Slashdot Mirror


Hackers Stole a Casino's High-Roller Database Through a Thermometer in the Lobby Fish Tank (businessinsider.com)

From a report: Nicole Eagan, the CEO of cybersecurity company Darktrace, told the WSJ CEO Council in London on Thursday: "There's a lot of internet of things devices, everything from thermostats, refrigeration systems, HVAC [air conditioning] systems, to people who bring in their Alexa devices into the offices. There's just a lot of IoT. It expands the attack surface and most of this isn't covered by traditional defenses."

Eagan gave one memorable anecdote about a case Darktrace worked on where an unnamed casino was hacked via a thermometer in a lobby aquarium. "The attackers used that to get a foothold in the network. They then found the high-roller database and then pulled that back across the network, out the thermostat, and up to the cloud," she said.

2 of 246 comments (clear)

  1. Re:Network Separation (Partial report from vendor) by Anonymous Coward · · Score: 5, Informative

    https://www.darktrace.com/resources/wp-global-threat-report-2017.pdf
    ---
    To ensure these communications remained separate
    from the commercial network, the casino configured
    the tank to use an individual VPN to isolate the tank’s
    data
    ---

    So yes, it was segregated via a VPN link. Clearly that wasn't enough.

  2. Re: What is a high-roller database? by Anonymous Coward · · Score: 2, Informative

    It is a list of people who due to the influence of puppeteers, and to roll above a seven on two six sided dice. Pierson's Casinos use the list to steer these high rollers to games where odds are more in their favor and away from things like craps where a two is a loss and an eleven is a win. Hackers will use it to place side bets to defraud the casino.

    There now you don't have to google it, ya lazy bums.