Skip to content
All industries
Gaming and Casino

MGM proved the stakes. Boyd, lottery operators, and tribal casinos followed.

Casinos run on uptime, regulatory trust, and guest data. One successful social-engineering call can shut a property for days. Blacklight monitors helpdesk workflows, slot and table systems, and loyalty-program databases, all on one platform.

Incidents and active campaigns in your sector

The pattern is published.

Notable incidents and active campaigns in your sector. The attacker techniques are documented. The regulator timelines are running. Blacklight contains the same patterns autonomously, before the disclosure window opens.

  • MGM Resorts
    Scattered Spider helpdesk social engineering, 10-day outage
    2023, $100M+ impact
  • Caesars Entertainment
    Ransom paid after social engineering
    2023, parallel campaign
  • Boyd Gaming
    Hackers targeted operator
    2025, confirmed breach
  • Jackpot Junction (MN)
    Cyberattack, March 2025
    Operations halted
  • IGT
    Cyberattack, Nov 2024 (ransomware unconfirmed)
    Outage
Case in point

Boyd Gaming, 2025: hackers targeted operator directly

MGM disclosed its breach in 2023; Boyd Gaming disclosed in 2025. A casino runs on uptime, regulatory trust, and guest data. One successful social-engineering call to helpdesk, one MFA reset, and slot systems, table games, and loyalty databases are all one session-token away from compromise. The regulatory fallout outlasts the operational outage. Blacklight detects Scattered-Spider-class helpdesk social engineering before the MFA reset completes. Anomalous admin access to slot, table, and sportsbook systems flagged in real time. Loyalty-database exfil contained autonomously, guest trust preserved. Gaming regulator audit evidence pre-formatted per jurisdiction (Nevada, Macau, Tribal, UK, etc.).

The Blacklight difference
  • Correlated against live threat intel in seconds, not hours.
  • Contained autonomously, before the human analyst arrives.
  • Regulator-ready evidence, bundled and pre-drafted.
What Blacklight would do

Four moves,
on autopilot.

Every action is logged, explained, and reversible. The analyst always has the last word, but they get the case ready-made.

  • Detect Scattered-Spider-style helpdesk social engineering before MFA reset
  • Monitor slot, table, and sportsbook systems for integrity violations and tampering
  • Contain loyalty-database exfil autonomously, preserving guest trust
  • Gaming regulator audit evidence pre-formatted per jurisdiction
Get started

See what truly predictive
security looks like.

Sixty minutes, under your control. See the platform run on a pre-loaded, anonymised environment, watch one real incident handled end to end, and map it to your sector, without connecting a single data source.

A typical demo
  • 01 A live tour on a pre-loaded, anonymised environment, running from minute one, not slides.
  • 02 One real incident, detected, investigated and contained, written up as a regulator-ready report.
  • 03 Mapped to your world: your sources, your sector's threats and your regulators.
  • 04 The questions your board will ask: deployment, residency, security, integrations and TCO.

No connectors or data required from you. A proof-of-value on your own telemetry is the next step, never the ask on a first call.