We are very aware of this user and are taking some active steps. We won't go into details as that only entices more attacks but we are working on a more solid response. For now, we have had to take some resources from the new multi-player to address this.
As a small background, Risk was a single-player and pass-and-play only game. We built the logic on the phones. We then noticed there was an interest in Multiplayer so we opened it up to see how popular it was – but the logic was still on the phone - and thus easily hackable. We always knew this, there is no point attempting to prove it to us. But without it, we probably never would have tested the waters for popularity of the MP game at all.
Unfortunately, this did bring in those hacking users and we had to react as quickly as possible: our long term solution is to move to a “server-authoritative” solution but in the meantime we can only do post-game validation. We have smarts that try to catch users (also made tricky by the way the game was originally written as a single-player game) but this again is after-the-fact. The only other fast (legal) solutions are to enforce authorised accounts where you need to register with emails etc – but this is not what we are about and determined that the actions of the few will not impact others.
Stay tuned – we’re working on it – but in the meantime do keep reporting these users and we’ll act as quickly as we can.