CSIDB logo
Threat actor

Eddie Raymond Tipton

Attribution profile

Type
Insider - Disgruntled
Location
United States of America
Known incidents
1 incident
First seen
2010-12-29
Last seen
2010-12-29
Updated
2026-07-31 07:41
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Eddie Raymond Tipton, also known by his full name, is a former security director for the Multi-State Lottery Association who operated within the United States, specifically in Iowa. He was arrested in January 2015 by the Iowa Division of Criminal Investigations after allegations surfaced that he had tampered with the lottery’s random number generation system in December 2010. Prosecutors contend that Tipton used his authorized access to the secure environment housing the offline number‑generator computer to alter video surveillance settings, reducing recording frequency to one second per minute, thereby creating a window for unauthorized physical interaction. During that window he is said to have inserted a thumb drive containing a self‑deleting rootkit intended to influence the outcome of the draw so that a winning ticket could be purchased and later claimed for a $14.3 million prize that remained unclaimed. Tipton has publicly denied the charges, but the case rests on surveillance footage showing him purchasing the ticket and on forensic analysis of the compromised computer.

The alleged activity demonstrates a clear focus on the gaming and lottery sector, with the geographic scope limited to the United States, and the strategic objective appears to be financial gain through fraud rather than espionage or disruption. The reported tactics include the use of a removable USB device as an initial access vector to bypass air‑gapped controls, the deployment of a custom rootkit designed to execute a specific function and then erase itself to avoid detection, and the manipulation of physical security controls—specifically the adjustment of CCTV recording parameters—to reduce the likelihood of observation. These techniques reflect an insider threat approach that abuses trusted privileges to introduce malicious code and to conceal the intrusion through environmental tampering. No evidence links Tipton to any state‑sponsored program, criminal consortium, or broader ideological motive; the attribution remains confined to his individual actions as a former employee of the lottery organization.

The only publicly documented operation associated with Tipton is the manipulation of the Multi-State Lottery Association’s random number generator that led to the alleged fraud surrounding the December 2010 draw and the subsequent legal proceedings initiated in 2015. This case stands as a singular example of how an individual with privileged access to a highly controlled, offline system can exploit procedural weaknesses, employ modest malware, and alter monitoring mechanisms to pursue illicit financial gain. The incident has been cited in discussions of insider threat mitigation, particularly concerning the safeguarding of critical random‑number‑generation assets in regulated industries. No further campaigns or affiliated activities have been attributed to him in open sources.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB