Another Las Vegas Casino Suffered Major Cyberattack — Back in January

The OYO Hotel & Casino Las Vegas (formerly Hooters Hotel & Casino) suffered a significant cyberattack in January 2025, according to court filings first reported by Crain’s New York Business on October 14, 2025. The resulting data breach reportedly compromised the personal information of 4,700 casino and hotel guests and employees.

The OYO Hotel & Casino in Las Vegas experienced a major cyberattack in January 2025, according to court filings reported last week. (Images: Shutterstock)

The cyber attack surfaced in a legal dispute between Highgate Hotels, a prominent hotel management firm, and OYO Hotels, which owns properties in Las Vegas and New York, among many other cities. Highgate filed suit contesting its abrupt termination from the OYO Times Square hotel, arguing that its August 1, 2025 dismissal violated New York Labor Law Section 860-a, which requires 90 days’ notice for certain mass layoffs.

OYO defended its action by citing “seriously deficient” IT practices at Highgate, as demonstrated by a Las Vegas data breach that went unreported by mainstream news outlets until the legal filings surfaced. (OYO also fired Highgate as its Las Vegas property manager, though Paragon continues to operate the casino, according to Vital Vegas.)

However, OYO’s termination of Highgate came six weeks before the breach’s official discovery date. As recorded by the state of Maine attorney general’s office, it wasn’t notified of the incident until September 18, 2025.

Crain’s characterized this timeline discrepancy as “unexplained,” suggesting that OYO may have chosen to keep the incident under wraps for eight months.

As determined by Casino.org, BreachSense.com, a dark web monitoring service, published this report of the incident on January 14, 2025, fingering LockBit 3.0, a notorious ransomware group that it claimed leaked the compromised OYO Las Vegas data on its dark web portal.

Further details published on August 15, 2025 by another cyber monitoring site, Brinztech.com, claimed that 30 gigabytes of sensitive data was stolen and exposed in the incident. This reportedly included:

  • Personal and financial information of hotel and casino patrons
  • Internal financial and operational records
  • Human resources files containing sensitive employee data
  • Proprietary documentation related to casino gaming systems and procedures

OYO did not immediately return Casino.org‘s request for a response.

Corey Levitan joined Casino.org in 2022 after a long career covering Las Vegas. He currently covers entertainment, dining and gaming news in Las Vegas.

Corey spent six years covering the Vegas Strip for the Las Vegas Review-Journal, where he also wrote the most popular humor column in the city’s history. (For “Fear and Loafing,” he tried out 176 Vegas jobs, including poker player, blackjack dealer and Follie Bergere dancer.)

Corey has won more than 100 local, state and national awards for his journalism, which has also appeared in Rolling Stone, New York Magazine and the New York Post.

Corey is a New York native whose hobbies include playing guitar, trying to be a better husband, and arguing with strangers on Facebook.

Contact Corey at corey@casino.org.

Comments icon

Conversation (1 comment)

+ Add a comment
  • D
    David October 19, 2025
    No mention of the casino operator. So who is at fault for the casino data? Total dangerous sh*thole
    Reply

Write a comment

Your email address will not be published.