INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
ShinyHunters Demands $1.5M to Keep Vegas Casino Data Private
| 2026-02-20 18:27 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
On February 20, 2026, data-grabbing and extortion gang ShinyHunters claimed to have stolen more than 800,000 records containing employees' Social Security numbers and other private details from Wynn Resorts. The targeted hospitality company was listed on the cybercrime crew's blog with a deadline of February 23 for it to pay $1.5 million in Bitcoin not to leak the data. ShinyHunters gained initial access to Wynn's systems via an Oracle PeopleSoft vulnerability using an employee's credentials, and samples of the stolen data contain employees' full names, emails, phone numbers, positions, salaries, start dates, birthdays, and other personal information. The gang has previously used social engineering tactics to obtain single-sign-on codes from users of Okta, Microsoft, and Google services, and in one case reportedly claimed it agreed to pay a CrowdStrike employee $25,000 for access.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity.
• Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc
• User Training (ATT&CK mitigation for Social Engineering): Reduces success of phishing/vishing/impersonation and modern “human interface” lures.
• Audit (ATT&CK mitigation for Social Engineering): Enables correlation of email/identity/SaaS/endpoint activity that appears legitimate.
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Scattered SpiderScattered Spider
Target & Sectors
Global Scope
healthhealth
hospitalityhospitality
retailretail
Incident Timeline
September 2025
Threat actors known as ShinyHunters demanded $1.5M not to leak data from a Las Vegas casino and resort chain, following their previous intrusions involving voice phishing and abuse of Okta SSO codes in late 2023.
Click on any entity below to view its context and source!
threat_actor
Scattered Spider
In late 2023, Scattered Spider abused Okta SSO codes and
help-desk calls
to break into both resort chains' networks, deployed ransomware on their networks, and stole data belonging to tens of thousands of customers.
At least
seven other
suspected Scattered Spider members were arrested in 2024 as part of wider probes following the Las Vegas resort intrusions.
financial
$25,000 employee
The group has previously used Telegram to solicit insider access, and in one case reportedly
claimed
it agreed to pay a CrowdStrike employee $25,000 for access, though the security shop said no systems were breached.
2026/02/20
ShinyHunters demanded $1.5 million not to leak the stolen data of Wynn Resorts, a hospitality company with 81 restaurants and 200 high-end retail outlets in Las Vegas.
Click on any entity below to view its context and source!
data_breach
800,000 records
On Friday, the cybercrime crew listed the hospitality company on its blog, claiming to have stolen more than 800,000 records containing employees' Social Security numbers and other private details.
financial
$1.5 ShinyHunters
ShinyHunters demands $1.5M not to leak Vegas casino and resort chain data.
ShinyHunters set a fee of 22.34 Bitcoin (about $1.5 million) as the "starting price" for the stolen files, according to a spokesperson for the crime group, who told
The Register
that the digital intruders gained initial access to Wynn's systems in…
Tactical Metrics
Metrics
data_breach
800,000
Records
Click for context!
On Friday, the cybercrime crew listed the hospitality company on its blog, claiming to have stolen more than 800,000 records containing employees' Social Security numbers and other private details.
Metrics
financial
1,500,000
Shinyhunters
ShinyHunters demands $1.5M not to leak Vegas casino and resort chain data.
ShinyHunters set a fee of 22.34 Bitcoin (about $1.5 million) as the "starting price" for the stolen files, according to a spokesperson for the crime group, who told
The Register
that the digital intruders gained initial access to Wynn's systems in…
Metrics
financial
25,000
Employee
The group has previously used Telegram to solicit insider access, and in one case reportedly
claimed
it agreed to pay a CrowdStrike employee $25,000 for access, though the security shop said no systems were breached.
Intelligence Sources
The Register - Cybercrime
2026-02-20
ShinyHunters demands $1.5M not to leak Vegas casino and resort chain data
The Register - Cybercrime
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T07:57
Comprehensive Tactical Telemetry
Highly Correlated Entities
13x
organisation
Identified Entity
Social Security
entity
4x
tactic
Cyber Operation Type
Extortion
tactic
4x
timeline
Temporal Reference
late 2023
date
2x
industry
Targeted Sector
Hospitality
sector
Contextual Telemetry
Context Block
8 METRICS
data breach
Records
800,000
records
general metric
Restaurants
81
restaurants
general metric
Retail Outlets
200
retail outlets
threat actor
APT Group
Scattered Spider
actor
financial
Shinyhunters
1,500,000
shinyhunters
general metric
Bitcoin
22
bitcoin
financial
Employee
25,000
employee
source region
Origin Country
United Kingdom
country
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.