Skip to content

Part IV: Financial Fraud · Internal Collusion & Employee Fraud

Scam #25: Database Breach and Customer Information Theft

IT Insider Threat / Cyber FraudSkill: Intermediate to Professional

How it works

Employees with access to customer databases can steal personal information including names, addresses, Social Security numbers, financial account information, and player card data. This information can be sold to identity thieves, used to create fraudulent credit applications, or exploited for direct financial gain. The Nevada Gaming Control Board has investigated numerous cases involving the compromise of player club program databases. In some cases, employees have been bribed to download sensitive information. The threat extends beyond casinos themselves - smartphone applications that require personal information are also targets. Cybercriminals from Eastern Europe have been identified as primary attackers targeting casino databases.

Where it appears

Customer databases, player club systems, mobile applications, financial records

On the record

In 2011, the Nevada Gaming Control Board publicly acknowledged investigating multiple cases of player club database compromises. In 2010, a hacker acquired attendee information from an event at Mandalay Bay. The Wynn Resorts data breach (2025-2026) affected 21,000+ employees when hackers targeted HR systems.

Published as a detection reference for surveillance, compliance and gaming-operations professionals. Thresholds and tuning are set by the property. Nothing here is instruction — the method is described so it can be recognised.