Sectors

Hospitality, Gaming & Travel

Documented social engineering incidents targeting the hospitality, gaming & travel sector, sourced and fact-checked.


8 Cases
Confirmed

Yujing Zhang Mar-a-Lago Intrusion

A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool visit and an unverified family-tie claim, then was found carrying a USB drive initially flagged as containing malware, a determination prosecutors later said may have been a false positive, along with four phones, over $7,600 cash, and a hidden-camera detector.

Incident 2019Read →
Confirmed

12-Defendant Nationwide Business Email Compromise Ring (United States v. Bosket et al., District of South Carolina)

A federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud, money laundering) for a nationwide BEC ring that monitored hacked/compromised business email accounts, spoofed emails from trusted insiders and vendors to redirect wire payments, and laundered more than $25 million through sham U.S. companies before sending proceeds overseas.

Incident 2020Read →
Confirmed

MGM Resorts Help-Desk Vishing Breach (Scattered Spider, 2023)

A roughly ten-minute phone call impersonating an MGM employee to the IT help desk let Scattered Spider reset MFA, seize identity-system control, and trigger an outage MGM valued at about $100 million.

Incident 2023Read →
Confirmed

FIN7 BadUSB "Best Buy" Gift Card Mailings via USPS

FIN7 (Carbanak) mailed USPS packages disguised as Best Buy gift-card rewards containing BadUSB hardware implants to HR, IT, and executive staff at US retail, restaurant, and hotel companies, aiming to trigger automatic malware installation the moment a curious employee plugged the device in.

Incident 2020Read →
Confirmed

FIN7 (Carbanak Group) DOJ Prosecutions: Fedorov, Hladyr, Kolpakov, and Iarmak (2018-2022)

DOJ unsealed indictments and won guilty pleas, prison terms, and multimillion-dollar restitution against FIN7 (Carbanak Group) members Fedir Hladyr, Andrii Kolpakov, and Denys Iarmak: the authoritative government case documenting the group's fake "Combi Security" recruitment front and its later mailed-USB (BadUSB) baiting campaigns against 100+ U.S. companies.

Incident 2015Read →
Confirmed

Caesars Entertainment Vendor Social Engineering Breach (2023)

Attackers later attributed to Scattered Spider (a group representative initially denied involvement) social-engineered Caesars Entertainment's outsourced IT support vendor, since identified in litigation as Coforge, into resetting credentials, stole the Caesars Rewards loyalty database (SSNs and driver's license numbers), and Caesars reportedly paid roughly $15 million to keep the data private. It was disclosed in an SEC 8-K days before the parallel MGM Resorts breach by the same actor.

Incident 2023Read →
Confirmed

Carnival Corporation Employee Vishing Breach (2026)

A single vishing call impersonating Carnival's own IT security team convinced an employee to hand over credentials, giving an unauthorized actor a foothold that led to the theft of personal data on nearly 6 million people.

Incident 2026Read →
Confirmed

Axie Infinity / Ronin Bridge Heist: A Fake LinkedIn Job Offer That Cost ~$600M

Lazarus operators spear-phished a senior Sky Mavis engineer through a fake LinkedIn recruiting process and a spyware-laced job-offer PDF, then pivoted to the Ronin bridge validator keys and drained roughly $540-625M in crypto.

Incident 2022Read →