How a Las Vegas Casino Fish Tank Breach Happened
In early 2026 a Las Vegas Strip property confirmed that its lobby aquarium control system had been compromised, exposing guest Wi-Fi credentials and point-of-sale terminals for roughly 45 minutes before isolation.
Step 1 – Reconnaissance
Threat actors scanned publicly reachable IoT devices attached to the fish-tank filtration network, identifying an unpatched operating system running outdated firmware from 2023.
- 1. Map external IPs tied to guest amenities
- 2. Identify legacy firmware on aquarium PLCs
- 3. Locate default credentials still in use
Step 2 – Initial Access
Attackers leveraged a known remote-code-execution vulnerability
to drop a web shell onto the
Attackers leveraged a known remote-code-execution vulnerability to drop a web shell onto the tank controller, then pivoted laterally to the payment VLAN through shared network segmentation.
- 4. Exploit unpatched CVE to gain shell
- 5. Escalate privileges via service account
- 6. Move laterally across flat network
Step 3 – Data Capture & Containment
Within the 45-minute window, credit-card tokens and loyalty account hashes were copied to an external server. Security teams cut the link once anomalous traffic triggered the casino’s SIEM alert.
- 7. Monitor SIEM for beaconing traffic
- 8. Isolate affected VLAN segment
- 9. Force password resets for all admin accounts
Lessons for Casino IT Teams
Isolate operational technology (OT) networks, enforce firmware patch cycles quarterly, and implement micro-segmentation between guest amenities and payment systems to prevent similar breaches.
