Latest News
Popular Gambling App Exposed Millions of Users in Massive Data Leak

Led by Noam Rotem and Ran Locar, vpnMentor’s research team discovered a data breach on casino gambling app Clubillion.
The breach originated in a technical database built on an Elasticsearch engine and was recording the daily activities of millions of Clubillion players around the world.
Aside from leaking activity on the app, the breached database also exposed private user information.
With this information publicly available, Clubillion’s users were vulnerable to fraud and various online attacks with potentially devastating results.
Company Profile
Clubillion is a free online casino game available for iOS and Android, offering players 30+ free slot games. While each app is listed under a different developer – Ouroboros on iOS and T7 Games on Android – these are most likely owned by the same company.
Both versions of Clubillion were released in 2019 and became instant hits. Each is now ranked the #1 ‘social slots’ casino app on Google Play and the App Store, with a 4.8 star on both.
Timeline of Discovery and Owner Reaction
Sometimes, the extent of a data breach and the owner of the database are obvious, and the issue quickly resolved. But rare are these times. Most often, we need days of investigation before we understand what’s at stake or who’s leaking the data.
Understanding a breach and its potential impact takes careful attention and time. We work hard to publish accurate and trustworthy reports, ensuring everybody who reads them understands their seriousness.
Some affected parties deny the facts, disregarding our research, or playing down its impact. So, we need to be thorough and make sure everything we find is correct and accurate.
In this case, the database was built on Elasticsearch and hosted on Amazon Web Services (AWS), with Clubillion’s name on its apps, and links to assets owned by the company.
Once Clubillion was confirmed as the owner of the database, we reached out to the developers. While awaiting a reply, we also contacted AWS with details of the leak. It was closed a few days later.
- Date discovered: 19th March 2020
- Date vendors contacted: 23rd March 2020
- Date of contact with AWS: 31st March 2020
- Date of Action: Approx. 5th April 2020
Example of Entries in the Database
Clubillion’s exposed database contained technical logs for millions of Clubillion users around the world, on both iOS and Android devices. Every time an individual player took any action on the app, a record was logged. Examples of records include:
- “enter game”
- “win”
- “lose”
- “update account”
- “create account”
During our investigation of the database, new entries continued to appear continuously. We estimated an average of approximately 200 million records per day – and sometimes, considerably more.
In total, this amounted to over 50GB of exposed records in the database every single day.
Within many of these records, were various forms of user Personally Identifiable Information (PII) data, including:
- IP addresses
- Email addresses
- Winnings
- Private messages
This data breach was truly global, with millions of records originating from Clubillion’s daily users all over the world. The following list is just a sample of countries affected, along with the average number of daily users from each country:
- USA – 10,000+
- UK – 2,475+
- France – 1,650+
- Israel – 408+
- Germany – 1,582+
- Spain – 1,026+
- Italy – 2,407+
- Netherlands – 622+
- Australia – 6,251+
- Canada – 7,792+
- Brazil – 3,859+
- Sweden – 191+
- Russia – 547+
Other countries affected included Uzbekistan, India, Poland, Romania, Vietnam, Lebanon, Indonesia, Philippines, Pakistan, Thailand, Austria, Hungry, and Latvia.
As you can see, on a single day, 10,000s of individual Clubillion players were exposed. Each one of these players could be targeted by malicious hackers for fraud and cyberattacks – along with millions more whose records were also contained in the database.
Data Breach Impact
Studies have shown that free gambling and gaming apps are especially prone to attacks and hacking from cybercriminals. They are routinely targeted for theft of private data and embedding malicious software on users’ devices.
Despite their popularity, gambling and casino apps often lack transparency, and it can be impossible to know what steps they’re taking to prevent cybercriminals successfully targeting their users.
One study of 23,000 free gambling apps found that: 3,200 posed a ‘moderate risk’ to users; 379 had known security vulnerabilities; 52 contained malicious software.
Any of these issues could be exploited to target app users in a wide range of frauds and cyberattacks, and Clubillion is no different.
With the exposed user PII and knowledge of their activity on the app, hackers could create elaborate schemes to defraud users. For example, some entries also included transaction errors for attempted card payments on Clubillion.
With the information in these transaction errors, hackers could target users with phishing campaigns, with the following aims:
- Trick them into providing their credit card details
- Trick them into providing additional PII to be used against them in further fraud
- Clicking a link that embeds malware, spyware, or ransomware onto their device.
If cybercriminals used Clubillion to embed malware or similar onto a user’s phone, they could potentially hack other apps, access files stored on the device, make calls, and send texts from the hacked device. They could even access a user’s phone contacts and steal the PII data of their friends and family.
Worse still, as people across the globe now find themselves under quarantine or self-isolation, as a result of the Coronavirus pandemic, the impact of a leak like this is potentially even more significant.
Clubillion stands to gain many new users, along with regular users playing more frequently. Hackers will be aware of this and looking for opportunities to exploit any vulnerabilities in the data security of such a massively popular app.
Had criminal hackers discovered Clubillion’s database, they could have targeted millions of people around the world, with devastating results.
Impact on Clubillion and it’s Developers
The most immediate risk for Clubillion is the loss of players. Data security is a growing concern for everyone these days, and this leak could turn many players off the app. Clubillion is not unique, and players have plenty of other choices for free gambling apps.
With fewer players, Clubillion will lose advertising revenue and reduced profits.
As many of Clubillion’s players reside within the EU, the app is under the jurisdiction of GDPR. The rules of GDPR also apply to apps, and Clubillion will need to take specific actions to ensure the regulatory body in charge doesn’t reprimand it.
Finally, Clubillion could also potentially be removed from Google Play and the App Store. Both Apple and Google are clamping down on apps that pose a risk to their users, removing apps embedded with malware, and taking data leaks much more seriously.
Each of these outcomes has a different likelihood of happening, but they would all negatively impact Clubillion’s revenue and business.
Advice from the Experts
Clubillion’s developers could have easily avoided this leak if they had taken some basic security measures to protect the database. These include, but are not limited to:
- Securing their servers.
- Implementing proper access rules.
- Never leaving a system that doesn’t require authentication open to the internet.
Any company can replicate the same steps, no matter its size.
For a more in-depth guide on how to protect your business, check out our guide to securing your website and online database from hackers.
For Clubillion Users
If you play on Clubillion and are concerned about how this breach might impact you, contact the app’s developers directly to find out what steps it’s taking to protect your data.
To learn about data vulnerabilities in general, read our complete guide to online privacy.
It shows you the many ways cybercriminals target internet users, and the steps you can take to stay safe.
How and Why We Discovered the Breach
The vpnMentor research team discovered the breach in Clubillion’s database as part of a huge web mapping project. Our researchers use port scanning to examine particular IP blocks and test different systems for weaknesses or vulnerabilities. They examine each weakness for any data being leaked.
Our team was able to access this database because it was completely unsecured and unencrypted.
Whenever we find a data breach, we use expert techniques to verify the owner of the database, usually a commercial company.
As ethical hackers, we’re obliged to inform a company when we discover flaws in their online security. We reached out to Clubillion’s developers, not only to let them know about the vulnerability but also to suggest ways in which they could make their system secure.
These ethics also mean we carry a responsibility to the public. Clubillion users must be aware of a data breach that exposes so much of their sensitive data.
The purpose of this web mapping project is to help make the internet safer for all users.
Powered by WPeMatico
Latest News
The Free Bet Wheel: Betting.bet Increases Player Engagement with New Gamification Tool

One of the UK’s leading betting aggregators, betting.bet, has introduced the Free Bet Wheel, a new free-to-play tool designed to increase user retention and interaction. Tied to the weekend’s Premier League football, this gamified feature offers users the opportunity to earn free bets and a weekly £100 cash reward.
At a time when most iGaming affiliates are focused on developing foreign markets such as Latin America and Africa, the function illustrates betting.bet’s ongoing commitment to the UK.
About the Free Bet Wheel
-
Weekend Availability: The Free Bet Wheel runs every weekend, aligned with major Premier League and international football matches.
-
Multiple Chances to Win: Players receive up to four spins to try their luck each weekend.
-
Winning Free Bets: Match three free bet colours within five spins to win a free bet on the featured match.
-
£100 Cash Jackpot: Land on the jackpot segment five times consecutively to win £100 in cash.
-
Loyalty Rewards: Players also collect bCoins, Betting.bet’s exclusive loyalty currency, which can be redeemed for a range of prizes, vouchers and rewards.
Strengthening Operator Partnerships Through Enhanced User Experience
By launching the Free Bet Wheel, betting.bet is not only elevating the player experience but also delivering tangible benefits to its network of partner operators. The feature offers a new avenue to profile selected betting partners, direct qualified traffic to safe free bets and reinforce affiliate partnerships through increased user activity and conversions.
Steve Gummer, Director of Betting.bet, stated: “We at betting.bet are dedicated to developing products and experiences that not only interest players but also provide clear value to our partners. Designed to benefit our UK community in a fun, frictionless manner, the Free Bet Wheel also supports important weekend traffic and sportsbook conversions.”
Driving Retention Through Gamification
This launch is part of a broader strategic focus on gamification and loyalty at betting.bet, aligning user enjoyment with commercial objectives. As the UK version of the platform continues to grow, features like the Free Bet Wheel are designed to support player acquisition, maximise LTV and drive weekend re-engagement.
The Free Bet Wheel is now live at betting.bet and available to all UK users aged 18+,
The post The Free Bet Wheel: Betting.bet Increases Player Engagement with New Gamification Tool appeared first on European Gaming Industry News.
Latest News
GR8 Tech Powers Smarter Betting with New Match Trackers

GR8 Tech has unveiled a powerful new upgrade to its high-performance sportsbook platform: high-quality, real-time Match Trackers—designed to bring more action, insight, and excitement to players. Match Trackers are available across all of GR8 Tech’s sportsbook solutions, including iFrame and the Hyper Turnkey.
“We’re always looking for ways to elevate the player experience and give our partners a competitive edge,” said Denys Parkhomenko, CPO at GR8 Tech. “Match Trackers have smart features that drive engagement, boost retention, and power faster betting decisions in real-time.”
With broad coverage across football, basketball, tennis, hockey, volleyball, and handball, the trackers are live for pre-match analytics and in-game updates. Key features include:
- Detailed Stats: From xG in football to rebounds in basketball and aces in tennis, players get live and historical stats tailored to each sport.
- Key Moments & Summaries: Goals, assists, red cards, substitutions, and more delivered in real-time.
- Pitch Animation: A dynamic, visual alternative to video streaming, showing key moments as they unfold on the field.
- Lineups & Live Updates: Full team sheets, coaches, and live substitutions, so players are always in the know.
- Live Standings: Updated rankings and tournament tables across all supported sports.
By providing operators with the tools to deliver everything players need in one place, GR8 Tech enhances the sportsbook user experience, enabling more confident betting and driving longer player sessions.
The launch of Match Trackers marks another step in the company’s long-term strategy to deliver a best-in-class, sportsbook-driven platform and become the leading sportsbook provider by 2028. Coverage will soon expand to even more sports to meet operators’ needs.
The post GR8 Tech Powers Smarter Betting with New Match Trackers appeared first on European Gaming Industry News.
Latest News
Midnite creates free limited-edition beer for fans to enjoy at World Snooker Championship

Midnite is the new official UK betting and casino partner of the World Championship, Snooker’s greatest event, which will run from April 19 to May 5.
To celebrate the partnership, Midnite has created a FREE limited edition lager – with one free beer available per person – which will be served at a local pub throughout the tournament.
The one-off lager will be served at The Graduate, an iconic Sheffield pub a short walk from The Crucible, with fans able to enjoy a new beer on tap while the World Championship comes to the city.
Midnite has partnered with London-based brewery Drop Project to bring the concept to life. Drop Project creates the freshest, premium flavoursome beers with consistent high-quality results, and pushes creative boundaries and brews the beers that both inspire their passions for the industry and our lifestyles.
A Midnite spokesperson, commented: “We have worked with Drop Project to bring fans a Midnite lager that they can enjoy throughout the whole tournament. We wanted to create something tangible that snooker fans can enjoy throughout, and to have been able to create our own beer is something we’re pleased with.
“The World Snooker Championship brings real excitement to the city, and fans can head straight from The Crucible, to The Graduate and enjoy a pint or two of our specially brewed lager, just for the occasion.”
Midnite is providing the beer free of charge – one free drink per person of Midnite Lager Only and for ticket holders to the Snooker World Championship (18+). Redeem by showing your matchday ticket at The Graduate. While stock lasts.
The post Midnite creates free limited-edition beer for fans to enjoy at World Snooker Championship appeared first on European Gaming Industry News.
-
Africa7 days ago
INCENTIVE GAMES SIGNS EXCLUSIVE DISTRIBUTION DEAL FOR NORTH AMERICA, EUROPE, SOUTH AFRICA AND UK WITH LIGHT & WONDER
-
Asia6 days ago
DigiPlus Bags 7 Wins at the 2025 Asia-Pacific Stevie Awards
-
Australia6 days ago
Martin Pakula Named Chair of Crown Melbourne
-
Better Collective7 days ago
Network Gaming partners with Better Collective to launch pioneering gaming ecosystem
-
Latest News6 days ago
SCCG Becomes Sponsor of SFT Combat
-
Compliance Updates7 days ago
Navigating Legal Frontiers: Nordic Legal’s Vision for the Finnish Gambling Market
-
Asia7 days ago
Grand Korea Leisure Partners with Robotis
-
Canada7 days ago
Soft2Bet’s ToonieBet Partners with the Ottawa Senators as Official Online Casino Partner