Lustich.de does not operate for profit. Surpluses go into charitable projects, for example building schools and wells in Benin (West Africa). Learn more
All Casino News in English
Regulierung

Nevada Tightens Rules: Casinos Must Report Cyberattacks Within 24 Hours

Editorially reviewed by Lisa LustichLast review:
Nevada verschärft Meldefrist: Casinos müssen Hackerangriffe binnen 24 Stunden meldenAI-GENERATED

Following major breaches at MGM and Caesars, Nevada introduces a 24-hour notification deadline for cybersecurity incidents.

The world of Las Vegas gaming is under constant digital siege. Hackers are increasingly targeting the vast amounts of data and financial flows managed by major resort operators. To counter this evolving threat, the Nevada Gaming Commission has implemented significant changes to reporting requirements. Effective immediately, a strict 24-hour deadline applies, during which a casino must notify authorities of a successful breach. Previously, companies had three full days to comply, which proved too slow in practice.

Regulators are responding to an unprecedented wave of cyberattacks that shook the American gambling capital in 2023. Specifically, the incidents at Caesars Entertainment and MGM Resorts International highlighted the industry's vulnerability. While Caesars reportedly paid $15 million in ransom to protect customer data, MGM refused to pay and faced massive operational disruptions costing over $100 million. Such figures attract criminals globally, who are now increasingly using artificial intelligence to bypass security barriers.

Numbers and facts

The threat level is both real and measurable. Cybersecurity firm Crowd Strike predicts an 89% increase this year in threat actors using artificial intelligence for attacks. Simultaneously, casinos are upgrading their technology to fight back with the same tools. However, recent months show that technical defense alone is not enough. Wynn Resorts became a victim of the ShinyHunters group in early 2025, with records of approximately 800,000 employees affected. The hackers demanded a ransom of $1.5 million.

Station Casinos was also targeted in March. Between 2007 and 2023, over 50 confirmed cyber incidents were recorded involving Nevada gaming companies, with the frequency increasing sharply over the last decade. As part of the new regulations, the Nevada Gaming Commission also updated its terminology. At the request of the industry, the term "cybersecurity incident" is now used officially instead of "cyberattack." This change is intended to increase acceptance among licensees, as the term sounds more neutral.

Background

Shortening the notification window from 72 to 24 hours was controversial within the industry. The Nevada Resort Association noted that third-party vendors often need 48 hours themselves to notify casinos of leaks. Nevertheless, the board stood firm. Mike Dreitzer, Chair of the Nevada Gaming Control Board, emphasized the need for timely communication, even if all details are not yet known at such an early stage. It is about establishing initial contact, a signal to the regulator that something is wrong.

"It was important for the Board that the notification of the cybersecurity incident happened within 24 hours. Seventy-two hours in practice was just too long. We modified the reporting requirements for the licensees thereafter to comport with what we now understand is best practice." - Mike Dreitzer, Chair of the Nevada Gaming Control Board

In addition to the 24-hour notice, operators must now submit a detailed incident response report within five days. Alternatively, they can request an in-person meeting with the Board Chair. In this case, the deadline for the written report is extended to 30 days. Throughout the resolution process, written updates are mandatory every 30 days. The goal is to ensure that the regulator is no longer the last thing on a company's mind during a crisis, as Kristi Torgerson of the enforcement division aptly noted.

Why it matters for German players

For German players active in GGL-licensed online casinos, this news from Las Vegas might seem distant, but IT security and data protection are regulated just as strictly here. The Interstate Treaty on Gambling 2021 (GlüStV 2021) places immense value on system integrity. In Germany, all licensed providers must be connected to the central LUGAS supervisory system. This system not only monitors the 1,000 Euro monthly deposit limit and the 1 Euro per spin limit for slots but also sets high technical bars for data protection.

A hacker attack on a German online casino would have immediate consequences for accessibility and data security. Since German providers are strictly regulated, they must also report security incidents immediately. The Joint Gambling Authority of the States (GGL) maintains a whitelist of companies that meet these stringent requirements. Players should therefore ensure they only play with providers holding a German license. Unlike unregulated casinos from Curacao or other offshore jurisdictions, the GGL license provides legal recourse and state oversight to protect player interests in the event of a data leak.

What it means for GGL-licensed casinos

The developments in Nevada could serve as a model for further tightening regulations in Europe. GGL-licensed casinos are already investing heavily in their IT infrastructure to meet GlüStV 2021 requirements. Connectivity through LUGAS and the OASIS exclusion database requires constant real-time communication. Should security gaps occur here, the integrity of the entire German player protection system would be at stake. German providers must therefore constantly update their response plans, much like the resorts in Las Vegas.

"Casinos are opportunistic targets because they have an extensive array of cyber entry points, have lots of money, and the public outcry is less conspicuous when they are attacked." - Researchers at UNLV (University of Nevada, Las Vegas)

For operators in Germany, technical reliability is not an optional extra but a prerequisite for existence. Neglecting system security risks not only fines but the revocation of the valuable GGL license. The Nevada rules demonstrate that transparency with the regulator is the only way to maintain public trust long-term. German players benefit indirectly from this global trend toward increased cybersecurity, as international standards often find their way into local regulations.

Frequently asked questions

Why do casinos in Nevada have to report hacker attacks faster now?

Following massive attacks on MGM and Caesars in 2023, it was determined that the old 72-hour window was too slow. The new 24-hour rule ensures that authorities are informed immediately and can better respond to crises.

What costs did casinos incur from recent cyberattacks?

MGM Resorts reported losses of over $100 million, while Caesars Entertainment paid approximately $15 million in ransom. Wynn Resorts was affected by a demand of $1.5 million in 2025.

What is the difference between a cyberattack and a cybersecurity incident?

In Nevada, the terminology was changed at the industry's request because "cybersecurity incident" sounds more neutral and less stigmatizing. It is primarily a linguistic adjustment in official regulations.

How often must casinos provide updates on an ongoing incident?

Once the initial notification is made, affected companies must provide a written report on the current status every 30 days. This continues until the incident is fully resolved and documented.

Are players in Germany protected from such hacker attacks?

German providers with a GGL license are subject to extremely strict IT security requirements under the Interstate Treaty on Gambling 2021. Connection to LUGAS and state controls ensure a significantly higher level of security than illegal offshore providers.

Share

About the author

Lisa Lustich

Lisa Lustich

Editor-in-chief & casino tester

Lisa Lustich has been testing German-language online casinos since 1997 and runs the Lustich.de newsroom. More than 400 published reviews, certified player-protection advisor (BZgA training, 2019).

All articles by Lisa Lustich

Sources & further reading

In category:Regulation & Licences
In country:United States

Gambling can be addictive. Please play responsibly. Help and counselling at 0800 1 372 700 (BZgA, free & anonymous).

Related topics

Further Reading