A cyberattack on the servers of Slovenian gambling and tourism operator Hit forced six casinos offline for about three days, disrupting gaming systems, loyalty services, cash registers, and hotel reception operations. The outage also led to temporary employee furloughs after the company detected the incident overnight between August 24 and 25 and shut down affected systems.
Hit engaged external cybersecurity specialists, notified authorities, and began a forensic investigation alongside Slovenian police. The operator has restored enough infrastructure for a phased reopening with limited gaming capacity, but table games, bingo, and the loyalty program remain unavailable; Hit has not disclosed the intrusion vector, whether data was stolen, whether ransomware was involved, or the financial impact.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
As of Monday, Hit's casinos were operating on a limited basis, with table games, bingo, and the loyalty program still unavailable. Temporarily furloughed employees were returning as systems were restored.
On August 28, Hit said it had restored enough IT infrastructure to gradually reopen the affected casinos. Initially, guests could access only a limited selection of slot machines while other systems and applications were restored.
After identifying the incident, Hit began a forensic investigation, engaged external cybersecurity specialists, and notified relevant authorities. Slovenian police opened an investigation into the attack.
Overnight between August 24 and 25, Hit detected a cyber intrusion and shut down affected operations at six Slovenian casinos, which remained offline for roughly three days. The outage disrupted gaming systems, loyalty services, cash registers, and hotel reception operations; hotels remained open with reduced services while some employees were furloughed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.