Threat Intelligence Brief
Curated summary with source attribution
Source: casino.org
Threat Risk: Medium
Victim: Rivers Casino Philadelphia / Rush Street Gaming
Incident: Exfiltration of 2.56 TB of sensitive personal and financial data.
Impact: Exposure of SSNs, passports, and banking information for employees and customers.
Attacker: Unidentified threat actors
Analysis: The incident involved the theft of 2.56 terabytes of sensitive data, including Social Security numbers and banking details, which were later sold on the dark web. While the company initially claimed only staff were affected, evidence suggests patrons’ data was also compromised. The breach has led to reported cases of identity theft, fraudulent charges, and increased phishing activity.
Recommendations: Encrypt all sensitive PII at rest to mitigate the impact of data exfiltration; Implement strict principle of least privilege (PoLP) for access to employee and customer databases; Deploy advanced monitoring for large-scale data egress to detect exfiltration in real-time
Source: Casino.org
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source