Hit, a Slovenian casino and tourism operator running six casinos across Slovenia and Bosnia and Herzegovina, resumed casino operations on August 31 after a cyberattack forced a three-day shutdown that disrupted gaming systems, cash registers, and hotel operations during the week of August 25 through August 30, though some gaming functions and the loyalty system remained unavailable even after partial reopening. The company stated: “We cannot publicly comment on any further details of the information security incident because the investigation is still ongoing,” declining to disclose whether data was stolen, how attackers gained access, or if a ransom was demanded.
Hit’s Six Slovenian and Bosnian Casino Locations Forced Offline During Week of August 25-30
The cyberattack impacted Hit’s gaming systems, point-of-sale cash registers, and hotel reservation and check-in systems, forcing the operator to close all six casino locations during the approximately three-day shutdown. The decision to take casinos offline suggests the attack either encrypted critical operational systems or that Hit chose to isolate networks to prevent further compromise during investigation and remediation. The partial reopening indicates Hit restored enough functionality to resume gambling operations while still working to recover the loyalty system and some gaming functions.
Hit operates six casinos across Slovenia and Bosnia and Herzegovina, making the three-day closure a regional event affecting gambling and hospitality operations in multiple jurisdictions. The simultaneous impact across all six locations indicates the attack targeted centralized IT systems rather than individual casino networks, suggesting Hit’s gaming, point-of-sale, and hotel systems were managed through shared infrastructure vulnerable to a single compromise point.
Loyalty System and Some Gaming Functions Remain Offline Despite Partial Reopening
The continued unavailability of the loyalty system and some gaming functions even after the August 31 reopening indicates the attack’s impact was severe enough that full restoration could not be achieved within the three-day window. Loyalty systems in casino environments track customer gambling activity, manage reward points, store contact information and payment preferences, and provide operators with customer behavior analytics. The system’s offline status creates operational friction for returning customers who cannot access their reward balances or accumulated benefits, and it raises the question of whether the system was taken offline as a precaution or because it was directly targeted by the attackers.
The partial restoration of gaming functions suggests Hit prioritized bringing slot machines, table games, and other revenue-generating systems back online before fully recovering backend administrative systems like loyalty tracking. This triage approach allows the operator to resume revenue generation while continuing remediation work on less critical systems, but it also means some customer-facing services remain degraded days after the initial reopening.
Hit Declines to Disclose Attack Vector, Data Theft, or Ransom Demand Details
Hit has not disclosed whether data was stolen, how attackers gained access to its systems, or whether a ransom was demanded. No threat actor has claimed responsibility for the attack, and no attribution has been provided by the company or law enforcement. The lack of public detail on attack vector, data exfiltration, or extortion demands leaves open whether this was a ransomware encryption event, a data theft extortion attempt, or a destructive attack.
The company’s statement—”We cannot publicly comment on any further details of the information security incident because the investigation is still ongoing”—is typical of organizations conducting active forensic analysis, but it also leaves affected customers and employees without information about whether their personal or payment data was compromised. The three-day closure decision suggests Hit treated the incident as severe enough to warrant complete operational shutdown rather than attempting to continue gambling operations with degraded systems.
Three-Day Closure Represents Significant Revenue Loss for Regional Gaming Operator
The three-day closure of six casinos represents significant revenue loss and customer disruption for a major regional gaming operator. Hit’s decision to keep casinos closed for three full days rather than attempt immediate reopening suggests the company prioritized containment and forensic investigation over short-term revenue recovery. The revenue impact calculation must account for not only lost gambling and hotel revenue during the closure but also the operational costs of maintaining staff, facilities, and security without corresponding income.
The attack timing—occurring during the week of August 25 through August 30—affects whether the closure coincided with peak or off-peak gambling periods, which influences the total revenue loss. The partial reopening on August 31 allows Hit to begin recovering revenue, but the continued degradation of the loyalty system and some gaming functions means the operator is not yet operating at full capacity. The absence of a disclosed attack vector or attribution creates uncertainty for other casino and hospitality operators about what defenses would prevent similar attacks on their own operations.
