Analyst: Casinos are no more vulnerable to cyberattacks than any big business

January 3, 2024
By
Leer en Español

The Chief Security Evangelist for ESET, a cybersecurity software company, says recent ransomware attacks of MGM and Caesars may have received a lot of media attention – but that all big organizations are at risk.

In an exclusive interview with Gaming America, Tony Anscombe told us he doesn't think Las Vegas was going through anything unusual with the September cyberattacks disclosed by Sin City’s two largest casino operators.

MGM disclosed in an October US Securities and Exchange Commission filing that it lost around $100m as a result of a criminal cybersecurity attack, which started around September 11 and resulted in the theft of some customers’ Social Security numbers.

Caesars was hit around the same time by the same “threat groups,” who also stole some customers’ driver license information and Social Security numbers.

The hacks received heavy media attention, but Anscombe believes there’s nothing special about Las Vegas casinos or casinos in general that make them more vulnerable to such crimes. Rather, he said, every major business faces such a risk these days.

Vegas casinos just happen to be more visible, so their attacks garner more attention, he said.

Anscombe did acknowledge that Sin City casino databases might contain information that hackers find more appealing because that information concerns individuals’ behavior in Las Vegas, which is where people tend to cut loose outside of their norms.

“That does make Vegas data a specific target,” Anscombe conceded.

But he also added that corporations as sophisticated as MGM and Caesars are going to have better security – that is, better technology and software – than, say, the school district in Las Vegas, which also was the victim of a significant hack in October 2023.

Indeed, Anscombe said both MGM and Caesars became victims of cybersecurity attacks not because they had some fault in their technology, but because the hackers were able to manipulate real people working for the companies to give out critical information that gave the hackers access to their systems.

This is known as a “social engineering attack,” and Anscombe said the way to prevent them is for corporations like MGM and Caesars to drill into their employees’ heads to be cautious about giving out critical pieces of information.

Anscombe said companies often require their employees to attend cybersecurity training once a year. He said he thought companies should do that more often to really drive home the point.

“Companies need to continually evolve their cybersecurity,” he said.

MGM reportedly refused to pay the hackers’ ransom demands. Caesars reportedly paid.

Anscombe said giving into ransom demands encourages more attacks – but he said one of the biggest drivers of this behavior is insurance companies that offer cyber risk insurance. These policies, he said, will pay hackers’ ransoms, which Anscombe doesn’t agree with.

But also acknowledged that insurance companies only issue these policies once companies have beefed up their cybersecurity technology. So, he conceded that while these policies can encourage the wrong behavior, they’re also encouraging the right behavior as well.

All of this, however, is not unique to the world of gaming. Businesses everywhere, he said need to invest in “continual education of employees at all levels,” Anscombe said.

Anscombe also spoke to Gambling Insider in November, declaring that there is "honesty among thieves."

State-by-State

Product Spotlight

CasinoTrac

CasinoTrac is reducing handpay downtime by nearly 90% with SlotSUITE's Self-Pay & W-2 G printing at the slot machine.
GA HUDDLE #087

John Connelly - Interblock preparing to launch online by the end of year

John Connelly, the Global CEO of Interblock, joins the Huddle to talk about:
- The company's conversion to the online space
- The performance of ETGs
- Interblock's new philanthropic efforts
- The trend of companies going private
- And more!
GA HUDDLE #086

Michael Hershman - Dispelling casino 'myths:' New York needs to lose fear of the unknown

Michael Hershman, CEO of the Soloviev Group, joins Tim Poole on the Huddle to put forward his case that the Freedom Plaza is the way to go for one of New York's casino licences. He fields a variety of questions - not shying away from any of them - on why 'myths' about casinos and a fear of the unknown should be dispelled, as well as acknowledging the strength of rival bids and discussing opposition to the project.

As the Tribal gaming sector congregates once more in the Golden State, is it too cliché of me to suggest we are heading for a golden era of Tribal gaming? With the industry set to meet at the Indian Gaming Association t...

10-11-From-the-top
From The Top: Will youth be served by Sports Betting?
Two recent interviews in our Huddle podcast revealed to Las Vegas correspondent Brian Joseph just how young sports betting entrepreneurs are becoming.
12-GA-MAR-10-year-v2
The Global Gaming Awards: Rewarding Excellence
The 10th edition of the Global Gaming Awards took place in Las Vegas last year. Gaming America looks back... and ahead to this year's.
16-18-IGA-Preview
Preview: Indian Gaming Tradeshow & Convention
Gaming America looks ahead to the 2024 Indian Gaming Tradeshow & Convention and what attendees can expect when they arrive at the Anaheim Convention Centre.
20-22-GA-Mar-888-Holding-article
888 and the US Market: A cautionary tale
Gaming America explores the risk of resting on your laurels and the challenge of remaining relevant in a rapidly expanding market.