DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

How not to explain a breach, Sunday edition

Posted on February 10, 2013 by Dissent

I came across a media report on what appears to be a breach involving card numbers of guests and employees of Island Resort & Casino in Michigan. But was it their breach or not?

Read the casino’s statement:

We would like to address the many rumors that are in circulation regarding the harvesting of credit/debit card information for use in unauthorized transactions.

Unfortunately, we have received reports that guests and employees of the Island Resort & Casino have had their debit/credit card information compromised while on property. As soon as we started receiving these reports, we immediately began working with those affected to not only determine the source of the compromise but also to ensure that no other guests or employees would be affected by these unscrupulous acts of fraud.

While in the process of working with the financial institutions of those affected by these acts of fraud, we have verified that all systems and processes of the Island Resort & Casino/Island Oasis are secure/uncompromised and that these incidents were NOT just isolated to the Island Resort & Casino/Island Oasis, but were also occurring on a local and national level as well.

As a result, we are encouraging everyone who has used their credit/debit card for ANY transactions to please check their credit/bank statements for any signs of fraudulent activity.

They repeat some of that in this media report.

So what are they saying?  Guests who experienced fraud following use of their cards at the casino posted some frustrated comments on Facebook. In their shoes, I might feel frustrated, too.  Was there a payment processor breach?  Suggesting that the breach is regional or national would seem to rule out an ATM compromise, wouldn’t it? Did the casino bring in an expert firm to check their systems thoroughly to confirm that their system is secure or is their statement that their system is secure/uncompromised based on their own IT department’s investigation?

What really happened here?  And why is there no notice on the casino’s web site? Posting signs on the premises or a Facebook page doesn’t reach everyone who may have experienced fraud and may be wondering whether the casino is aware of a problem.

I’ve emailed the casino to ask them to clarify their statement. If I get a response, I’ll update this post.

No related posts.

Category: Breach IncidentsCommentaries and Analyses

Post navigation

← Walmart: no, there’s been no breach of walmart.com
Three breaches, some details (updated) →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • DOJ investigates ex-ransomware negotiator over extortion kickbacks
  • Hackers Using PDFs to Impersonate Microsoft, DocuSign, and More in Callback Phishing Campaigns
  • One in Five Law Firms Hit by Cyberattacks Over Past 12 Months
  • U.S. Sanctions Russian Bulletproof Hosting Provider for Supporting Cybercriminals Behind Ransomware
  • Senator Chides FBI for Weak Advice on Mobile Security
  • Cl0p cybercrime gang’s data exfiltration tool found vulnerable to RCE attacks
  • Kelly Benefits updates its 2024 data breach report: impacts 550,000 customers
  • Qantas customers involved in mammoth data breach
  • CMS Sending Letters to 103,000 Medicare beneficiaries whose info was involved in a Medicare.gov breach.
  • Esse Health provides update about April cyberattack and notifies 263,601 people (1)

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Oregon Amends Its Comprehensive Privacy Statute
  • Wisconsin Supreme Court’s Liberal Majority Strikes Down 176-Year-Old Abortion Ban
  • 20 States Sue HHS to Stop Medicaid Data Sharing with ICE
  • Kids are making deepfakes of each other, and laws aren’t keeping up
  • The Trump administration is building a national citizenship data system
  • Supreme Court Decision on Age Verification Tramples Free Speech and Undermines Privacy
  • New Jersey Issues Draft Privacy Regulations: The New

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.