INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

ShinyHunters Demands $1.5M to Keep Vegas Casino Data Private

| 2026-02-20 18:27 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
On February 20, 2026, data-grabbing and extortion gang ShinyHunters claimed to have stolen more than 800,000 records containing employees' Social Security numbers and other private details from Wynn Resorts. The targeted hospitality company was listed on the cybercrime crew's blog with a deadline of February 23 for it to pay $1.5 million in Bitcoin not to leak the data. ShinyHunters gained initial access to Wynn's systems via an Oracle PeopleSoft vulnerability using an employee's credentials, and samples of the stolen data contain employees' full names, emails, phone numbers, positions, salaries, start dates, birthdays, and other personal information. The gang has previously used social engineering tactics to obtain single-sign-on codes from users of Okta, Microsoft, and Google services, and in one case reportedly claimed it agreed to pay a CrowdStrike employee $25,000 for access.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity. • Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc • User Training (ATT&CK mitigation for Social Engineering): Reduces success of phishing/vishing/impersonation and modern “human interface” lures. • Audit (ATT&CK mitigation for Social Engineering): Enables correlation of email/identity/SaaS/endpoint activity that appears legitimate. • Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Scattered SpiderScattered Spider
Target & Sectors
Global Scope healthhealth hospitalityhospitality retailretail
Incident Timeline
‎September 2025
Threat actors known as ShinyHunters demanded $1.5M not to leak data from a Las Vegas casino and resort chain, following their previous intrusions involving voice phishing and abuse of Okta SSO codes in late 2023.
threat_actor Scattered Spider
financial $25,000 employee
‎2026/02/20
ShinyHunters demanded $1.5 million not to leak the stolen data of Wynn Resorts, a hospitality company with 81 restaurants and 200 high-end retail outlets in Las Vegas.
data_breach 800,000 records
financial $1.5 ShinyHunters
Tactical Metrics
Metrics
data_breach
800,000
Records
Metrics
financial
1,500,000
Shinyhunters
Metrics
financial
25,000
Employee
Intelligence Sources
The Register - Cybercrime 2026-02-20