Risk
7/2/2008
07:07 PM
Connect Directly
LinkedIn
Twitter
Google+
RSS
E-Mail
50%
50%

High-Tech Card Cheat Pleads Guilty

One of the devices used by the group was a wireless transmitter to anticipate the cards players would be dealt, according to a Justice Department indictment.

Between March 2003 and July 2006, the Tran Organization -- a group of high-tech card cheats -- scammed casinos around the country for about $7 million. On one occasion, they made $868,000 in about 90 minutes.

On Tuesday, the U.S. Department of Justice said that Son Hong Johnson, one of the members of the group, had pleaded guilty to cheating casinos around the country. He is the 11th defendant to plead guilty out of 13 individuals named in an indictment returned on May 22, 2007.

One of the defendants, Han Truong Nguyen, was sentenced in May to 27 months in prison and ordered to pay $1,896,659 in restitution. The remanding defendants await sentencing. Johnson is scheduled to be sentenced in December.

According to the indictment, the group would bribe card dealers at casinos to create a false shuffle that returned a group of cards to the deck in a known order. This "slug" of cards enabled Tran members to anticipate the cards players would be dealt.

One member of the group would act as "card recorder" and would note at least some of the cards dealt during the course of play. "During mini-baccarat games, the card recorder usually would record the value of the cards on a paper form the casino provided to mini-baccarat players in the normal course of play," the indictment said. "In blackjack games, the card recorder would use a hidden transmitter or microphone and a cellular telephone to relay the order of the cards to an enterprise member or associate, who would enter the order of the cards into a computer program loaded with a specially designed card tracking computer program."

One of the devices used by the group was a wireless transmitter purchased from the Spy Shops of the U.S. and Canada. The indictment does not specifically name the device used, but it may have been what the site calls the wireless in-ear cellular communicator ($950), which is designed for covert communication.

The group didn't always win. Indeed, the indictment said that the group sometimes lost intentionally to deflect suspicion. In addition, members sometimes made mistakes in the execution of their scheme, resulting in losses.

Members of the group often cashed out with gambling winnings of less than $10,000 to avoid federal reporting requirements.

Still, they weren't careful enough. The indictment does not specify how the group was finally identified and caught, but it may have had something to do with an attempt to fleece the Imperial Palace Casino in Biloxi, Miss., that went awry.

In June 2006, one of the defendants attempted to bribe an undercover agent at the Imperial Palace. That's the sort of misstep that's likely to bring unwanted attention from law enforcement authorities.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Latest Comment: nice one
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-0845
Published: 2015-04-17
Format string vulnerability in Movable Type Pro, Open Source, and Advanced before 5.2.13 and Pro and Advanced 6.0.x before 6.0.8 allows remote attackers to execute arbitrary code via vectors related to localization of templates.

CVE-2015-0967
Published: 2015-04-17
Multiple cross-site scripting (XSS) vulnerabilities in SearchBlox before 8.2 allow remote attackers to inject arbitrary web script or HTML via (1) the search field in plugin/index.html or (2) the title field in the Create Featured Result form in admin/main.jsp.

CVE-2015-0968
Published: 2015-04-17
Unrestricted file upload vulnerability in admin/uploadImage.html in SearchBlox before 8.2 allows remote attackers to execute arbitrary code by uploading a file with an executable extension and the image/jpeg content type, a different vulnerability than CVE-2013-3590.

CVE-2015-0969
Published: 2015-04-17
SearchBlox before 8.2 allows remote attackers to obtain sensitive information via a pretty=true action to the _cluster/health URI.

CVE-2015-0970
Published: 2015-04-17
Cross-site request forgery (CSRF) vulnerability in SearchBlox before 8.2 allows remote attackers to hijack the authentication of arbitrary users.

Dark Reading Radio
Archived Dark Reading Radio
Join security and risk expert John Pironti and Dark Reading Editor-in-Chief Tim Wilson for a live online discussion of the sea-changing shift in security strategy and the many ways it is affecting IT and business.