Article Details
Scrape Timestamp (UTC): 2023-11-07 14:39:35.334
Original Article Text
Click to Toggle View
Marina Bay Sands discloses data breach impacting 665,000 customers. The Marina Bay Sands (MBS) luxury resort and casino in Singapore has disclosed a data breach that impacts personal data of 665,000 customers. According to the statement, the security incident was discovered on October 20 and an unauthorized party was able to access information belonging to members of the MBS loyalty program. “Marina Bay Sands became aware of a data security incident on 20 October 2023 involving unauthorized third-party access on 19 and 20 October 2023 to some of our customers’ loyalty programme membership data,” reads the announcement. “Investigations have since determined that an unknown third party accessed customer data of about 665,000 non-casino rewards programme members,” the company added. The type of information exposed in the data breach includes the following: The data could help an attacker target MBS customers in various scams as well as phishing and social engineering attacks. It is specifically clarified that current evidence does not indicate that casino members (Sands Rewards Club) have been impacted by the incident. The company says that MBS customers who have had their personal data exposed to the attackers will be informed of the breach and impact in indivifual notifications. After discovering the incident, MBS reported it to authorities in Singapore and other relevant countries. While the scope of the attack has not been clarified publicly, the intrusion could be related to a ransomawre attack. Threat actors are often stealing data from company networks and then try to extort money from the victim. At the time of writing, though, no ransomware actor has claimed the attack on Marina Bay Sands. BleepingComputer has contacted the resort to ask for more information about the security incident, but a spokesperson declined to comment beyond the details in the official statement.
Daily Brief Summary
Marina Bay Sands resort and casino in Singapore reported a data breach affecting the personal information of around 665,000 customers.
The unauthorized access, discovered on October 20, compromised data belonging to members of the MBS loyalty program.
Exposed data could potentially be used by attackers to target MBS customers in various scams, phishing, and social engineering attacks. The casino members (Sands Rewards Club) are believed to be unaffected by the breach.
Following discovery of the breach, MBS reported the incident to Singaporean authorities and others in relevant countries.
Although the scale of the attack remains unclear, it may be linked to a potential ransomware attack where threat actors steal data to extort money. As of now, no ransomware perpetrator has claimed responsibility.
MBS has declined to comment further than the official statement on the issue, which affirmed that customers whose personal data was exposed will be individually informed.