Skip to content
Casino

Station Casinos Cyberattack Highlights Escalating AI Threat Facing Casino Industry

The latest cyberattack targeting Station Casinos underscores a growing challenge for gaming operators: hackers are now leveraging artificial intelligence to strike faster, smarter, and at greater scale than ever before.

Adam Hutchinson
Adam Hutchinson

Las Vegas casinos have long been high-value targets for cybercriminals, but a new and more dangerous phase is underway. The latest cyberattack against Station Casinos — following the high-profile breaches of MGM Resorts International and Caesars Entertainment in recent years — serves as the latest reminder that the gaming industry is locked in an arms race it cannot afford to lose. And artificial intelligence is tipping the balance toward the attackers.

Station Casinos confirmed a cybersecurity incident in March, stating it would not impact operations, but industry veterans aren’t treating it as routine. For Rick Arpin, managing partner in Las Vegas for KPMG, the pattern is unmistakable.

“The gaming industry is always under attack,” Arpin said. “It’s a high-visibility target for hackers. We’ve gone through waves of incidents in this industry.”

Why Casinos Keep Getting Hit

Tim Williams, chief information officer for Sahara Las Vegas, offered a blunt explanation for why the gaming sector continues to be singled out by hackers. The answer goes beyond the obvious money angle. Modern megaresorts are essentially small cities — running hotels, restaurants, entertainment venues, and casino floors — each governed by separate systems with countless points of access.

“The landscape the technology teams have to handle is non-trivial and there’s such differentiation and so many points of access,” Williams said. “There’s limited resources and it’s a never-ending battle. You can never have a good night’s sleep, because there is always somebody out there trying to get at you. New technology with AI accelerates it.”

The stakes have only risen as AI reshapes what phishing looks like. Williams pointed to highly personalized, AI-generated phishing messages that are nearly indistinguishable from legitimate correspondence — a leap beyond the generic scam emails of a decade ago.

“Everything is moving so fast that something that was maybe state-of-the-art two years ago is now passé,” he said. “Now, AI-tailored phishing messages are so specific to one individual that they’re hard to tell from legitimate emails.”

Shadow IT and the Inside Threat

Williams also flagged an emerging risk that has little to do with external hackers: AI-assisted coding and shadow IT. This occurs when employees outside of information technology create internal tools without proper security oversight, inadvertently opening vulnerabilities.

Kevin Kealy, senior vice president and global chief information security officer for Light and Wonder, put it in blunter terms: The biggest concern is people doing the wrong things for the wrong reasons, and AI enables those mistakes to happen faster and on a larger scale.

“You need some form of AI governance to stop people burning those tokens, running up huge bills, and doing stuff that either doesn’t matter or hurts you,” Kealy said.

Light and Wonder has responded by developing an AI-powered penetration testing tool called APE — AI Pin Test Engineer — which has slashed the time to certify gaming products from six weeks down to one hour and 34 minutes. The approach allows the company to catch security flaws before products ever reach casino floors. For bettors looking to wager at secure, licensed platforms, options like FanDuel Promo Code and DraftKings Promo Code represent operators with extensive cybersecurity investment built into their regulatory compliance requirements.

The Human Factor Remains the Biggest Vulnerability

Despite all the technological countermeasures, the consensus among security professionals is that people — not software — are both the biggest threat and the best line of defense.

Arpin noted that roughly 80% of breaches originate from a human element, citing cases where Las Vegas Strip employees were socially engineered into handing over account credentials. The response cannot just be annual compliance training. Williams said that model is dead.

“The days of once-a-year compliance training with a little bit of a cyber element to it are in the rearview mirror,” Williams said. “For us, it’s a constant approach. Monthly trainings are adaptive and take on a person’s proclivity for things they shouldn’t be doing.”

Kealy echoed that philosophy, emphasizing that employees need to be trusted while simultaneously protected. Multi-step authentication protocols ensure that no single person can authorize a payment or alter payment details without additional verification.

The Cloud Dilemma

A final tension emerging in the gaming industry’s cybersecurity response involves cloud computing. As casinos increasingly migrate operations to cloud-based platforms, some are reconsidering whether on-premises systems might offer better control over sensitive data.

Arpin said the concern centers on data sovereignty — ensuring proprietary and customer information cannot fall into the wrong hands. For properties like Sahara Las Vegas, moving to cloud-oriented applications has brought a practical benefit: access to the dedicated external security teams of major cloud providers, supplementing lean internal IT departments that simply cannot staff up to the scale of a cyberattack response on their own.

The gaming industry’s cybersecurity challenge is not going away. As long as casinos sit at the intersection of enormous cash flows, complex technology ecosystems, and high public visibility, they will remain prime targets. The difference between the operators who weather attacks and those who don’t increasingly comes down to whether they treat cybersecurity as a continuous operational discipline — not a quarterly checkbox. Check out BetMGM Sportsbook Review for more on how major online gaming operators approach player account security.

Subscribe for Casino updates

Join our newsletter to get the latest straight to your inbox!