The Fish Were Innocent. The Aquarium Was Not.
A casino's connected aquarium reportedly transferred 10GB of data to Finland. The strange true story offers a practical lesson about overlooked network devices.
An internet-connected fish tank, a North American casino, and an unexpected destination in Finland. Sometimes the strangest device on the network is the one worth watching.
Something fishy on the network
In 2017, cybersecurity company Darktrace reported an unusual discovery at a North American casino: its internet-connected aquarium was sending data somewhere it shouldn’t.
Not fish data. Not water-temperature readings. Approximately 10 gigabytes of data had been transferred outside the casino’s network through equipment associated with the fish tank, according to Darktrace.
The destination was a device in Finland that no other company device had contacted.
The casino had presumably installed the aquarium to entertain its guests. Instead, it had acquired an unexpected second occupation: international data transfer.
The fish themselves were not identified as suspects.
The aquarium had an IT department. Sort of.
This was not an ordinary glass tank with a bubbling plastic treasure chest.
According to Darktrace’s account, the casino had installed a high-tech aquarium with connected sensors that helped regulate temperature, salinity, and feeding schedules. Its equipment needed to communicate electronically so that the aquarium could be monitored and maintained.
That made it another network-connected system.
The casino had even configured the aquarium’s communications through a separate virtual private network, or VPN, in an effort to isolate its data.
Nevertheless, Darktrace reported detecting unusually large transfers from the aquarium equipment to an external destination.
A fish tank needs to exchange some information to keep its occupants comfortable. Ten gigabytes heading to an unfamiliar destination is a rather different level of conversation.
The precise attack sequence was not made public. In particular, Darktrace did not establish in its published account exactly how the attackers initially gained access to the casino’s systems or what the transferred data contained.
That distinction matters. The aquarium was involved in the reported data transfer; the commonly repeated claim that attackers first entered the casino through the fish tank goes further than the published technical details conclusively establish.
The casino has not been publicly identified. Finland was the reported destination of the transfer, not a confirmed location of the attackers.
Those uncertainties don’t make the incident less interesting. They simply prevent us from turning a strange cybersecurity case into a fictional heist movie.
Your office probably has a fish tank, too.
Perhaps not a literal one.
But consider the things that connect to a modern business network: security cameras, smart televisions, conference-room equipment, printers, thermostats, access-control systems, and devices installed by outside vendors.
Each may have a perfectly reasonable job. Each may also contain a small computer, software that needs updating, credentials, and some way to communicate with other systems.
The problem is not that connected devices are inherently bad. A remotely monitored aquarium is a perfectly sensible idea if you operate an aquarium.
The problem begins when nobody is quite sure which devices are connected, who maintains them, or what they can reach.
A business might spend considerable time protecting its servers and employee computers while giving much less thought to a device installed by the company that services its building.
The device doesn’t need to contain valuable information itself to become relevant to the security of everything around it.
Three questions worth asking before the next fish tank arrives
There is no need to ban smart equipment or turn every office into a cybersecurity laboratory.
A more useful starting point is to establish who is responsible for connected equipment and what access it actually requires.
When a vendor installs a camera system, environmental controller, or other connected device, ask what it connects to and whether it needs access to the same network as business-critical systems.
Find out who maintains its software, controls its administrator credentials, and can connect to it remotely.
Then make sure someone responsible for the business’s IT understands that the device exists.
Those questions won’t prevent every security incident. They can, however, expose an uncomfortable category of risk: equipment that everyone assumes somebody else is managing.
The fish weren’t the problem
The aquarium story is memorable because a fish tank is such an unlikely participant in a data-security incident.
But the underlying issue is ordinary.
Businesses depend on technology installed and maintained by many different people, for many different purposes. Over time, it becomes surprisingly easy to lose track of which systems are connected and where responsibility for them begins and ends.
The lesson is not to distrust fish.
It’s to remember that the strange little device in the corner may be a computer, too.
And if it starts sending ten gigabytes of data to Finland, somebody should probably ask why.
Sources
- The Washington Post — “How a fish tank helped hack a casino” (July 21, 2017)
- SecurityWeek — “Hacked Smart Fish Tank Exfiltrated Data to ‘Rare External Destination’” (July 26, 2017)
- Wired — “You used to build a wall to keep them out, but now hackers are destroying you from the inside” (June 25, 2018)
