Feeds

DON'T PANIC! No credit card details lost after hackers crack world's largest casino group

Las Vegas Sands email and website still down after hackers trash CEO Sheldon Adelson

Internet Security Threat Report 2014

IT administrators at the Las Vegas Sands casino are having a tough time restoring their systems after hackers successfully got inside the corporation's firewall, but it appears that the most valuable sections of the network are safe, according to the Nevada Gaming Control Board.

Board chairman A.G. Burnett told Associated Press that the credit card database of customers at the world's largest gambling chain is secure, and that the integrity of the gambling systems run by the chain hasn't been breached, so no Ocean's 11–style antics are expected.

The problems for the casino started on Monday when the attackers took control of the company's website and posted an image of the consortium's US casinos in flames, along with a picture of CEO Sheldon Adelson with Israeli Prime Minister Benjamin Netanyahu and the message "Damn A, don't let your tongue cut your throat. Encouraging the use of weapons of mass destruction, under any conditions, is a crime."

Hackers deface the Las Vegas Sands website

Hardly a well-designed website

More worryingly, the hackers also added a scrolling list of employees, their email addresses, some social security numbers, and other identifying information. The Sands website is still down and a spokesperson confirmed to El Reg that the email systems still haven't been switched back on.

"While we have been able to confirm that certain core operating systems were not impacted by the hacking, the company remains focused on working through a step-by-step process to ascertain what, if any, additional systems may have been impacted," Sands spokesman Ron Reese said in a reported statement.

At first sight this looks like a politically motivated attack against Sheldon Adelson, the billionaire CEO of the Sands group. Adelson's biography reads like a Horatio Alger myth: the son of poor Ukrainian immigrants who became the ninth richest man in the world, and he's known in the technology industry as the founder of the COMDEX trade show, which he sold in 1995 for $862m.

Adelson also donates millions to American political campaigns – almost exclusively to the Republican Party and its candidates – and is somewhat outspoken on foreign policy issues in the Middle East. The hacker's message presumably refers to a comment he made suggesting the US should explode a nuclear weapon over uninhabited Iran's land as a precursor to negotiations over its nuclear program – a comment he later dismissed as hyperbole.

Defacing a website isn't too hard, and usually has minimal effect on the owners, but the fact that internal systems were broken into to is cause for concern. Seemingly innocuous hacking or DDoS attacks have been used in the past to mask deeper penetrations in the past, and computer forensics teams will be scouring through server logs to find out exactly what happened.

Nevada gaming officials are investigating the attack at the moment, and the FBI is also reported to be looking into the case. Neither was available for comment at time of going to press. ®

Internet Security Threat Report 2014

More from The Register

next story
George Clooney, WikiLeaks' lawyer wife hand out burner phones to wedding guests
Day 4: 'News'-papers STILL rammed with Clooney nuptials
Shellshock: 'Larger scale attack' on its way, warn securo-bods
Not just web servers under threat - though TENS of THOUSANDS have been hit
Apple's new iPhone 6 vulnerable to last year's TouchID fingerprint hack
But unsophisticated thieves need not attempt this trick
PEAK IPV4? Global IPv6 traffic is growing, DDoS dying, says Akamai
First time the cache network has seen drop in use of 32-bit-wide IP addresses
Oracle SHELLSHOCKER - data titan lists unpatchables
Database kingpin lists 32 products that can't be patched (yet) as GNU fixes second vuln
Who.is does the Harlem Shake
Blame it on LOLing XSS terroristas
Researchers tell black hats: 'YOU'RE SOOO PREDICTABLE'
Want to register that domain? We're way ahead of you.
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
The next step in data security
With recent increased privacy concerns and computers becoming more powerful, the chance of hackers being able to crack smaller-sized RSA keys increases.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.