Categories: Data Breach

Online Gaming Platform VIP Games Exposes 23 Million Data Records On Misconfigured Server

Online Gaming Platform VIP Games Exposes 23 Million Data Records On Misconfigured Server

More than 23 million records were left exposed on a misconfigured server by free gaming platform VIPGames.com.

Researchers from WizCase found the personal data of 66,000 users – equating to 23 million datasets – exposed on an Elasticsearch server, a blog post reads.

“Our cybersecurity team found that confidential data on VIPGames.com was accessible to the public and could be viewed by anyone with the URL of the ElasticSearch server, left open without any password protection or encryption,” researcher Chase Williams wrote.

Compromised information includes usernames, email addresses, device details, IP addresses, hashed passwords, and more.

Also Read: 10 Principles On How To Build A Good Governance Model

Game over

VIP Games, owned by software development company Casualino JSC, offers free online versions of classic board and card games such as Ludo, Rummy, and Dominoes.

According to WizCase, it attracts more than 20,000 daily active players on its desktop site, while its mobile app has more than 100,000 downloads from the Google Play Store alone.

Researchers found more than 30GB of sensitive data records, some of which included details on in-game transactions.

WizCase warned that the implications of the breach could be costly for victims if the exposed data is viewed by nefarious actors.

“If such data had fallen into the hands of cybercriminals, it could have been exploited for identity theft, fraud, phishing, scamming, espionage and malware infestation,” wrote the researchers in a blog post.

Also Read: IT Governance Framework PDF Best Practices And Guidelines

The Daily Swig has reached out to VIP Games.com for comment.

Privacy Ninja

Recent Posts

Role of Enhanced Access Controls in Safeguarding Personal Data in Telecommunications

Role of Enhanced Access Controls in Safeguarding Personal Data in Telecommunications that every Organisation in…

4 days ago

Role of Effective Incident Response Procedures in Strengthening Data Security

Effective Incident Response Procedures in Strengthening Data Security that every Organisation in Singapore should know…

5 days ago

Strengthening Your Cyber Defenses: The Crucial Role of Regular Vulnerability Scanning

Crucial Role of Regular Vulnerability Scanning that every Organisation in Singapore should know. Strengthening Your…

6 days ago

Enhancing Data Security with Multi-Factor Authentication

Enhancing Data Security with Multi-Factor Authentication that every Organisation in Singapore should know. Enhancing Data…

2 weeks ago

A Strong Password Policy: Your Organization’s First Line of Defense Against Data Breaches

Strong Password Policy as a first line of defense against data breaches for Organisations in…

2 weeks ago

Enhancing Website Security: The Importance of Efficient Access Controls

Importance of Efficient Access Controls that every Organisation in Singapore should take note of. Enhancing…

3 weeks ago