Cyber Incident Victim: Menominee Casino Resort
Date:
Jun 2021
Location:
United States of America
Summary
Menominee Casino Resort experienced a cyberattack described as an attempted external intrusion targeting its computer systems, causing severe technical difficulties. The incident prompted a complete operational shutdown due to the significant impact, with leadership characterizing the breach as having substantial consequences. While no specific data compromise was disclosed, the resort temporarily closed all facilities to address the attack and implement recovery measures, aiming to restore normal operations within days.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On or around June 11, 2021, Menominee Casino Resort in Wisconsin experienced a cyberattack that disrupted its operations. Tribal Legislature Chairman Gunnar Peters confirmed the security breach occurred on Friday, characterizing the incident as an "attempted external attack on our computer systems" in official communications. The casino publicly acknowledged technical difficulties stemming from this attack, though it did not specify the nature of the intrusion or identify affected systems. The impact was severe enough that management deemed the situation "beyond significant," leading to an immediate operational shutdown as containment measures. All casino facilities ceased operations completely following the breach, though the organization expressed optimism about resuming services by the following Thursday, June 17. No details were provided regarding detection methods, attacker origins, or whether customer or financial data was compromised during the incident.

The complete closure represented a substantial operational disruption for the resort, though the organization did not quantify financial losses or specify which business functions were most affected. Management prioritized system security recovery over partial operations, opting for a full shutdown rather than maintaining limited services. Public statements emphasized the external origin of the attack but omitted technical specifics about attack vectors or remediation efforts. The casino maintained transparency about the closure timeframe while withholding details about forensic investigations or potential data exposure. No ransomware claims or threat actor communications were referenced in available reports. The incident marked a significant cybersecurity event for the tribal enterprise, requiring multi-day recovery efforts before anticipated restoration of normal operations.
