HomeCyber BalkansFBI warns of ransomware actors targeting casinos through third parties

FBI warns of ransomware actors targeting casinos through third parties

Published on

spot_img

An FBI Private Industry Notification issued on Tuesday revealed that ransomware threat actors are increasingly finding access to casinos through third-party vendors. The Nov. 7 notification focused on initial access, the method used by threat actors to infiltrate a victim’s network.

The notification highlighted various ransomware trends observed by the FBI, including the exploitation of vulnerabilities in vendor-controlled remote access to casino servers. Additionally, the FBI noted that small and tribal casinos have been targeted by ransomware attacks, resulting in the encryption of servers and the compromise of personally identifying information (PII) belonging to employees and patrons.

The notification emphasized that between 2022 and 2023, ransomware attacks had compromised casinos through third-party gaming vendors. However, specifics regarding the gaming vendors involved and how they were compromised were not disclosed by the FBI.

The timing of the notification coincided with the disclosure of high-profile social engineering attacks against industry giants, Caesars Entertainment and MGM Resorts. In the case of MGM, the Alphv/BlackCat ransomware gang claimed responsibility for the attack, causing significant disruptions at MGM hotels and casinos for several days.

Another concerning trend highlighted in the notification was the victimization of companies through the use of legitimate system management tools to elevate network permissions. The FBI pointed to a campaign by the Luna Moth ransomware gang, notorious for callback phishing, where victims were duped into installing legitimate system management tools that were then repurposed for malicious activities.

The FBI proposed several mitigations for organizations looking to enhance their identity and access management practices. These included the implementation of phishing-resistant multifactor authentication, regular review of networks for new or unrecognized accounts, and configuring user access controls according to the principle of least privilege.

The FBI’s efforts to provide timely and relevant information to organizations underscore the severity of the ransomware threat and the importance of implementing robust cybersecurity measures. The implications of ransomware attacks on small and tribal casinos as well as larger gaming vendors have far-reaching consequences, highlighting the need for increased vigilance and preparedness within the gaming industry.

Source link

Latest articles

Deceptive GitHub Stars and AI Videos Conceal Crypto Clipper

Title: Cryptocurrency-Themed Malware Campaign Deceives Users with Fabricated Popularity In the world of cybersecurity, a...

F5 Addresses NGINX Vulnerability Allowing Code Execution and DoS Attacks

F5 Alerts Customers About Critical NGINX Vulnerabilities F5 Networks has issued an important out-of-band security...

CISA Emphasizes OT Resilience Amid Stark Warnings on Cyberattacks

Vital Service Providers Need a Plan to Work Through Internet Outages, CISA Warns In recent...

FortiBleed Campaign Exposes 75,000 Fortinet Firewalls Globally

In a recent analysis regarding cybersecurity threats, researchers from SOCRadar have indicated that ongoing...

More like this

Deceptive GitHub Stars and AI Videos Conceal Crypto Clipper

Title: Cryptocurrency-Themed Malware Campaign Deceives Users with Fabricated Popularity In the world of cybersecurity, a...

F5 Addresses NGINX Vulnerability Allowing Code Execution and DoS Attacks

F5 Alerts Customers About Critical NGINX Vulnerabilities F5 Networks has issued an important out-of-band security...

CISA Emphasizes OT Resilience Amid Stark Warnings on Cyberattacks

Vital Service Providers Need a Plan to Work Through Internet Outages, CISA Warns In recent...