Vegas casinos are still reeling from a cyberattack
fastcompany.com
fastcompany.com
https://www.cringely.com/2013/07/30/the-origins-of-defcon/
The events in that article took place in 1993. Read the whole article, but here's the best bit.
Hotel security had mistakenly kicked out attendees at that conference, so they decided to get revenge by hacking their system. The is from Cringely:
***
The meeting reconvened at 9 or 10 with the topic suddenly changed to Revenge on the Sands. Gail Thackeray, then a U. S. Attorney from Arizona who at that moment had approximately half the room under indictment, rose to offer her services representing the kids against the hotel management.
Thackeray had been invited to speak by the very people she wanted to put in jail. I told you this was surreal.
Adult assistance might be nice, but a potentially more satisfying alternative was offered by a group that had breached the hotel phone system, gained access to the computer network, obtained root level access to the VAX minicomputer that ran the Sands casino, and were ready at any moment to shut the sucker down. It came to a vote: accept Thackeray’s offer of assistance or shut down the casino.
There was no real contest: they voted to nuke the casino. Not one to be a party pooper, I voted with the majority.
Gail Thackeray, feeling her lawyer’s oats, was perfectly willing to be a party pooper, though. She explained with remarkable patience that opting en masse to commit a felony was a move that we might just want to reconsider, especially given the three strikes implications for some of the older participants.
We could accept her help or accept a date with the FBI that afternoon. The Sands (now the Venetian), which was ironically owned by the same folks who used to run Comdex, never knew how close it came to being dark.
It was a thrilling moment like you’d never see today. Everyone who was in that room shares a pirates’ bond. And though I can’t defend what we almost did, I don’t regret it.
And like the others, I wish Gail Thackeray had stayed in Arizona and we’d shut the sucker down.
Caesars was hacked a month ago.
>>Caesars told the SEC it had “determined that the unauthorized actor acquired a copy of, among other data, our loyalty program database, which includes driver’s license numbers and/or social security numbers.
A lot of what was happening back then compared to today is just such a stark difference. The kind of attack vectors I was chasing myself are now so obsolete that most of these gangs will just give you that info for free… I mean holy shit… you can just load up Tor and go download terabytes of information in any industry imaginable. Free of charge. No need to spend endless weeks or months planning out the perfect attack (although that process is rewarding in its own way) …
This year has been huge for ransomware attacks, how long until one of the major FAANG companies get toppled over?
But by the looks of it a lot of these groups are after specific targets, for example - chipmakers. No way they want their secrets out in the public so they’ll happily pay up, especially if they are from places outside of the US.
I sometimes see on my Twitter feed, alerts of big Bitcoin transactions that are never disclosed publicly but are associated with well known laundering networks.
How do you find any of it?
https://ransomwatch.telemetry.ltd/#/recentposts
I trust you will be able to figure out the rest.
(attributed to bank robber Willie Sutton)
A previous company I worked for took the “high road”. Mostly cause the CIO was a delusional psychopath. She refused to pay the mere 1 mil ransom. Told the CEO the disaster recovery systems would bring the company back online in a few hours (everybody, except her apparently, knew the DR system was a total joke). Hackers wiped the encrypted drives of every machine in the company and said good day.
4 weeks later they had the website, basic email and server operations functioning again. 3 months later they had restored business continuity more or less.
She was fired a week after that.
I’m guessing it cost the company 10’s if not over 100 million.
Still might be better for them being a "quiet" incident as opposed to disrupting operations like mgm.
[1] https://igamingbusiness.com/casino/more-bullishness-for-las-...
[2]https://www.forbes.com/sites/willyakowicz/2023/02/01/nevada-...
Even setting aside the high roller slots, the regular machines will allow $25/spin now and 5 seconds a spin means it’s easy to cruise through $1k in 5 minutes.
I’ve sat and watched one person so that (not in the high roller slots) and they left down about $4000 after a 20 minute sit. They didn’t even seem phased in the slightest and only left due to what seemed like the need to meet someone rather than running out of cash.
I’m talking about gambling amount. You’re intuition is way off here. Most Americans will not gamble that much.
I.e even if we take the top of your guess (<$1000), it is still much less than other expenses (lodging, dining, entertainment, etc).
https://www.theverge.com/2021/5/10/22428996/colonial-pipelin...
"easy come, easy go"
The idea that they're paying because a hit squad is about to drop in, murder them all and get the money back is pure fantasy. If modern casinos figure out who did this they'll forward it to law enforcement. In all likelihood they have no idea, though.
If there's any evidence that these casinos still commit murder like that I'm all ears.