Aristocrat Leisure confirmed employee data stolen through MOVEit flaw

Organization
Aristocrat Leisure Limited
Exploit
Hacking
Industry
Gaming Technology

Aristocrat Leisure Limited, the Sydney-based manufacturer that is Australia's largest maker of gaming machines, confirmed in early August 2023 that it had been caught in the mass exploitation of a zero-day vulnerability in the MOVEit managed file transfer product. In a public statement, the company said a criminal actor exploited the previously unknown flaw in the third-party file sharing software it used and extracted data from one of its servers on or around 1 June 2023.

The company said the stolen material included personal information belonging to Aristocrat employees along with other data. It added that it was aware of reports that the criminals had published extracts of the stolen data online. Aristocrat did not state how many staff were affected or break down the categories of personal information involved, and it did not publicly name the group behind the intrusion.

Aristocrat said it contained the incident and remediated the MOVEit vulnerability, engaged independent security professionals to determine what had been taken, and notified law enforcement and gaming industry regulators. It informed its global workforce and offered all employees complimentary credit monitoring and identity theft protection.

Having completed a risk assessment, the company said it expected the incident to have a low impact on its business operations, provided its mitigation plan was carried out. As of the August 2023 disclosure the matter remained under investigation.

Sources