Marina Bay Sands breach exposed data on 665,000 loyalty members
- Organization
- Marina Bay Sands
- Exploit
- Hacking
- Industry
- Hospitality
Marina Bay Sands, the Singapore hotel, retail and casino complex owned by Las Vegas Sands, disclosed on November 7, 2023 that an unauthorised third party had reached membership data belonging to about 665,000 customers. The access took place on October 19 and 20, 2023, and the resort said it became aware of the incident on October 20.
The affected records belonged to the Sands LifeStyle programme, the resort's non-casino loyalty scheme. Exposed fields included names, email addresses, mobile phone numbers, country of residence, membership numbers and membership tiers. Marina Bay Sands said its casino rewards programme was not involved, and reporting on the notice indicated Social Security numbers and credit card data were not part of the exposure.
Chief operating officer Paul Town said the company acted immediately on discovery. Marina Bay Sands engaged an external cybersecurity firm to investigate, said it had strengthened its systems, and began contacting affected members directly while also messaging customers who were not affected. The resort stated it had no evidence to date that the unauthorised third party had misused the data to cause harm to customers.
The incident was reported to Singaporean authorities and to regulators in other jurisdictions where affected members lived, and the company said it was cooperating with their inquiries. The investigation remained open as of mid-November 2023, and security commentators noted the exposed contact details could be reused in phishing campaigns aimed at members.