What to Do If You Suspect Your Casino Account Has Been Hacked — article cover

What to Do If You Suspect Your Casino Account Has Been Hacked

Brian Kessler·
Share

Maria found out on a Tuesday, at the kind of Shoreditch cafe where they play early Dylan at a volume that pretends to be incidental. Her phone buzzed twice. The first message was her bank asking whether she had authorised a debit of three hundred pounds. The second was the casino, thanking her for her deposit and wishing her luck with the slots.

She had not played in six weeks.

She is forty-one years old, a senior radiographer at a London teaching hospital, and the sort of person who has a password manager and a shredder and opinions about cloud backups. She had, in other words, done most of the things one is supposed to do. And yet here was a thing happening, in the middle of an afternoon, in a way that had clearly already been happening for some hours by the time she noticed.

She put down the coffee and did what most people do first, which is the wrong thing. She opened the casino app to have a look.

The First Hour

There is a specific quality to the panic that comes with a hacked account, which is that it operates at the speed of a lunch break and the money moves at the speed of a wire. The best thing Maria did, in hindsight, was also the simplest. She did not click any of the links in either email. She navigated, by typing the URL, to the casino's main site and used the forgotten-password flow to reset her credentials from a position she knew was genuine.

This matters more than it sounds. A meaningful fraction of account-takeover incidents begin not with the casino being breached but with the player being phished. An email that looks like the casino, a login page that looks like the casino, a form that captures the real password and sometimes the second factor as well. If Maria had opened the casino email and clicked the link in it, she would most likely have walked into the same door the attacker walked through the first time.

From the password-reset page, she changed the password, activated two-factor authentication, which she had not previously enabled, and then called the casino's support line rather than using the chat widget, on the reasoning (correct, as it happened) that chat widgets can be compromised along with the site they live on. Calls take time. Maria had time. Her coffee was already cold.

The support agent, a patient man in Malta called Samir, walked her through the next phase.

Freezing, Documenting, Reversing

The first task is to put the account into a state where nothing further can move out of it. Most regulated operators will, on a credible report of unauthorised access, place an immediate hold on withdrawals and deposits pending investigation. Maria's account was frozen inside ten minutes, which is typical for a licensed operator with a twenty-four-hour security desk. The deposited funds were still in the account balance, having not yet been wagered. The attacker had evidently set up the deposit but not finished the job; some attackers prefer to accumulate a balance across several sessions before moving it to a betting pattern that allows funds to be extracted through wins, the so-called bet-and-cashout laundering method.

Samir asked her to document everything: timestamps of the notifications, the IP addresses on her recent logins (which the account portal exposes in a settings screen), and any unusual password-reset emails from the previous seventy-two hours. Maria found one, dated the previous Sunday, which she had filed as spam. That was the breach point. Somebody had, on Sunday evening, requested a password reset to an email account she owned but had stopped using, linked to the casino from years ago. The reset went through. She had never seen it because she never checked that inbox.

The bank call came next. Her debit card had been used for the casino deposit, which meant she could file a disputed transaction under the relevant chargeback rules. In the United Kingdom, where Maria lives, the consumer protection framework here is fairly generous: if the card was used without authorisation and the cardholder acted reasonably, the bank must refund. The rub is the phrase acted reasonably. If the attacker got the card details from a phished form that also got the casino password, the bank may take the view that the cardholder's own security was at fault. Maria's case was borderline. It took six weeks to resolve, and the resolution was a credit for the disputed amount minus a small administrative irritation.

The Longer Recovery

The account itself took longer to put right. Over the next several days, she and the casino's security team performed what is, in essence, a forensic pass over the account's recent activity. Which logins were hers and which were not. Which withdrawals, if any, had been initiated. Whether the attacker had added a new bank account or crypto address as a withdrawal destination, a common move designed to let funds drain out at the next successful wager. He had, as it turned out, added a prepaid card. The card was removed and flagged; if the issuing bank is willing to cooperate, it becomes a breadcrumb the casino's anti-fraud team can follow.

Maria also, on the advice of a friend who runs security for a fintech, did the patient work of auditing every account tied to the breached email address. Anywhere that address had been used as a recovery option, she migrated to a fresh address she had not broadcast. Anywhere she had reused the password, she rotated. She found seven accounts with the old password, including a long-abandoned forum from 2014 that was the most likely original leak point. The password itself was in the well-known data-breach corpus; she looked it up, months later, on a service that tells you whether a credential has appeared in a public dump. It had, in three separate breaches, the earliest in 2016.

The Lessons, Such As They Are

A hacked casino account is rarely an attack on the casino. It is usually the downstream consequence of something the player did years earlier and forgot about: an old password, a recycled email, a forum that folded and sold its user database. The casino is the place where the money came out, not the place where the door was opened.

Two things, in Maria's judgement after the fact, would have changed the outcome. Two-factor authentication on the account would have stopped the attacker at the first step. A unique password, generated by her manager rather than chosen by her younger self, would have stopped him at the zeroth. She now has both, on the casino account and on every other account she could find, which took an evening and a bottle of decent Rioja to complete.

The casino, to its credit, reversed the deposit and reinstated the account balance as it stood before the incident. Samir sent a polite follow-up two weeks later confirming the case was closed. Maria did not rush back to the slots. When she did return, a month or so later, it was to withdraw the balance and close the account. She did not want, she said, to keep a room in a house that had already been broken into once. The landlord had fixed the lock. She was choosing to move anyway. That, at the end of the afternoon, is a reasonable thing to choose.

Related posts