Latest News
Popular Gambling App Exposed Millions of Users in Massive Data Leak
Led by Noam Rotem and Ran Locar, vpnMentor’s research team discovered a data breach on casino gambling app Clubillion.
The breach originated in a technical database built on an Elasticsearch engine and was recording the daily activities of millions of Clubillion players around the world.
Aside from leaking activity on the app, the breached database also exposed private user information.
With this information publicly available, Clubillion’s users were vulnerable to fraud and various online attacks with potentially devastating results.
Company Profile
Clubillion is a free online casino game available for iOS and Android, offering players 30+ free slot games. While each app is listed under a different developer – Ouroboros on iOS and T7 Games on Android – these are most likely owned by the same company.
Both versions of Clubillion were released in 2019 and became instant hits. Each is now ranked the #1 ‘social slots’ casino app on Google Play and the App Store, with a 4.8 star on both.
Timeline of Discovery and Owner Reaction
Sometimes, the extent of a data breach and the owner of the database are obvious, and the issue quickly resolved. But rare are these times. Most often, we need days of investigation before we understand what’s at stake or who’s leaking the data.
Understanding a breach and its potential impact takes careful attention and time. We work hard to publish accurate and trustworthy reports, ensuring everybody who reads them understands their seriousness.
Some affected parties deny the facts, disregarding our research, or playing down its impact. So, we need to be thorough and make sure everything we find is correct and accurate.
In this case, the database was built on Elasticsearch and hosted on Amazon Web Services (AWS), with Clubillion’s name on its apps, and links to assets owned by the company.
Once Clubillion was confirmed as the owner of the database, we reached out to the developers. While awaiting a reply, we also contacted AWS with details of the leak. It was closed a few days later.
- Date discovered: 19th March 2020
- Date vendors contacted: 23rd March 2020
- Date of contact with AWS: 31st March 2020
- Date of Action: Approx. 5th April 2020
Example of Entries in the Database
Clubillion’s exposed database contained technical logs for millions of Clubillion users around the world, on both iOS and Android devices. Every time an individual player took any action on the app, a record was logged. Examples of records include:
- “enter game”
- “win”
- “lose”
- “update account”
- “create account”
During our investigation of the database, new entries continued to appear continuously. We estimated an average of approximately 200 million records per day – and sometimes, considerably more.
In total, this amounted to over 50GB of exposed records in the database every single day.
Within many of these records, were various forms of user Personally Identifiable Information (PII) data, including:
- IP addresses
- Email addresses
- Winnings
- Private messages
This data breach was truly global, with millions of records originating from Clubillion’s daily users all over the world. The following list is just a sample of countries affected, along with the average number of daily users from each country:
- USA – 10,000+
- UK – 2,475+
- France – 1,650+
- Israel – 408+
- Germany – 1,582+
- Spain – 1,026+
- Italy – 2,407+
- Netherlands – 622+
- Australia – 6,251+
- Canada – 7,792+
- Brazil – 3,859+
- Sweden – 191+
- Russia – 547+
Other countries affected included Uzbekistan, India, Poland, Romania, Vietnam, Lebanon, Indonesia, Philippines, Pakistan, Thailand, Austria, Hungry, and Latvia.
As you can see, on a single day, 10,000s of individual Clubillion players were exposed. Each one of these players could be targeted by malicious hackers for fraud and cyberattacks – along with millions more whose records were also contained in the database.
Data Breach Impact
Studies have shown that free gambling and gaming apps are especially prone to attacks and hacking from cybercriminals. They are routinely targeted for theft of private data and embedding malicious software on users’ devices.
Despite their popularity, gambling and casino apps often lack transparency, and it can be impossible to know what steps they’re taking to prevent cybercriminals successfully targeting their users.
One study of 23,000 free gambling apps found that: 3,200 posed a ‘moderate risk’ to users; 379 had known security vulnerabilities; 52 contained malicious software.
Any of these issues could be exploited to target app users in a wide range of frauds and cyberattacks, and Clubillion is no different.
With the exposed user PII and knowledge of their activity on the app, hackers could create elaborate schemes to defraud users. For example, some entries also included transaction errors for attempted card payments on Clubillion.
With the information in these transaction errors, hackers could target users with phishing campaigns, with the following aims:
- Trick them into providing their credit card details
- Trick them into providing additional PII to be used against them in further fraud
- Clicking a link that embeds malware, spyware, or ransomware onto their device.
If cybercriminals used Clubillion to embed malware or similar onto a user’s phone, they could potentially hack other apps, access files stored on the device, make calls, and send texts from the hacked device. They could even access a user’s phone contacts and steal the PII data of their friends and family.
Worse still, as people across the globe now find themselves under quarantine or self-isolation, as a result of the Coronavirus pandemic, the impact of a leak like this is potentially even more significant.
Clubillion stands to gain many new users, along with regular users playing more frequently. Hackers will be aware of this and looking for opportunities to exploit any vulnerabilities in the data security of such a massively popular app.
Had criminal hackers discovered Clubillion’s database, they could have targeted millions of people around the world, with devastating results.
Impact on Clubillion and it’s Developers
The most immediate risk for Clubillion is the loss of players. Data security is a growing concern for everyone these days, and this leak could turn many players off the app. Clubillion is not unique, and players have plenty of other choices for free gambling apps.
With fewer players, Clubillion will lose advertising revenue and reduced profits.
As many of Clubillion’s players reside within the EU, the app is under the jurisdiction of GDPR. The rules of GDPR also apply to apps, and Clubillion will need to take specific actions to ensure the regulatory body in charge doesn’t reprimand it.
Finally, Clubillion could also potentially be removed from Google Play and the App Store. Both Apple and Google are clamping down on apps that pose a risk to their users, removing apps embedded with malware, and taking data leaks much more seriously.
Each of these outcomes has a different likelihood of happening, but they would all negatively impact Clubillion’s revenue and business.
Advice from the Experts
Clubillion’s developers could have easily avoided this leak if they had taken some basic security measures to protect the database. These include, but are not limited to:
- Securing their servers.
- Implementing proper access rules.
- Never leaving a system that doesn’t require authentication open to the internet.
Any company can replicate the same steps, no matter its size.
For a more in-depth guide on how to protect your business, check out our guide to securing your website and online database from hackers.
For Clubillion Users
If you play on Clubillion and are concerned about how this breach might impact you, contact the app’s developers directly to find out what steps it’s taking to protect your data.
To learn about data vulnerabilities in general, read our complete guide to online privacy.
It shows you the many ways cybercriminals target internet users, and the steps you can take to stay safe.
How and Why We Discovered the Breach
The vpnMentor research team discovered the breach in Clubillion’s database as part of a huge web mapping project. Our researchers use port scanning to examine particular IP blocks and test different systems for weaknesses or vulnerabilities. They examine each weakness for any data being leaked.
Our team was able to access this database because it was completely unsecured and unencrypted.
Whenever we find a data breach, we use expert techniques to verify the owner of the database, usually a commercial company.
As ethical hackers, we’re obliged to inform a company when we discover flaws in their online security. We reached out to Clubillion’s developers, not only to let them know about the vulnerability but also to suggest ways in which they could make their system secure.
These ethics also mean we carry a responsibility to the public. Clubillion users must be aware of a data breach that exposes so much of their sensitive data.
The purpose of this web mapping project is to help make the internet safer for all users.
Powered by WPeMatico
Latest News
March sports calendar 2026: use Boomerang Partners’ schedule to win in the TIME TO WIN tournament
The halfway point of the TIME TO WIN affiliate tournament, organized by Boomerang Partners, is approaching. Until March 31st, participating teams can complete five types of tasks and accumulate points to gain access to five draws for valuable prizes. The company is offering unique experiences and rewards, thanks to its status as an Official Regional Partner of AC Milan: ranging from a trip to Milan for a top-tier Serie A match against FC Juventus to an exclusive visit to Milanello powered by Clivet, AC Milan’s training ground.
The perfect time to join the TIME TO WIN tournament
Affiliate teams that haven’t yet joined the TIME TO WIN tournament can do so at any time. And right now is the perfect moment to jump in – the March sports calendar is packed with top-tier tournaments. Sports-focused affiliates can leverage this by tackling the task of driving new sports users for brands in Boomerang Partners’ client portfolio. The more points they earn, the higher their chances of qualifying for the prize draws. These prizes include exclusive TIME TO WIN merch packs, official AC Milan jerseys signed by players, a trip to the AC Milan v Cagliari home match, a trip to the AC Milan v Juventus home match complete with exclusive behind-the-scenes access, and an exclusive trip to AC Milan’s legendary Milanello powered by Clivet training base.
Here are just a few examples of promising tournaments for participants in the TIME TO WIN competition:
- March 10-12 and 17-19: UEFA Champions League Round of 16 matches
- March 12-13 and 19-20: UEFA Europa League and Conference League Round of 16 matches
- March 25: The MLB season kicks off with San Francisco Giants v New York Yankees at Oracle Park, the world’s premier baseball league
- March 15-29: The Miami Open, one of tennis’s elite events, takes place
- The NHL and NBA regular seasons are approaching their decisive phases – by the end of March, the playoff picture for many teams should become clearer.
Given that March is packed with sports tournaments, affiliate teams can avoid traffic drops by effectively switching their audience from one competition to another. To do this, they need to encourage migration, for example, from football to tennis by highlighting major tournaments, daily express bets, and simple markets. Successfully managing this helps affiliates reduce churn and retain traffic across sports.
Timing is key during a busy sports season. Therefore, preparation and attention to detail are essential for affiliates. Affiliates can benefit from using performance dashboards to track campaigns by geographical region, device, and traffic type, maintain a content calendar for Pre-, Live-, and Post-event pushes, and regularly review conversion and traffic data to refine audience targeting and offer selection. Interested affiliate teams (especially TIME TO WIN tournament participants) can find more useful tips in the Calendar.
Darina Sharban, Affiliate Team Lead at Boomerang Partners: “We expected a strong start to the tournament, but the level of participant activity has still impressed us. We’re seeing interest across all five task types and are confident the competition for the prizes will be fierce. It’s great that we can offer our affiliate partners such unique prizes, like the trip to Milanello. Good luck to everyone!”
Only ___ days remain until the end of the tournament – it concludes on March 31st. Every day, the participants are racking up more points. Now is the time to make your move.
About Boomerang
Boomerang Partners is a rapidly growing global marketing agency offering a wide range of services. Boomerang Partners is an Official Regional Partner of AC Milan. In 2024, it launched the inaugural Golden Boomerang Awards – a global tournament for affiliate teams. More than 400 affiliate teams participated in the second season of the tournament in 2025. Partners of the Agency launched six new products in 2024-2025, contributing to a nearly 1.5-fold increase in product users.
The agency’s client portfolio contains 10+ brands offering affiliate and entertainment services across 40+ markets in compliance with local regulations. These products provide personalized bonuses and 24/7 multilingual support.
iGaming
Tugi Tark and Narnium Solutions Announce Strategic Partnership to Strengthen Player Support Across Multiple iGaming Brands
Tugi Tark has entered into a strategic partnership with Narnium Solutions, an operator managing multiple online casino brands, to deploy its customer service platform alongside AI-powered support agents across the operator’s portfolio.
Narnium Solutions brings over 15 years of experience spanning casino operations, compliance, payments, marketing, and platform management. As the company continues to expand across both emerging and established markets, delivering scalable and consistent player support has become a key operational priority.
Through this collaboration, Narnium Solutions is integrating Tugi Tark’s platform and AI agents—trained on more than 10 million real iGaming support interactions—to streamline player communication across all brands within a single, unified environment.
A company representative at Narnium Solutions said:
“Partnering with Tugi Tark marks an important step forward for us. We’re excited to introduce an AI-powered chat experience into our ecosystem, strengthening our modern iGaming stack and enhancing player communication across our brands.”
The platform is being used to centralise support operations across the NarniaSlots brand family. Tugi Tark’s AI-driven chat widget is embedded directly into each site, enabling automated handling of player queries while allowing support teams to focus on more complex cases within a shared workspace.
The solution is designed to scale alongside Narnium Solutions’ growing pipeline, which includes upcoming brands such as Lucky Mary and House of Slots, as the company continues to expand its footprint.
Harpo Lilja, CEO of Tugi Tark, said:
“Narnium Solutions operates on a global scale with the kind of multi-brand complexity our platform was built to support. We’re pleased to welcome them on board and to power player support across their entire portfolio.”
The partnership aligns with Narnium Solutions’ broader strategy of building compliant, scalable iGaming operations across international markets. With a centralised support infrastructure and AI-driven capabilities in place, the company is well positioned to deliver consistent, high-quality player experiences as it continues to grow.
The post Tugi Tark and Narnium Solutions Announce Strategic Partnership to Strengthen Player Support Across Multiple iGaming Brands appeared first on Eastern European Gaming | Global iGaming & Tech Intelligence Hub.
Industry News
QTech Games recruits banking and AI leader Jonny Youssef as CTO to drive next phase of its growth journey
QTech Games, the leading game aggregator for emerging markets, has appointed Jonny Youssef as Chief Technology Officer (CTO) to lead the next phase of the company’s technology organisation, innovation and technology strategy as QTech accelerates its global expansion. Jonny will lead the continued development of QTech’s platform architecture and engineering organisation, focusing on scalability, AI-driven capabilities and next-generation tools designed to support operators and content partners across fast-growing markets. Jonny brings more than 20 years of technology leadership experience across banking, fintech, SaaS platforms and AI-driven innovation. His background combines enterprise-scale infrastructure expertise with hands-on experience building and scaling digital platforms and emerging technology systems. Previously, Jonny served as Head of Innovation for Swedbank Group Lending & Payments, where he led digital initiatives across lending, payments, APIs and digital channels within one of the Nordic region’s largest banking groups. He has also held senior technology leadership roles at Entercard Group, overseeing technology infrastructure and mission-critical production environments supporting large-scale payment operations across Nordic markets. Alongside his enterprise leadership experience, Jonny has founded and scaled several technology ventures and digital platforms. As a technology founder and CTO, he has led the design and development of international platforms operating across Europe and Asia, building distributed engineering teams and scalable digital infrastructure.
In recent years, Jonny has contributed to the development of next-generation AI and sustainability technology initiatives, including work with Circular Living and Biotonomy, where advanced AI, IoT and Edge AI systems are used to power intelligent environments, autonomous infrastructure and real-time operational insights. Beyond his commercial initiatives, he is also a board member and early contributor to The AI Community of Sweden, a national innovation network connecting professionals, enterprises and academia to collaborate on AI innovation. At QTech Games, Jonny will focus on strengthening the company’s technology foundations as it continues to scale globally, enhancing AI-driven functionality, automation and analytics capabilities that enable partners to unlock greater value from the platform. He will also oversee QTech’s engineering and technology teams to ensure continued innovation while maintaining the speed, reliability and integration flexibility that have become hallmarks of QTech’s aggregation platform.
QTech Games’ CEO, Philip Doftvik, said: “We’re delighted to welcome Jonny to QTech at an important moment in our growth journey.
“He brings a rare combination of enterprise technology leadership, platform-building expertise and forward-looking innovation in AI and automation. His experience across banking infrastructure, global digital platforms and emerging technology ecosystems makes him uniquely positioned to guide us through its next phase of technological evolution.
“As we continue to expand across emerging markets, Jonny’s leadership will help ensure we remain at the forefront of innovation — delivering scalable infrastructure, AI-driven insights and powerful technology solutions that help our partners grow.”
Jonny Youssef added: “QTech Games has built a strong reputation as one of the most innovative and reliable aggregation platforms serving emerging markets.
“What impressed me most is the company’s focus on speed, simplicity and partner success — combined with a clear ambition to continue evolving the platform through technology. I’m excited to join the team at a time when AI, automation and data-driven capabilities are creating new opportunities to deliver even greater value to operators and game providers.
“My focus will be on strengthening the platform architecture, scaling our technology capabilities with AI and supporting the next phase of QTech’s growth.”
The post QTech Games recruits banking and AI leader Jonny Youssef as CTO to drive next phase of its growth journey appeared first on Eastern European Gaming | Global iGaming & Tech Intelligence Hub.
-
Africa7 days agoBooming Games teams up with Agreegain to power continued African growth
-
Canada7 days agoWazdan launches Green Brick Labs partnership via Maverick Games to expand Ontario reach
-
Australia6 days agoRegulating the Game Global Awards: First-Ever Winners Announced
-
Asia7 days agoGodLike Esports’ gaming creator Sharkshe unveils upgraded gaming room powered by Red Bull
-
Africa7 days agoHollywoodbets to deploy ClearStake’s ID by Bank for improved player verification
-
AGCO5 days agoCanada’s Ontario iGaming Market in 2026: Advertising Rules, Self-Exclusion and the Next Phase of Regulation
-
Asia6 days agoPG Soft revealed as Title Sponsor for Global Game Connect 2026
-
Asia5 days agoNODWIN Gaming joins forces with ICONiQ White to headline NH7 Weekender 2026 as Title Sponsor; to be ‘Powered By’ Mastercard



