Wynn Resorts has become the latest Las Vegas casino operator to report a cyberattack, underscoring ongoing security challenges across the gambling industry.
Key Takeaways
* Wynn Resorts experienced a cyber incident affecting approximately 800,000 employee records, with the alleged hacker claiming data deletion.
* Nevada regulators have implemented new cybersecurity reporting rules, requiring licensees to notify authorities within 24 hours of activating incident response plans.
* The incident has led to two federal class-action lawsuits against Wynn, while previous large-scale attacks on MGM Resorts and Caesars Entertainment highlight a persistent threat to Las Vegas operators.
Wynn Resorts Faces Cyber Incident and Lawsuits
Wynn Resorts recently disclosed a cyber incident, termed a “cyberattack” or “cyber incident” under Nevada’s updated regulations. The company stated that an unauthorized third party acquired certain employee data. This incident, reportedly carried out by the cybercrime group ShinyHunters, involved approximately 800,000 records containing sensitive employee information.
According to The Register, the hackers claimed the attack on February 20 and set a $1.5 million ransom deadline for the following Monday. Wynn acknowledged the attack in a statement on Tuesday, though it did not specify whether any ransom was paid. The operator indicated that the third party “stated that the stolen data has been deleted” and that Wynn has “not seen any evidence that the data has been published or otherwise misused.”
This incident marks Wynn’s first time following the state’s new protocols, as confirmed by the company to iGB. The Nevada Gaming Control Board (NGCB) did not confirm if this was the initial incident reported under the revised regime.
Following the incident, Wynn Resorts is now facing two federal lawsuits in the US District Court in Las Vegas. Richard Reed, a California resident and Wynn customer, filed the first suit, seeking class-action status over allegations of negligent information handling. It is important to note that reports indicate only employee data was affected, not customer information. A second class-action lawsuit was filed by former Wynn employee Drake Maynard, alleging the company’s lack of “adequate data security measures.” This suit seeks damages exceeding $5 million. Wynn has not commented on the lawsuits but confirmed it is offering credit and identity theft services to affected employees.
Evolving Regulatory Landscape and Industry Concerns
Cybersecurity has emerged as a persistent concern for Las Vegas casino operators, with Caesars, MGM, and Boyd also reporting incidents within the last three years. In response, state regulators this year approved amendments to cybersecurity reporting rules, aiming for increased transparency from licensees. The updated rules, finalized in January, now require operators to notify regulators within 24 hours “after activating the response procedures set forth in its cybersecurity incident response plan,” a reduction from the previous 72-hour window.
At an NGCB workshop in December, Chair Mike Dreitzer noted a “misalignment” between older rules and what regulators considered “best practice.” While these changes aim to improve communication, industry representatives, such as Erik Hanson, information security officer for Affinity Gaming, cautioned at the December workshop that it could increase reports of non-material incidents.
Las Vegas Casinos as Prime Targets
Las Vegas casinos have become frequent targets for cybercrime. A UNLV study last year documented over 50 confirmed cyber incidents involving Nevada gaming companies between 2007 and 2023, with the majority occurring in the last decade. Researchers highlighted that casinos are “opportunistic targets” due to their extensive cyber entry points, significant financial assets, and the less conspicuous public outcry when attacked. The study also pointed out that much of the gaming industry relies on older technology, making it vulnerable.
Concerns about cybercrime in Las Vegas intensified following two large-scale attacks in 2023 on MGM Resorts and Caesars Entertainment. These separate incidents were widely attributed to the “Scattered Spider” hacker group. Both companies experienced operational interruptions, resulting in substantial financial losses and national media attention. Caesars confirmed paying a $15 million ransom, while MGM, which did not pay a ransom, reportedly incurred approximately $100 million in costs when its systems were offline for over a week.
Law enforcement has taken action in connection with these attacks. Last September, the Las Vegas Metropolitan Police Department announced the arrest of a teenager on charges including identity theft and extortion. In 2024, another teenager allegedly linked to the attacks was arrested in England. MGM assisted the UK investigation, stating, “We’re proud to have assisted law enforcement in locating and arresting one of the alleged criminals responsible for the cyberattack against MGM Resorts and many others.” The company emphasized its stance: “By voluntarily shutting down our systems, refusing to pay a ransom and working with law enforcement on their investigation and response, the message to criminals was clear: it’s not worth it.”
Wynn Resorts, for its part, has acknowledged potential cyber risks for years, detailing them in its 2024 annual report to the Securities and Exchange Commission. The company stated, “Despite the security measures we currently have in place, our facilities and systems… may be vulnerable to security breaches, acts of vandalism, phishing attacks, computer viruses… and other events.” Wynn maintains it is taking appropriate steps and working with third-party cybersecurity experts to strengthen its systems against future incidents.
I remember the first time I saw Kai Tak, Hong Kong’s gambling city, I thought I was in a fairy tale. All the lights blinking, the music and the monumental buildings, what 9-year-old wouldn’t think they’ve come to a magical place? It was my father who brought me, dragging me along and when inside I was hit by the smell of frying duck. As soon as I hit 21 I returned to Kai Tak, A bit nervous to see if my mind had embellished the memory, but it hadn’t. Kai Tak was still a magical place. I decided I wanted to spend as much time as I could at this place, so I did.