The Hard Rock Hotel & Casino of Las Vegas has admitted that criminal hackers may have had access to credit or debit card information in a breach that lasted from September 2014 until last month.
The exposed information includes names, card numbers and CVV codes. Hard Rock Hotel & Casino gave few details, only stating in a website notice that «some» restaurants, bar and retail points on the property of Hard Rock Hotel Las Vegas, including the Culinary Dropout Restaurant, were affected, while the attack had no impact on the hotel’s, casino’s and the Nobu, Affliction, John Varvatos, Rocks, Hart & Huntington Tattoo, Reliquary Spa & Salon transactions.
«Trust and faith of our customers is our highest priority,» Hard Rock Hotel & Casino says in its statement. «We sincerely apologize for this incident, [and] we are sorry for any inconvenience it may have caused.»
The statement is brief, and refers Hard Rock Hotel & Casino customers to credit check and fraud detection services.
«The consumer is somewhat helpless in’ this case and must rely on the hotel's data security to prevent the theft of his card information», said George Rice, senior payments director at HP Security Voltage, in an email of «Most hotels require a card on file because cash is not a good option (and we definitely would not want to recommend that). PIN debit can protect that transaction, but not the PAN which could be used elsewhere without the RIN… and I'm not sure that PIN debit is generally accepted in hotels. EMV will not prevent data theft and is (still) not mandatory in the US. Payment tokens could help, but in my opinion, generally, they are not accepted in hotels.»
Add also, «it is within every consumer's jurisdiction to review bank statements and credit reports carefully and regularly.»
Ken Westin, a security analyst at Tripwire, added that the payments industry must massively shift towards point-to-point encryption (P2PE), which of course may have a high cost because it often requires an examination of existing payment systems, resulting in this process not being able to be executed quickly.
However, «the fact that we continue to see the «retail breaches» even after the massive breaches we had last year, this means two things,» he noted. «First, attackers are adapting their methods and the complexity of their tools. Second, many retailers need to invest more in detection and have not yet adapted their defenses to detect these very significant and real threats.»

