Record wins · Daily read
The Crown Casino Scam: How 33 Million Was Stolen via CCTV
An employee at Crown Casino Melbourne stole 33 million dollars by manipulating CCTV systems that monitored high-limit gaming rooms. The case reveals how insider threats exceed external security concerns.
By Wendy Cole, 3 min read
Day187
Entered under Record wins. Also under Headlines.

Seventeen years. That is how long the Crown Casino Melbourne employee stole money before getting caught. Seventeen years of walking through the same corridors, accessing the same systems, moving through the same security protocols that nobody questioned because he was staff.
The employee was an IT worker with access to the surveillance system. The high-limit gaming room had CCTV coverage, as all casinos do. The CCTV was not there to catch thieves. It was there to prevent cheating. To watch the dealers. To watch the players.
But someone with access to the CCTV system could use it for a different purpose. They could access the footage. They could delete it. They could hide evidence of certain transactions.
The scheme was simple in structure. A player (or the employee himself, the details are unclear) would exchange cash for chips in the high-limit room. The employee would delete or obscure the CCTV footage showing the transaction. Officially, the transaction never happened. The chips belonged to someone and money disappeared from the cage.
Over seventeen years, this happened enough times to accumulate 33 million dollars in losses for the casino.
How This Happened
Crown Casino Melbourne is one of the largest casinos in the world. The operational complexity is enormous. The security apparatus is substantial. But security has a weakness: it is only as good as the people implementing it.
The IT worker had clearance. He was staff. His access was monitored, but access by staff is inherently trusted. When a staff member logs into a system, they are not immediately questioned. There is an assumption that staff are vetted and trustworthy.
In reality, staff are humans. They develop financial problems. They develop gambling problems. They develop the idea that they can steal from their employer because they understand the systems so well.
The specific vulnerability was that CCTV access was centralized with IT staff. A single person with administrative access could theoretically access any footage. The casino had probably assumed that ethical standards and background checks would prevent misuse.
The assumption was wrong.
How It Was Discovered
The theft was discovered not through surveillance but through discrepancies in the cage accounting. The cage is where chips are stored. Every chip in the cage is counted and reconciled regularly. When there were more chips in the cage than should be there based on the recorded transactions, someone noticed.
Investigators began looking at CCTV footage to reconcile the discrepancy. They found gaps. Entire segments of footage were missing or corrupted. The pattern of missing footage corresponded exactly to times when the extra chips would have been brought into the cage.
From there it was a matter of investigating who had access to the CCTV system. The employee was identified. The investigation proceeded. Charges were filed.
The Broader Implications
The Crown Casino case demonstrates that insider threats can exceed external security concerns in magnitude. More money has been stolen by casino employees than by professional cheaters or organized crime in modern casinos.
But the case also demonstrates something darker: that large organizations assume their security systems are secure. The CCTV system was probably maintained by the same company that installed it. That company probably had access to all the systems. The casino probably trusted them because they had been the vendor for years.
Vendor management is a security vulnerability. When you give a vendor long-term access to your systems, you are assuming they will not abuse that access. Modern casinos now rotate vendors and limit access, but the principle remains: trust is always a security vulnerability.
Current Safeguards
Modern casinos have implemented checks specifically to prevent CCTV manipulation. Multiple people have access to different segments of the system. CCTV footage is encrypted and backed up to offsite locations. Access logs are reviewed for anomalies. If someone deletes footage, the deletion is logged and flagged.
But the fundamental vulnerability remains: people with legitimate access can abuse that access. The only real solution is to reduce the number of people with access and to monitor those people rigorously.
The Crown Casino employee stole 33 million dollars because the casino trusted him. The casino now trusts fewer people, and monitors those people more closely. But perfect security is impossible. Someone will always find a way.
End of the entry for Day 187
