Case file · SANDS CASINO 2014

The Las Vegas Sands cyberattack: a forgotten test server and a wiped casino network

Published 2026-09-29 · 4 min read · Missing control: Lock down forgotten development servers

One of the world's largest casino companies had about three-quarters of its Las Vegas servers wiped in early 2014, and the attackers got their start on a test web server at a casino in Pennsylvania.[1][2] This case file covers the remark that preceded the attack, how the intruders moved from a side door to headquarters, what the damage cost, and the one control that was missing.

What happened

In October 2013, Las Vegas Sands chairman and CEO Sheldon Adelson spoke at Yeshiva University in New York and suggested the United States could fire a nuclear weapon into the Iranian desert as a warning over Iran's nuclear program.[1][3] The comment drew angry responses in Iran.

In January 2014, intruders began targeting Sands Bethlehem, the company's casino resort in Bethlehem, Pennsylvania.[1] Their way in was a web development server, a machine the company used to test website pages before they went live.[1][4] By the start of February they had found login details belonging to a company engineer who worked at headquarters but had used systems in Bethlehem, and they used them to reach the Las Vegas network.[1]

In early February 2014, they released destructive software that erased data across the company's computers. About three-quarters of the Las Vegas servers were hit, email went down, and staff found desktops and laptops unusable.[1][2] The company cut itself off from the internet to stop the spread.[1]

How they got in

The weak point was not the casino floor or the main website. It was a server built for testing, the kind of machine that is often set up quickly, given a simple login, and then forgotten while attention goes to production systems. The attackers ran automated password guessing against it, trying thousands of combinations a minute until one worked.[1]

Once on that machine, they looked for passwords left behind by people who had logged in earlier. One belonged to an engineer with access to the Las Vegas headquarters network, and the company's internal connection between sites let them follow that path.[1][4] In other words, a low-value test box in one property shared enough with the rest of the business that taking it over opened the way to everything else.

The wiper itself was not sophisticated. Reports described it as a short program of about 150 lines.[1] It did not need to be clever, because by then the attackers had the access they needed.

What it cost

The company estimated the cost of replacing and rebuilding systems at more than $40 million.[1][2] Core casino operations kept running because they relied on a separate mainframe system that the wiper did not reach.[1] In filings, the company also said attackers had likely compromised the Pennsylvania property and may have taken data, including some customer information.[5]

No one was charged. On February 26, 2015, Director of National Intelligence James Clapper told the Senate Armed Services Committee that Iran was responsible, and he grouped the attack with North Korea's destructive hack of Sony Pictures.[5][6] That was the first time the U.S. government publicly attributed the Sands attack to Iran.[6]

The missing control

The missing control: lock down forgotten development servers. Test machines that face the internet need the same strong logins, limits on repeated guessing and monitoring as production systems, or they should not face the internet at all.

Each part of that would have helped. Blocking an account after a handful of wrong guesses, or requiring a second login factor, would have made the password-guessing attack fail. Keeping the test server off the internet, or behind a login only staff could reach, would have taken away the side door entirely. And keeping development machines separated from the network that connects to headquarters would have meant that even a fully compromised test box led nowhere. Thousands of guesses a minute is also noisy; someone watching that server's logs had a chance to spot it weeks before the wipe.[1]

What to do in your business

Watch the case
The casino owner's Iran remark and the wiper that followedDrops 2026-12-22
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More patching and monitoring cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. Nextgov: Sands casino corporate systems eviscerated by Iranians
  2. Casino.org: Iranian hackers retaliated against Sheldon Adelson for $40M hit
  3. Tablet: When Iranian hackers hit Adelson's casinos
  4. The Hill: Iranian hackers downed Adelson's casino empire
  5. CNN Money: Iran hacked an American casino, U.S. says
  6. Bloomberg: Iran behind cyber-attack on Adelson's Sands Corp., Clapper says