DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

How not to explain a breach, Sunday edition

Posted on February 10, 2013 by Dissent

I came across a media report on what appears to be a breach involving card numbers of guests and employees of Island Resort & Casino in Michigan. But was it their breach or not?

Read the casino’s statement:

We would like to address the many rumors that are in circulation regarding the harvesting of credit/debit card information for use in unauthorized transactions.

Unfortunately, we have received reports that guests and employees of the Island Resort & Casino have had their debit/credit card information compromised while on property. As soon as we started receiving these reports, we immediately began working with those affected to not only determine the source of the compromise but also to ensure that no other guests or employees would be affected by these unscrupulous acts of fraud.

While in the process of working with the financial institutions of those affected by these acts of fraud, we have verified that all systems and processes of the Island Resort & Casino/Island Oasis are secure/uncompromised and that these incidents were NOT just isolated to the Island Resort & Casino/Island Oasis, but were also occurring on a local and national level as well.

As a result, we are encouraging everyone who has used their credit/debit card for ANY transactions to please check their credit/bank statements for any signs of fraudulent activity.

They repeat some of that in this media report.

So what are they saying?  Guests who experienced fraud following use of their cards at the casino posted some frustrated comments on Facebook. In their shoes, I might feel frustrated, too.  Was there a payment processor breach?  Suggesting that the breach is regional or national would seem to rule out an ATM compromise, wouldn’t it? Did the casino bring in an expert firm to check their systems thoroughly to confirm that their system is secure or is their statement that their system is secure/uncompromised based on their own IT department’s investigation?

What really happened here?  And why is there no notice on the casino’s web site? Posting signs on the premises or a Facebook page doesn’t reach everyone who may have experienced fraud and may be wondering whether the casino is aware of a problem.

I’ve emailed the casino to ask them to clarify their statement. If I get a response, I’ll update this post.

Category: Breach IncidentsCommentaries and Analyses

Post navigation

← Walmart: no, there’s been no breach of walmart.com
Three breaches, some details (updated) →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Nova Scotia Power hit by cyberattack, critical infrastructure targeted, no outages reported
  • Georgia hospital defeats data-tracking lawsuit
  • 60K BTC Wallets Tied to LockBit Ransomware Gang Leaked
  • UK: Legal Aid Agency hit by cyber security incident
  • Public notice for individuals affected by an information security breach in the Social Services, Health Care and Rescue Services Division of Helsinki
  • PowerSchool paid a hacker’s extortion demand, but now school district clients are being extorted anyway (3)
  • Defending Against UNC3944: Cybercrime Hardening Guidance from the Frontlines
  • Call for Public Input: Essential Cybersecurity Protections for K-12 Schools (2025-26 SY)
  • Cyberattack puts healthcare on hold for hundreds in St. Louis metro
  • Europol: DDoS-for-hire empire brought down: Poland arrests 4 administrators, US seizes 9 domains

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Apple Siri Eavesdropping Payout Deadline Confirmed—How To Make A Claim
  • Privacy matters to Canadians – Privacy Commissioner of Canada marks Privacy Awareness Week with release of latest survey results
  • Missouri Clinic Must Give State AG Minor Trans Care Information
  • Georgia hospital defeats data-tracking lawsuit
  • No Postal Service Data Sharing to Deport Immigrants
  • DOGE aims to pool federal data, putting personal information at risk
  • Privacy concerns swirl around HHS plan to build Medicare, Medicaid database on autism

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.