Blog|Login|中文Deutsche日本語
July 23, 2012
 Gambling with File Security
Pin It

Here we have a good lesson in file security from Las Vegas' Palms casino: The IT department reported that on April 14, Hemingway had emailed from her Palms email address to a personal email address extensive amounts of Palms data from a system called the ''Super Playmate'' database, including:

  • The ''Palms’ High Worth Customer List,'' containing data on 86 of the property’s largest customers with $11.7 million in play history. This included their play records and credit amounts.
  • A telemarketing list naming 419 more ''high worth customers'' with a combined credit line of more than $12 million.
  • A February slot tournament list with information on 1,050 players.
  • A list with information on 6,000 players who qualified for invitation to the Palms 2012 Super Bowl party.
  • A list of 4,000-5,000 inactive players.
  • A 2011 marketing document covering the property’s entire special events and marketing campaign for out-of-town customers.
  • The Palms said this information wasn’t readily available to Hemingway and that she had no authority or reason to possess it.

Both file and database breaches often show some similar characteristics that security teams should note:

  • Proper access rights reviews were not occurring. Think back to Manning's access of Hillary's files that enabled WikiLeaks.
  • Security policies to layer additional access controls could have blocked or at least alerted on the activity.

Comments

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been saved. Comments are moderated and will not appear until approved by the author. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment

Comments are moderated, and will not appear until the author has approved them.

« SharePoint Security Challenge #3: Respond to Suspicious Activity | Main | SharePoint Security Challenge #4: Protect Web Apps from Attack »

Find Us Online
RSS Feed - Subscribe Twitter Facebook iTunes LinkedIn YouTube
Authors
Monthly Archives
Email Subscription
Sign up here to receive our blog: