Major casino operators have experienced well-publicized computer system security breaches in recent years. One expert in the field says the cyberattacks will continue.
Retired Navy chief cryptologist Chase Cunningham spoke at the World Game Protection Conference at South Point Casino in Las Vegas this week. He painted a grim picture for the industry. He said despite significant budgets to fight cyberthreats, most companies will experience a breach at some point, CDC Gaming reported.
“If you think you can spend your way to better cybersecurity compared to others who don’t spend as much, you’re wrong,” Cunningham said. “Organizations spend (millions of dollars) a year on cybersecurity and they all get breached.
“What does that all mean for us? We should accept the reality that there is no perfect defense. It doesn’t matter what you do. Sooner or later, the very nature of engineering and building something means someone out there can reverse engineer. This is why the bad guys have a lot of reasons to do this stuff.”
Resilience Is Key
Rather than working to prevent all breaches, Cunningham said companies should accept that hacking will occur at some point. He recommended instead focusing more on “resilience in operations and blast control.”
Despite advances in technology, companies regularly become victims, he said. These advances have mostly been fruitless. Cunningham urged vigilance, but also stressed accepting that no plans are foolproof.
“It’s not keeping up, because no wall is high enough,” he said. “This is the only market where as we invest more and vendors win more, things don’t get better.”
Simple processes like using complex passwords can go a long way toward prevention, he said. Cunningham added that expenses incurred from a breach can be bad for the entire industry, as these costs are passed on to customers in the long run.
Recent Casino Cyberattacks
Cunningham’s comments come after Las Vegas casino companies faced serious breaches over the last few years. Wynn Resorts became the latest in February, when hackers demanded $1.5 million and threatened to release 800,000 employee records if the demand wasn’t met.
In September, Boyd Gaming acknowledged a security breach in a filing with the Securities and Exchange Commission. The company said hackers gained access to some employee information and “a limited number of other individuals.”
The 2023 attacks against MGM affected the company’s casinos across the country and ultimately cost MGM $100 million. At the same time, Caesars Entertainment was attacked. It ultimately paid a $15 million ransom to regain control of many of its systems.
Attackers have also targeted online casino operators. In 2023, Mexican online gambling operator Strendus allegedly left player data accessible online after failing to set a password to secure the information.
In 2022, PokerStars experienced hacking attempts during the World Championship of Online Poker tournament series. As a result, the company postponed several tournaments for later in the year. PokerStars noted that player information remained secure.
More recently, PokerGO experienced a DDoS attack at the start of the World Series of Poker main event final table. The issue was quickly resolved and viewers didn’t miss much of the coverage.

