Casino Cyber Breach
Hackers steal casino’s customer data via connected fish tank NEWSBYTE CEO of cybersecurity company Darktrace, Nicole Eagan, has shared details of an embarrassing casino data breach. The anecdote appears to epitomise the flaws in many organisations’ approaches to IoT security, while highlighting some serious industry-wide problems. The cyber-attack encrypted data that was on the network, which made the information inaccessible. Nez Perce Tribal Enterprise Executive Officer Kermit Mankiller confirmed Friday there had not been a data breach and no personal information stored in the systems was shared or compromised. 'We continue to work diligently toward resolving the issue.
Having a whole bunch of smart objects like lights, appliances, and thermometers can make life a little more convenient for businesses, but buying into the internet of things can also make those same businesses more vulnerable to hackers.
Nicole Eagan, CEO of cybersecurity company Darktrace, revealed Thursday that a casino fell victim to hackers thanks to a smart thermometer it was using to monitor the water of an aquarium they had installed in the lobby, Business Insider reported. The hackers managed to find and steal information from the casino's high-roller database through the thermometer.
SEE ALSO: The Internet of Things: Everything You Need to Know In 2 Minutes
'The attackers used that to get a foothold in the network,' Eagan said at a Wall Street Journal panel. 'They then found the high-roller database and then pulled that back across the network, out the thermostat, and up to the cloud.'
That database may have included information about some of the unnamed casino's biggest spenders along with other private details, and hackers got a hold of it thanks to the internet of things.
As Eagan explained at the panel, the proliferation of connected smart devices makes people more vulnerable to cyber attacks. Hardly a surprise revelation, but this case stands as a good object example of the risks.
SEE ALSO: Lawmakers propose bill to make make smart devices more secure
'There's a lot of internet of things devices, everything from thermostats, refrigeration systems, HVAC systems, to people who bring in their Alexa devices into the offices,' she said. 'There's just a lot of IoT. It expands the attack surface, and most of this isn't covered by traditional defenses.'
Because these devices tend to be very basic, they often don't include added security features outside of the common WPA2 Wi-Fi protocol, which by itself isn't a great line of defense. Of course, people are working to make these devices safer and more secure, but the world is still a long way off from being totally safe from hackers who exploit the internet of things.
Last Updated March 25, 2019
Privacy Breach at the Casino Rama Resort
On November 10, 2016, the Casino Rama Resort (Casino Rama) announced that it was informed on November 4, 2016 that its internal computer network was subjected to a cyberattack in which confidential data of employees, customers and vendors was stolen. The privacy breach was reported to the Privacy Commissioner of Canada and the Information and Privacy Commissioner of Ontario. Casino Rama reported that it is also working with the Ontario Provincial Police (OPP), the Royal Canadian Mounted Police (RCMP), the Ontario Lottery and Gaming Corporation (OLG) and the Alcohol and Gaming Commission of Ontario to address the issue.
Updates
May 7, 2019
Superior Court declines to certify class action against Casino Rama.
Read the decision here.
March 25, 2019
The Privacy Complaint Report of the Information and Privacy Commissioner of Ontario was released on January 30, 2019. In the report, the investigator concludes:
- Casino Rama did not have reasonable security measures in place to prevent unauthorized access to records.
- A total of 39 Casino Rama network systems had been compromised in the attack.
- A number of security measures required by legislation were not implemented at the time of the cyber attack.
- Audit report recommendations made by the AGCO in 2015 were not implemented at Casino Rama due to limited IT resources. The failure of Casino Rama to implement the audit report recommendations contributed to the cyber attack.
A summary of the Privacy Complaint report prepared by Charney Lawyers can be found here.
The Privacy Complaint Report of the Information and Privacy Commission of Ontario can be found here.
January 17, 2019
In November 2018, the certification hearing commenced before Justice Belobaba, but was adjourned at the court’s request to allow for further evidence to be filed on the scope of the breach and the number of affected individuals. We anticipate the hearing will resume in spring 2019 and will post further information when it becomes available. We encourage anyone who received notice of the breach from Casino Rama or who was affected by the breach to register at the link above and to continue to visit this site for further updates.
November 2, 2018 – The motion to certify this action as a class action will be heard on November 7 and 8, 2018 in Toronto.
June 6, 2018 – The plaintiffs recently successfully argued a motion to compel the defendants to produce an investigation report authored by Mandiant, a third party cybersecurity company. Mandiant was hired by Casino Rama to investigate the breach immediately after it occurred, and produced a report on its findings. Casino Rama claimed privilege over the Mandiant report, but Justice Glustein ruled that privilege had been waived and ordered the production of relevant portions of the report. You can read Justice Glustein’s reasons for decision here.
Casino Rama’s Press Statements
On November 10, 2016, Casino Rama posted a statement on its website announcing the privacy breach. On November 11, 2016, Casino Rama update the statement to indicate that personal information obtained by hackers has been posted online. The statement can be viewed here.
Who Is Affected and What Confidential Information Was Compromised?
According Casino Rama’s statement, an anonymous hacker claims to have stolen confidential employee information from 2004 to 2016 including performance reviews, payroll data, terminations, social insurance numbers and dates of birth.
Casino Rama also stated that the hacker claims to have stolen other confidential information dating back to 2007, including the Casino Rama’s IT information, hotel and casino financial reports, security incident reports, email, customer credit inquiries, collection and debt information and vendor information and contracts. Some of Casino Rama’s affected customers received an email from Casino Rama advising of the privacy breach.
Privacy Commissioner Investigation
The privacy breach was reported to the Privacy Commissioner of Canada and the Information and Privacy Commissioner of Ontario. On November 10, 2016, the Information and Privacy Commissioner of Ontario posted a statement advising that it has launched an investigation. The statement may be viewed here.
Casino Rama Privacy Breach Class Action
On November 14, 2016, Charney Lawyers PC and Sutts, Strosberg LLP (now Strosberg Sasso Sutts LLP) commenced a national class action on behalf of Casino Rama employees (past and present), customers and vendors for damages arising from the privacy breach. The plaintiffs also seek damages on behalf of members of the OLG’s Self-Exclusion Program whose personal information was provided to Casino Rama by the OLG.
The proposed class consists of all persons residing in Canada, excluding the defendants and the defendants’ executives, whose personal information was collected by Casino Rama, or was provided to Casino Rama by the OLG, and was then stolen or accessed in the breach.
The defendants are Casino Rama Services, Inc., the OLG, CHC Casinos Canada Limited and Penn National Gaming, Inc.
In the action, the plaintiffs assert that the defendants were negligent and that Casino Rama breached its Privacy Policy by failing to take reasonable security measures to protect against unauthorized access to class members’ personal and confidential information.
On May 10, 2017, Justice Belobaba of the Superior Court of Justice in Toronto ordered that carriage of the proposed class action be granted to the plaintiffs represented by Charney Lawyers PC and Strosberg Sasso Sutts LLP, who have served a motion record for certification of the proposed class action. A copy of the decision can be viewed here. A separate class action concerning the Casino Rama privacy breach, commenced by Flaherty McCarthy LLP in Oshawa, has been stayed. The plaintiffs’ motion for certification of the proposed class action has been delayed due to the unavailability of the court to hear the motion as originally scheduled. New dates have been booked for the hearing of the certification motion on April 25-27, 2018. Further details on the outcome of that motion will be posted here as soon as they are available.
What to Do Next?
Anyone who received a notice of the privacy breach from Casino Rama or who believes their private information may have been compromised is urged to immediately notify their banks and credit card companies and to monitor their accounts for suspicious activities. Affected individuals may also contact a credit bureau such as TransUnion Canada or Equifax to determine whether there have been any unauthorized transactions on their accounts to explore options to purchase credit protection services.
Casino Cyber Breach Settlement
Register for the Casino Rama Class Action
Casino Cyber Breach Update
Employees, customers or vendors of Casino Rama who provided their confidential information to Casino Rama as early as 2004 and/or who received Casino Rama’s notice of the breach are also urged to REGISTER HERE to receive updates about the class action, especially if there is a settlement or award of damages.
Contact Us
If you have any questions, please contact:
Tina Q. Yang
Charney Lawyers PC
tinay@charneylawyers.com
Casino Cyber Breach Lawsuit
David Robins