Feeds

DON'T PANIC! No credit card details lost after hackers crack world's largest casino group

Las Vegas Sands email and website still down after hackers trash CEO Sheldon Adelson

Build a business case: developing custom apps

IT administrators at the Las Vegas Sands casino are having a tough time restoring their systems after hackers successfully got inside the corporation's firewall, but it appears that the most valuable sections of the network are safe, according to the Nevada Gaming Control Board.

Board chairman A.G. Burnett told Associated Press that the credit card database of customers at the world's largest gambling chain is secure, and that the integrity of the gambling systems run by the chain hasn't been breached, so no Ocean's 11–style antics are expected.

The problems for the casino started on Monday when the attackers took control of the company's website and posted an image of the consortium's US casinos in flames, along with a picture of CEO Sheldon Adelson with Israeli Prime Minister Benjamin Netanyahu and the message "Damn A, don't let your tongue cut your throat. Encouraging the use of weapons of mass destruction, under any conditions, is a crime."

Hackers deface the Las Vegas Sands website

Hardly a well-designed website

More worryingly, the hackers also added a scrolling list of employees, their email addresses, some social security numbers, and other identifying information. The Sands website is still down and a spokesperson confirmed to El Reg that the email systems still haven't been switched back on.

"While we have been able to confirm that certain core operating systems were not impacted by the hacking, the company remains focused on working through a step-by-step process to ascertain what, if any, additional systems may have been impacted," Sands spokesman Ron Reese said in a reported statement.

At first sight this looks like a politically motivated attack against Sheldon Adelson, the billionaire CEO of the Sands group. Adelson's biography reads like a Horatio Alger myth: the son of poor Ukrainian immigrants who became the ninth richest man in the world, and he's known in the technology industry as the founder of the COMDEX trade show, which he sold in 1995 for $862m.

Adelson also donates millions to American political campaigns – almost exclusively to the Republican Party and its candidates – and is somewhat outspoken on foreign policy issues in the Middle East. The hacker's message presumably refers to a comment he made suggesting the US should explode a nuclear weapon over uninhabited Iran's land as a precursor to negotiations over its nuclear program – a comment he later dismissed as hyperbole.

Defacing a website isn't too hard, and usually has minimal effect on the owners, but the fact that internal systems were broken into to is cause for concern. Seemingly innocuous hacking or DDoS attacks have been used in the past to mask deeper penetrations in the past, and computer forensics teams will be scouring through server logs to find out exactly what happened.

Nevada gaming officials are investigating the attack at the moment, and the FBI is also reported to be looking into the case. Neither was available for comment at time of going to press. ®

Endpoint data privacy in the cloud is easier than you think

More from The Register

next story
14 antivirus apps found to have security problems
Vendors just don't care, says researcher, after finding basic boo-boos in security software
'Things' on the Internet-of-things have 25 vulnerabilities apiece
Leaking sprinklers, overheated thermostats and picked locks all online
iWallet: No BONKING PLEASE, we're Apple
BLE-ding iPhones, not NFC bonkers, will drive trend - marketeers
Multipath TCP speeds up the internet so much that security breaks
Black Hat research says proposed protocol will bork network probes, flummox firewalls
Only '3% of web servers in top corps' fully fixed after Heartbleed snafu
Just slapping a patched OpenSSL on a machine ain't going to cut it, we're told
Microsoft's Euro cloud darkens: US FEDS can dig into foreign servers
They're not emails, they're business records, says court
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Israel's Iron Dome missile tech stolen by Chinese hackers
Corporate raiders Comment Crew fingered for attacks
prev story

Whitepapers

7 Elements of Radically Simple OS Migration
Avoid the typical headaches of OS migration during your next project by learning about 7 elements of radically simple OS migration.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Solving today's distributed Big Data backup challenges
Enable IT efficiency and allow a firm to access and reuse corporate information for competitive advantage, ultimately changing business outcomes.
A new approach to endpoint data protection
What is the best way to ensure comprehensive visibility, management, and control of information on both company-owned and employee-owned devices?