Published on September 19, 2023
The casino industry is no stranger to attacks, but this time, two online casinos in the U.S. have detected two cyberattacks. The two casinos, Caesars Entertainment and MGM Resorts, were hit by the attacks by a cybercrime group. This opens a discussion of the security of the casinos and whether this could also happen to other online casinos.
The first casino giant, MGM Resorts, witnessed the cyberattack at several hotels in Las Vegas on a Sunday morning. Slot machines and door locks weren’t working, and some guests weren’t able to make reservations or use elevators. The cyberattack also affected digital room keys, as guests were restricted from playing and checking into their rooms. MGM Resorts tried to mitigate the situation, even though the circumstances were chaotic for several hotel guests. Since then, the FBI has investigated the cyberattack, and the Nevada government is in contact with the casino.
Thankfully, the cyberattack didn’t target any casino sites and focused on the land-based operator. However, shortly after the first attack, Caesars were also hit by cyberattacks. This time, the hackers stole social security numbers from several customers. The cybercrime group by the name of UNC3944 demanded a ransom of $30 million, where Caesars negotiated to pay half the amount of the ransom. While both casinos are working to resolve the cybersecurity issue, there is no denying that it has affected the experience of many guests.
It is not the first time cyberattacks have hit land-based casinos. In fact, it has happened to the same hotels before. Some hacker groups have tried to hack the hotels by using fraudulent phone calls to employees to try and get login credentials. Since casinos are known to possess and transfer large amounts of money, they are regarded by hackers as a honey pot or a valuable target that malicious actors hope to exploit.
Therefore, casinos can sometimes seem like a clear target for these hackers. However, there is a difference between physical and online casinos. For example, some of the best online blackjack sites might not experience the same cyberattacks because of high data security. These websites have SSL encryption, which ensures a safe gaming environment for gamblers.
After the cyberattack on the casinos, authorities have tried to find out who is behind the attacks. A research group posted to X, formerly known as Twitter, that a ransomware group called ‘Black Cat’ is allegedly responsible for the cyberattack. According to the research group, the hackers found an employee on LinkedIn and called the Help Desk of MGM Resorts. Because of this, the casino is trying to ensure it won’t happen again.
Caesars Entertainment Inc. has ensured the hackers have deleted the stolen data. However, this isn’t 100 percent sure. Furthermore, they have not determined to what extent they would let their cybersecurity insurance offset the costs and impacts of the incident.
Because of cyber attacks, online casinos could seem even more vulnerable since all activity takes place online. However, the legal and licensed casinos take measures to ensure a safe gambling experience for players. One way is SSL encryption, where the casino servers protect the players’ sensitive information. Secondly, online casinos regularly update their software since hackers can exploit data vulnerabilities, which older software versions could reveal. Lastly, casino staff should always be trained to detect and defeat these phishing attacks by recognizing hacking attempts.
The cyberattacks on two large U.S. casinos show the importance of choosing an online casino that takes data security seriously. Choosing a casino with a license is the first step. But also making sure they use secure technology is crucial to not potentially lose any critical and sensitive data such as card information.