NATIONAL NEWS

Two Vegas casinos fell victim to cyberattacks, shattering the image of impenetrable casino security

Sep 15, 2023, 5:44 PM

An error message is displayed on a machine at MGM Grand in Las Vegas, Tuesday, Sept. 12, 2023. MGM ...

An error message is displayed on a machine at MGM Grand in Las Vegas, Tuesday, Sept. 12, 2023. MGM Resorts said a cybersecurity attack began Sunday, affecting reservations and casino floors in Las Vegas and other states. (K.M. Cannon/Las Vegas Review-Journal via AP)
Credit: ASSOCIATED PRESS

(K.M. Cannon/Las Vegas Review-Journal via AP)

LAS VEGAS (AP) — A persistent error message greeted Dulce Martinez on Monday as she tried to access her casino rewards account to book accommodations for an upcoming business trip.

That’s odd, she thought, then toggled over to Facebook to search for clues about the issue on a group for MGM Resorts International loyalty members. There, she learned that the largest casino owner in Las Vegas had fallen victim to a cybersecurity breach.

Martinez, 45, immediately checked her bank statements for the credit card linked to her loyalty account. Now she was being greeted by four new transactions she did not recognize — charges that she said increased with each transaction, from $9.99 to $46. She canceled the credit card.

Unsettled by the thought of what other information the hackers may have stolen, Martinez, a publicist from Los Angeles, said she signed up for a credit report monitoring program, which will cost her $20 monthly.

“It’s been kind of an issue for me,” she said, “but I’m now monitoring my credit, and now I’m taking these extra steps.”

MGM Resorts said the incident began Sunday, affecting reservations and casino floors in Las Vegas and other states. Videos on social media showed video slot machines that had gone dark. Some customers said their hotel room cards weren’t working. Others said they were canceling their trips this weekend.

The situation entered its sixth day on Friday, with booking capabilities still down and MGM Resorts offering penalty-free room cancelations through Sept. 17. Brian Ahern, a company spokesperson, declined Friday to answer questions from The Associated Press, including what information had been compromised in the breach.

By Thursday, Caesars Entertainment — the largest casino owner in the world — confirmed it, too, had been hit by a cybersecurity attack. The casino giant said its casino and hotel computer operations weren’t disrupted but couldn’t say with certainty that personal information about tens of millions of its customers was secure following the data breach.

The security attacks that triggered an FBI probe shatter a public perception that casino security requires an “Oceans 11”-level effort to defeat it.

“When people think about security, they are thinking about the really big super-computers, firewalls, a lot of security systems,” said Yoohwan Kim, a computer science professor at the University of Nevada, Las Vegas, whose expertise includes network security.

It’s true, Kim said, that casino giants like MGM Resorts and Caesars are protected by sophisticated — and expensive — security operations. But no system is perfect.

“Hackers are always fighting for that 0.0001% weakness,” Kim said. “Usually, that weakness is human-related, like phishing.”

Tony Anscombe, the chief security official with the San Diego-based cybersecurity company ESET, said it appears the invasions may have been carried out as a “socially engineered attack,” meaning the hackers used tactics like a phone call, text messages or phishing emails to breach the system.

“Security is only as good as the weakest link, and unfortunately, as in many cyberattacks, human behavior is the method used by cybercriminals to gain the access to a company’s crown jewels,” Anscombe said.

As the security break-ins left some Las Vegas casino floors deserted this week, a hacker group emerged online, claiming responsibility for the attack on Caesars Entertainment’s systems and saying it had asked the company to pay a $30 million ransom fee.

It has not officially been determined whether either of the affected companies paid a ransom to regain control of their data. But if one had done so, the experts said, then more attacks could be on the way.

“If it happened to MGM, the same thing could happen to other properties, too,” said Kim, the UNLV professor. “Definitely more attacks will come. That’s why they have to prepare.”

___

Parry reported from Atlantic City. Associated Press videographer Ty O’Neil in Las Vegas contributed.

National News

Phoenix heat...

Associated Press

Arizona’s sweltering summer could set new record for most heat-associated deaths in big metro

PHOENIX (AP) — America’s hottest metro area is on track to set an annual record for heat-associated deaths after a sweltering summer, particularly in Phoenix. Public health officials in Maricopa County, home to Phoenix and Arizona’s most populous county, said Friday that 289 heat-associated deaths were confirmed as of Sept. 16, with another 262 deaths […]

2 hours ago

FILE - President Joe Biden addresses the 78th session of the United Nations General Assembly at Uni...

Associated Press

Biden faces foreign policy trouble spots as he aims to highlight his experience on the global stage

WASHINGTON (AP) — This probably wasn’t how President Joe Biden envisioned his big foreign policy week ending. Biden spent much of the time trying to make the case to world leaders at the U.N. General Assembly as well as to Democratic donors and voters that his decades of foreign policy experience and demonstrated moral clarity […]

3 hours ago

Danielle Wilkes is seen by a dentist during a clinic visit Thursday, Sept. 7, 2023, in Nashville, T...

Associated Press

Many states are expanding their Medicaid programs to provide dental care to their poorest residents

NASHVILLE, Tenn. (AP) — For months, Carlton Clemons endured crippling pain from a rotting wisdom tooth. He couldn’t sleep, barely ate and relied on painkillers to get by. The 67-year-old from Nashville, Tennessee, could not afford to see a dentist on the $1,300-a-month his family gets in Social Security and disability payments. So he waited […]

5 hours ago

Associated Press

Florida siblings, ages 10 and 11, stopped while driving mom’s car on freeway 200 miles from home

GAINESVILLE, Fla. (AP) — A 10-year-old Florida boy and his 11-year-old sister who were running away to California drove 200 miles (320 kilometers) in their mother’s car before they were stopped by sheriff’s deputies on an interstate highway, authorities said. The Alachua County Sheriff’s Office says deputies spotted the sedan on Interstate 75 near Gainesville […]

6 hours ago

Associated Press

New Jersey house explosion hospitalizes 5 people, police say

WEST MILFORD, N.J. (AP) — Five people were transported to hospitals after an explosion at a New Jersey home on Friday night, police said. The house in West Milford was heavily damaged by the explosion around 9 p.m., the West Milford Police Department said in a statement. A sixth person at the scene refused additional […]

9 hours ago

Associated Press

Tropical Storm Ophelia moves inland over North Carolina as coastal areas lashed with wind, rain

ANNAPOLIS, Md. (AP) — Residents in coastal North Carolina and Virginia braced for potential flooding after Tropical Storm Ophelia made landfall near a North Carolina barrier island on Saturday morning, bringing rain, damaging winds and dangerous surges of water. The storm came ashore near Emerald Isle with near-hurricane-strength winds of 70 mph (113 kph) at […]

12 hours ago

Sponsored Articles

Swedish Cyberknife...

September is Prostate Cancer Awareness Month

September is a busy month on the sports calendar and also holds a very special designation: Prostate Cancer Awareness Month.

Ziply Fiber...

Dan Miller

The truth about Gigs, Gs and other internet marketing jargon

If you’re confused by internet technologies and marketing jargon, you’re not alone. Here's how you can make an informed decision.

Education families...

Education that meets the needs of students, families

Washington Virtual Academies (WAVA) is a program of Omak School District that is a full-time online public school for students in grades K-12.

Emergency preparedness...

Emergency planning for the worst-case scenario

What would you do if you woke up in the middle of the night and heard an intruder in your kitchen? West Coast Armory North can help.

Innovative Education...

The Power of an Innovative Education

Parents and students in Washington state have the power to reimagine the K-12 educational experience through Insight School of Washington.

Medicare fraud...

If you’re on Medicare, you can help stop fraud!

Fraud costs Medicare an estimated $60 billion each year and ultimately raises the cost of health care for everyone.

Two Vegas casinos fell victim to cyberattacks, shattering the image of impenetrable casino security