the database, new entries continued to appear continuously. We estimated an average of approximately 200 million records per day – and sometimes, considerably more.
In total, this amounted to over 50GB of exposed records in the database every single day.
Within many of these records, were various forms of user Personally Identifiable Information (PII) data, including:
- IP addresses
- Email addresses
- Winnings
- Private messages
This data breach was truly global, with millions of records originating from Clubillion’s daily users all over the world. The following list is just a sample of countries affected, along with the average number of daily users from each country:
- USA – 10,000+
- UK – 2,475+
- France – 1,650+
- Israel – 408+
- Germany – 1,582+
- Spain – 1,026+
- Italy – 2,407+
- Netherlands – 622+
- Australia – 6,251+
- Canada – 7,792+
- Brazil – 3,859+
- Sweden – 191+
- Russia – 547+
Other countries affected included Uzbekistan, India, Poland, Romania, Vietnam, Lebanon, Indonesia, Philippines, Pakistan, Thailand, Austria, Hungry, and Latvia.
As you can see, on a single day, 10,000s of individual Clubillion players were exposed. Each one of these players could be targeted by malicious hackers for fraud and cyberattacks – along with millions more whose records were also contained in the database.
Data Breach Impact
Studies have shown that free gambling and gaming apps are especially prone to attacks and hacking from cybercriminals. They are routinely targeted for theft of private data and embedding malicious software on users’ devices.
Despite their popularity, gambling and casino apps often lack transparency, and it can be impossible to know what steps they’re taking to prevent cybercriminals successfully targeting their users.
One study of 23,000 free gambling apps found that: 3,200 posed a ‘moderate risk’ to users; 379 had known security vulnerabilities; 52 contained malicious software.
Any of these issues could be exploited to target app users in a wide range of frauds and cyberattacks, and Clubillion is no different.
With the exposed user PII and knowledge of their activity on the app, hackers could create elaborate schemes to defraud users. For example, some entries also included transaction errors for attempted card payments on Clubillion.
With the information in these transaction errors, hackers could target users with phishing campaigns, with the following aims:
- Trick them into providing their credit card details
- Trick them into providing additional PII to be used against them in further fraud
- Clicking a link that embeds malware, spyware, or ransomware onto their device.
If cybercriminals used Clubillion to embed malware or similar onto a user’s phone, they could potentially hack other apps, access files stored on the device, make calls, and send texts from the hacked device. They could even access a user’s phone contacts and steal the PII data of their friends and family.
Worse still, as people across the globe now find themselves under quarantine or self-isolation, as a result of the Coronavirus pandemic, the impact of a leak like this is potentially even more significant.
Clubillion stands to gain many new users, along with regular users playing more frequently. Hackers will be aware of this and looking for opportunities to exploit any vulnerabilities in the data security of such a massively popular app.
Had criminal hackers discovered Clubillion’s database, they could have targeted millions of people around the world, with devastating results.
Impact on Clubillion and it’s Developers
The most immediate risk for Clubillion is the loss of players. Data security is a growing concern for everyone these days, and this leak could turn many players off the app. Clubillion is not unique, and players have plenty of other choices for free gambling apps.
With fewer players, Clubillion will lose advertising revenue and reduced profits.
As many of Clubillion’s players reside within the EU, the app is under the jurisdiction of GDPR. The rules of GDPR also apply to apps, and Clubillion will need to take specific actions to ensure the regulatory body in charge doesn’t reprimand it.
Finally, Clubillion could also potentially be removed from Google Play and the App Store. Both Apple and Google are clamping down on apps that pose a risk to their users, removing apps embedded with malware, and taking data leaks much more seriously.
Each of these outcomes has a different likelihood of happening, but they would all negatively impact Clubillion’s revenue and business.
Advice from the Experts
Clubillion’s developers could have easily avoided this leak if they had taken some basic security measures to protect the database. These include, but are not limited to:
- Securing their servers.
- Implementing proper access rules.
- Never leaving a system that doesn’t require authentication open to the internet.
Any company can replicate the same steps, no matter its size.
For a more in-depth guide on how to protect your business, check out our guide to securing your website and online database from hackers.
For Clubillion Users
If you play on Clubillion and are concerned about how this breach might impact you, contact the app’s developers directly to find out what steps it’s taking to protect your data.
To learn about data vulnerabilities in general, read our complete guide to online privacy.
It shows you the many ways cybercriminals target internet users, and the steps you can take to stay safe.
How and Why We Discovered the Breach
The vpnMentor research team discovered the breach in Clubillion’s database as part of a huge web mapping project. Our researchers use port scanning to examine particular IP blocks and test different systems for weaknesses or vulnerabilities. They examine each weakness for any data being leaked.
Our team was able to access this database because it was completely unsecured and unencrypted.
Whenever we find a data breach, we use expert techniques to verify the owner of the database, usually a commercial company.
As ethical hackers, we’re obliged to inform a company when we discover flaws in their online security. We reached out to Clubillion’s developers, not only to let them know about the vulnerability but also to suggest ways in which they could make their system secure.
These ethics also mean we carry a responsibility to the public. Clubillion users must be aware of a data breach that exposes so much of their sensitive data.
The purpose of this web mapping project is to help make the internet safer for all users.
Powered by WPeMatico
Latest News
DBET partners with Swedish Basketball Association for multi-year sponsorship deal

Immense Group is proud to announce that its sport betting brand DBET has entered a multi-year strategic partnership with the Swedish Basketball Association (SBBF) and the top leagues SBL Women and SBL Men. The collaboration, which will kick off with the Women’s European Championship 2025, marks a significant step in DBET’s ongoing commitment to deepening its presence in Sweden’s sports landscape and enhancing the experience for Swedish basketball fans.
As part of the partnership, DBET will sponsor the senior national teams and the SBL leagues, SBL Dam and SBL Herr. The deal will extend through to the Men’s World Championship 2027, providing ample opportunity to engage with Swedish sports fans across multiple platforms and events.
“Partnering with DBET, a dynamic and innovative player in the betting market, is an exciting opportunity for Swedish basketball,” says Susanne Jidesten, Chairwoman of the Swedish Basketball Association. “Together, we can broaden the reach of Swedish basketball and create new engagement opportunities for both fans and players.”
Launched in 2024, DBET has quickly gained recognition in the Swedish gaming market with a focus on responsible gaming and community involvement. This new collaboration with Swedish basketball underscores DBET’s commitment to growing its brand presence while supporting the expansion of Swedish basketball on both the national and league levels.
“We are excited to partner with Swedish basketball, a sport that is rapidly gaining popularity in Sweden,” says Jesper Kärrbrink, Group CEO/Chairman of Immense Group. “This partnership will help us engage with Swedish sports fans and strengthen DBET’s position in Sweden’s sports betting market.”
This collaboration builds on DBET’s growing presence in Swedish sports, including its recent partnership with football legend Anders Svensson and its involvement with the Swedish Bandy Association. DBET remains committed to expanding its reach in the Swedish sports sector through strategic alliances with iconic teams and athletes.
The post DBET partners with Swedish Basketball Association for multi-year sponsorship deal appeared first on European Gaming Industry News.
Eberhard Dürrschmid CEO at Golden Whale
Golden Whale to broaden horizons with Logrand partnership

Pioneering data-driven service provider teams up with fast-growing Mexico-focused online casino group to extend its operations into Latin America for the first time
With Golden Whale’s mission to extend its innovative data-driven services to every corner of the globe continuing to pick up pace, the company has announced it has formed a new partnership with Logrand Entertainment Group that will see it enter Mexico in 2025.
Rightfully recognised as one of the fastest growing markets in the Latin American region, over the coming months Golden Whale will work with Logrand’s Strendus.mx online casino brand to implement a number of AI and ML-backed solutions that will enhance the platform’s operations.
Already one of the country’s best-loved online gambling destinations, Strendus.mx was the first Mexican site launched by Logrand and currently offers customers a market-leading selection of over 4,000 slots, table games and live casino options as well as a dedicated sports betting hub.
Active since 2017, Strendus.mx has steadily built up a loyal following among Mexican players thanks to its generous promotions, popular loyalty scheme and engaging gamification mechanics – all of which are major areas where Golden Whale’s solutions can add further value.
In addition to its commitment to innovation and customer engagement, Strendus.mx also maintains a strong focus on corporate social responsibility. This year, the brand has further strengthened its efforts by supporting a variety of charitable initiatives, including programs that promote donations to institutions dedicated to helping children affected by catastrophic illnesses. These activities reflect Strendus’ broader vision of not only delivering top-tier entertainment but also contributing positively to the communities in which it operates.
Given the wealth of player data the site has accumulated since its launch, there will be plenty of information that can be run through Golden Whale’s advanced AI and ML modules to optimise Strendus.mx’s operations, and both companies are excited about the opportunities ahead.
Eberhard Dürrschmid, CEO at Golden Whale, said: “Many iGaming companies have already woken up to the benefits that Golden Whale’s powerful AI and ML-backed technology can bring, so the next step for us is making sure our solutions are available in as many markets as possible. This new partnership with Logrand will enable us to breach new frontiers in Latin America via the Strendus.mx casino brand and I’m looking forward to seeing the impact we can make there.”
Eduardo Pelaez, COO Online at Logrand Entertainment Group, said: “Launched in 2017, Strendus.mx is already one of Mexico’s flagship online casino brands – but we want to push this legacy further. By partnering with Golden Whale, we’ll be able to harness the power of AI and ML to deliver an even more personalised experience to Strendus.mx’s customers, helping us cement our position as both a genuine innovator and a true market leader in the LatAm region.”
The post Golden Whale to broaden horizons with Logrand partnership appeared first on Gaming and Gambling Industry in the Americas.
Latest News
Soft2Bet to Unveil MEGA-Powered Engagement Workshops and Turnkey Platform at iGB Live 2025

Soft2Bet, a leading turnkey iGaming provider that delivers high-quality products and services for online gambling operators, will exhibit at iGB Live 2025 in London on 2–3 July. Known for its data-driven iGaming solutions for player retention, which drive brand performance across the Nordic, European, and North American markets, the company will host One-on-One Workshop Sessions at Stand N46 and participate in key discussions where major market developments are explored. Attendees can explore its full-service platform alongside MEGA, the gamification layer behind recent revenue growth across its operator portfolio.
Over the past six months since ICE 2025 Barcelona, Soft2Bet has launched new brands, secured new deals, and formed strategic partnerships across key markets. During this period, the company continues to track strong operator results, with measurable gains across core performance indicators. Brands using Soft2Bet’s platform have seen a 65% increase in net gaming revenue and a 45% rise in average revenue per user. Player screen time has quadrupled. Deposit values are up 50%, with deposit frequency increasing by 30%.
These results are driven by MEGA’s real-time missions, challenges, and loyalty features, along with integrated player account management, a proprietary CMS, access to over 12,500 casino games through a single integration, a full sportsbook, a flexible payments hub, and adaptive operating models backed by no-code tools and analytics.
This momentum is reflected in the performance of Soft2Bet’s brands, including Betinia, CampoBet, ToonieBet, QuickCasino, and Don.ro. These have been recognised by major industry awards and approved by reputable regulators. Their success is further supported by a strong focus on UX and UI innovation, helping each brand to implement effective localised strategies. As a result, they have achieved leading positions in app stores, resonating strongly with local users and fans.
“iGB Live is a valuable moment to show how our technology moves beyond traditional methods of player engagement,” stated Martin Collins, Chief Business Development Officer of Soft2Bet. “We’ll be sharing real examples of how MEGA and the wider Soft2Bet platform work as a unified ecosystem where design, personalisation, and gamification come together to support stronger engagement and long-term results.”
To help prospective partners apply these results to their own operations, Soft2Bet will offer one-to-one MEGA workshops during the show. These 30-minute sessions, led by Sales Director Nicolas Campano and Senior Sales Managers Ross Main and Slobodan Georgijevski will run across both exhibition days and offer a hands-on look at how MEGA drives engagement, retention, and player value. Slots are limited and can be booked in advance at https://www.soft2bet.com/mega.
The post Soft2Bet to Unveil MEGA-Powered Engagement Workshops and Turnkey Platform at iGB Live 2025 appeared first on European Gaming Industry News.
-
Africa6 days ago
Uganda: National Lotteries and Gaming Regulatory Board and Uganda Police- Rwizi Region Deepen Ties in Enforcing the Gaming Law
-
BMM Innovation Group6 days ago
BMM Innovation Group to Participate in Peru Gaming Show 2025
-
Conferences7 days ago
Win Systems will showcase its new range of Gold Club Colors electronic roulettes at PGS.
-
Latest News6 days ago
Light Up the Reels with Explosive Wins in Liberty & Freedom Hold and Win Extreme 10,000
-
Amusnet6 days ago
Amusnet Strengthens Commitment to Latin America at Peru Gaming Show
-
Darwin Filho6 days ago
Onabet marks its second anniversary with digital expansion and a sharpened focus on the casino segment
-
Balkans5 days ago
SYNOT Group Showcased its Latest Products at Belgrade Future Gaming 2025
-
Friday Fireworks5 days ago
Plaza Hotel & Casino to celebrate Fourth of July with a holiday edition of its free Welcome to the Weekend Friday Fireworks