Part III: Slot Machine Cheating · Electronic & Digital Cheating Methods
SCAM #27: IoT Device Pivot Attack
How it works
Casinos increasingly deploy Internet of Things (IoT) devices — smart thermostats, connected lighting, digital signage, environmental sensors, smart fish tanks, and more — often on the same network as critical gaming systems. Attackers exploit vulnerabilities in these often poorly secured IoT devices to gain an initial foothold, then “pivot” laterally through the network to reach gaming systems. In the famous 2017 incident, hackers breached a North American casino’s network through an internet-connected fish tank thermometer, ultimately extracting 10 GB of high-roller customer data. A similar attack targeting gaming systems could potentially reach slot machines, CMS servers, or progressive controllers. IoT devices often have weak default passwords, unpatched firmware, and no encryption — making them ideal entry points.
Where it appears
Any casino network where IoT devices share infrastructure with gaming systems; potential targets include CMS, slot machines, player databases, progressive controllers, and financial systems
On the record
In 2017, Darktrace reported a North American casino breach that began with an internet-connected fish tank thermometer. The aquarium had sensors connected to a PC to regulate temperature, salinity, and feeding. Hackers used this as an entry point, moved laterally through the network, and extracted 10 GB of data to a device in Finland. The attack evaded traditional security tools by targeting an unconventional device.
Published as a detection reference for surveillance, compliance and gaming-operations professionals. Thresholds and tuning are set by the property. Nothing here is instruction — the method is described so it can be recognised.