Case file · CASINO FISH TANK

How a casino got hacked through its fish tank: the gadget on the network

Published 2026-09-29 · 5 min read · Missing control: Segment IoT devices from core network

One of the strangest break-ins on record started with an aquarium: attackers got into a North American casino's network through an internet-connected fish tank and sent data out to a device in Finland.[1][2] This case file covers what the security firm that caught it reported, why a fish tank could reach anything important, and the one control that keeps small gadgets from becoming a side door.

What happened

In July 2017 the security company Darktrace published its annual global threat report. Among its examples was a casino in North America that had installed a high-end fish tank with sensors that managed the water temperature, the salinity and the feeding schedule, all controlled over the internet.[2]

The casino was not named, and still has not been. According to the report, the tank had been connected through its own virtual private network, a setup meant to keep it apart from everything else. Even so, attackers got into it, and data began flowing from the casino's network to an unusual outside destination in Finland.[2]

A Darktrace analyst told reporters that someone had used the fish tank to get into the network, then looked around for other weaknesses and moved on to other systems from there.[1] The data transfer was flagged and the security team was alerted.[1][2]

The story came back in April 2018, when Darktrace's chief executive told a business conference in London about a casino whose lobby aquarium thermostat had been used to pull its database of high-rolling gamblers out through the network and up to the cloud.[3] Press coverage described that casino only as being in Las Vegas, and it was never made clear whether the two accounts describe the same incident.[3]

How it worked

The "Internet of Things" is the catch-all name for everyday devices that connect to a network: thermostats, cameras, door locks, printers, TVs, smart speakers and, in this case, aquarium controllers. These devices are built to be cheap and easy to set up. They often ship with simple passwords, rarely receive updates, and are installed by facilities staff or outside vendors rather than the IT team.

That makes them attractive footholds. Once an attacker controls one, it becomes a computer sitting inside the building, trusted by the network around it. In the casino case, reports described the attacker using the tank as a starting point, scanning for other weaknesses, and moving sideways toward more valuable systems.[1]

The detail that stands out is that the tank was supposed to be isolated. It had its own private connection, which on paper should have kept it apart from the rest of the business. Yet the reports make clear that the attacker could still reach other parts of the network from it, and that data could still leave the building through it.[1][2] Separation that exists in a diagram but not in the actual traffic rules is not separation.

How it was caught

This was not caught by an antivirus alert or a tip. The casino was using monitoring software that learns what normal traffic looks like for each device and flags behavior that does not fit.[1] A fish tank has no reason to send large amounts of data to a rare outside address in another country, and that transfer is what stood out.[2]

What exactly was taken, and how much, was not reported in the coverage we could confirm. No arrests or charges have been linked to the case, and the attacker has never been publicly identified. The main public record is the security firm's own account, so the details should be read as its description rather than an official investigation.[2][3]

The firm used the case to make a broader point: companies connecting more objects to their networks often have very little visibility into those devices, which become hidden outposts attackers can use.[2] The same report described an architecture firm whose smart drawing tablets were hijacked and used to flood other organizations with junk traffic.[2]

The missing control

The missing control: segmenting IoT devices from the core network. A fish tank controller needs to talk to its vendor's service and nothing else. It should never be able to reach guest databases, business systems or an arbitrary server abroad.

Real segmentation means putting gadgets on a separate network zone with firewall rules that block them from reaching internal systems and limit where they can send data outside. With those rules in place, compromising the tank would have given the attacker a thermometer and a feeder, not a path to anything worth stealing. Tight outbound limits would also have stopped, or at least slowed, the transfer to Finland.[1][2]

What to do in your business

Watch the case
The casino that was hacked through its fish tankDrops 2027-01-12
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More patching and monitoring cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. CNN Money: A smart fish tank left a casino vulnerable to hackers
  2. SC Media: Hacking Nemo: adversary compromises smart fish tank at casino
  3. Casino.org: Hackers stole Las Vegas casino high-roller database via its fish tank