Regulations centered around cybersecurity attacks against casinos, including notification to Nevada regulators within 24 hours, were one of the highlights of new rules adopted this year.
Las Vegas casinos continue to be targets of hackers, following successful attacks in 2023 against Caesars Entertainment and MGM Resorts International. Caesars is reported to have paid $15 million in ransom to access personal information of customers. MGM claimed losses of $100 million-plus after it was hacked, with casino operations impacted nationwide.
Wynn Resorts was hacked in 2025, with reports saying the resort paid $1.5 million in ransomware to the hackers. Station Casinos was also attacked in March.
American cybersecurity company Crowd Strike has reported this year it expected an 89% increase in threat actors using artificial intelligence for cyberattack, while companies, including casinos, are using the same technology to combat them. When there’s a chance at millions of dollars in ransomware, experts say hackers won’t stop going after casinos and other businesses.
“We expect people to be under attack on a daily basis from cyber threats,” said Jeremy Eberwein, chief of the technology division for the Nevada Gaming Control Board. “We’re looking for cases where attacks are successful. If a system is taken down or data (is compromised or removed), that’s what we’re looking for.”
Among the new regulations approved by the Nevada Gaming Commission as recommended by the Nevada Gaming Control Board is renaming a “cyberattack” to a “cybersecurity incident” at the request of the gaming industry.
Operators are required to have a cybersecurity incident response plan that outlines procedures for preparing for, protecting, responding to, and recovering from an attack.
Another change is the requirement for casinos to give the Board a written notification of an attack to only a notification and to reduce the time period to make that notification from 72 hours to 24 hours.
Casinos are now required to submit a cybersecurity response report within five days of activating the response procedures. In lieu of that report, casinos can request an in-person meeting with the Board chair within those five days.
If an in-person meeting is chosen, the casino must still prepare a report, but it has 30 days from the incident to submit it. Casinos are also required to provide a written update of the cyberattack every 30 days from the initial reporting date until the incident is fully resolved.
“It was important for the Board that the notification of the cybersecurity incident happened within 24 hours,” said Board Chair Mike Dreitzer. “Seventy-two hours in practice was just too long. We modified the reporting requirements for the licensees thereafter to comport with what we now understand is best practice. Previously, the regulation didn’t comport with best practices and it caused a lot of confusion and consternation on the part of licensees. They would have to potentially provide a written response before they were ready or prepared to do so.”
Dreitzer said they had significant input from license holders and cybersecurity experts before drafting the new regulations. Requiring a written report within five days was too soon and license holders needed more time to commit to writing, Dreitzer said. When the Board gets a notice within 24 hours that an attack has happened, it takes a while for the licensee to assess the matter. “The idea is that they’re still assessing the full scope of what happened.”
Kristi Torgerson, chief of the enforcement division, said the 24-hour notification was important, so regulators know what’s happening immediately instead of waiting 72 hours. “We found during a time of crisis that the Gaming Control Board is the last thing on their mind and we don’t need much at the beginning, but an initial notification.”
“The (previous) regulation caused confusion and as a practical matter the licensees weren’t following it because they were confused about how to do so,” Dreitzer said. “This is an appropriate and responsible approach for them to give us the information we need for both real time and at the same time giving them the opportunity to commit it to writing once they have sufficient information to do so.”
Torgerson noted that the name change from cyberattack to cybersecurity incident “seemed to be more palatable for licensees.”
The casino reports are expected to detail who made the attack if they know, what the impact on the business was, what was compromised, whether the system was down, if data was removed, and what the remediation was.
In addition to cybersecurity, the other big regulation passed this year dealt with anti-money laundering problems faced by the Las Vegas Strip casinos.




