Hacking group Anubis claims $700 million Catawba Two Kings Resort casino hack

25 April 2025 2 minutes Author: Newsman

Criminals are demanding ransom, holding exhaustive plans for servers, chip storage, CCTV and evacuation systems

The recently built Catawba Two Kings casino in North Carolina has been hacked in a major cyberattack: hackers from Anubis have issued an ultimatum on their darknet website. They claim to have seized an “extremely detailed archive” that includes:

  • Plans of the main hall, hotel and parking
  • Location of server rooms and safes
  • Location of surveillance cameras
  • Evacuation plans, areas for personnel interrogation
  • Even cadastral documentation and seismic reports

If the company refuses to pay the ransom, they promise to make all the files publicly available. The attack potentially threatens the security of the future casino, which is planned to house 4,300 slot machines, 100 tables, a 400-room hotel and dozens of restricted areas. Complicating matters, the project has been plagued by controversy from the very beginning, from fines for lack of licenses to lawsuits with previous partners and conflicts with the Cherokee tribe, which considers the construction illegal.

Anubis is a new but aggressive group that has been active since December 2024. Its business model is ransomware-as-a-service: hackers offer access to their own infrastructure to other criminals. They use a double extortion tactic – file encryption and the threat of data disclosure if a ransom is not paid. Such attacks are becoming increasingly frequent and are aimed at infrastructure and construction sites – especially those associated with public resonance or conflict projects.

Catawba Resort risks becoming the first major building in history to have its security compromised before it’s even finished. If the leaked blueprints are confirmed, it would set a precedent that would force investors and developers to rethink their approach to cybersecurity, not just in the gaming industry, but across all real-world infrastructure.

Other related articles
News
Read more
Hackers have been stealing Caritas donations for over a year
The web skimming attack on Caritas España lasted for over a year and affected 17 WordPress sites. The attackers used WooCommerce to inject malicious scripts, stealing users' payment information. Experts at Jscrambler recommend implementing client-side security and monitoring JavaScript changes in real time.
85
News
Read more
Goodbye cookie requests, hello IP protection in Chrome Incognito mode
Google is changing the rules of the game in Chrome: the separate request for third-party cookies has been canceled, and instead the IP Protection feature will appear in Incognito mode. This tool will reduce tracking via IP address, strengthening user privacy. The innovation is part of the Privacy Sandbox initiative and a response to criticism of the company from regulators and developers.
88
Found an error?
If you find an error, take a screenshot and send it to the bot.