Key takeaways
- The combination of casino revenue, sensitive member data and critical infrastructure makes tribal governments an attractive target for cybercriminals.
- Effective cybersecurity for tribes requires multiple layers of defense, including phishing-resistant MFA, continuous monitoring, immutable backups, regular penetration testing and ongoing employee training.
- For tribes, the risk is bigger than financial loss and disruption to services. Culturally and historically significant files could be lost in an attack.
Cybercrime continues to plague the U.S., and the problem is only accelerating. According to the 2025 FBI Internet Crime Report, there were 1,008,597 cybercrime complaints filed in the year. That is the biggest number on record.
No industry or government body is safe from a cyberattack. This includes tribal governments and the businesses they operate, particularly casinos. In this environment, investing in cybersecurity isn’t an option. You shouldn’t be asking if you’ll be attacked, but rather when and if you’ll be ready.
Keep reading to learn steps your tribe can take to bolster its cybersecurity posture.
Why tribes must take cybersecurity seriously
Nearly 90 tribes nationwide own and operate broadband networks. It’s common for critical infrastructure managed by tribes, such as water treatment facilities and healthcare centers, to be connected. Tribal businesses, such as casinos and resorts, also rely on the internet to deliver services and manage day-to-day operations. Add it all together and tribes have a large attack surface that bad actors can target.
Tribes hold sensitive data of their members and customers that need to be protected. There’s also invaluable cultural heritage data that could be compromised in an attack.
From critical services to members being disrupted to financial information being stolen, the consequences of a cyberattack could be disastrous for a tribe. A cybersecurity program that is regularly tested is a must for tribes to protect their communities.
Why do cybercriminals target tribes?
The reason tribes are targeted is simple: they run high-dollar businesses, manage critical infrastructure and possess sensitive data. The information or infrastructure that attackers could attempt to compromise includes:
Financial data
Tribal casinos, resorts and other businesses generate significant revenue. As a result, they hold large amounts of credit card numbers, bank routing information, gaming loyalty program data and more.
Examples of attacks on tribal casinos include:
- Several Kewadin Casinos locations were forced to temporarily close following an attack.
- A ransomware attack impacted gaming operations and other tribal services for the Lower Sioux Indian Community.
Tribal enrollment and membership records
Tribes hold a significant amount of their members’ Personally Identifiable Information (PII), including names, Social Security numbers, dates of birth, physical addresses and potentially even biometric data.
Financial records linked to distributions, tribal housing assistance funds and more could also be compromised if your tribe is the victim of an attack.
Healthcare records
Many tribes manage independent medical centers via the Indian Health Service (IHS) or localized tribal health networks. As a result, they possess protected health information (PHI). In addition to the ethical need to protect their members’ health records, holding PHI means tribes must comply with HIPAA.
Disruption of critical services
Some cyberattacks are carried out simply to create chaos. Tribes provide a variety of essential services to their communities, and their disruption could upend day-to-day life. Services that are vulnerable to an attack include:
- Health centers
- Police, fire and emergency dispatch centers
- Emergency alerting systems
- Utilities, including water and power
- Social services such as housing and welfare programs
Cultural heritage and language assets
Hackers can also target a tribe’s digital archives. If successful, they can hold your cultural and historical files ransom.
It took the Eastern Band of Cherokee Indians eight months to recover audio and video recordings of tribal members speaking their native language after they were stolen in a ransomware attack.
Other valuable assets could include digital copies of sacred artifacts, geographic land boundaries, water rights documents and historical government treaties.
What cybersecurity actions should tribes take?
Here are seven ways tribes can mitigate cyber risks across their government and business operations:
1. Multi-factor authentication (MFA)
MFA remains one of the most effective controls a tribe can deploy, but not all MFA is equal. SMS-based codes, in which an access code is texted to a cell phone, are now considered a weaker form of MFA due to SIM-swapping attacks, in which criminals convince a carrier to transfer your phone number to a device they control.
Tribes should prioritize a phishing-resistant MFA, such as FIDO2 hardware security keys or authenticator apps that generate time-based codes. These methods help prevent the most common cyberattacks, including phishing, credential stuffing and adversary-in-the-middle (AiTM) attacks, a newer technique that attackers use to bypass traditional MFA by intercepting authentication sessions in real time.
2. Penetration testing
Penetration testing simulates real-world attacks against your systems, applications and people. A pen test will expose vulnerabilities in your security that hackers may exploit. For example, the third-party firm you hire to perform penetration testing might create simulated phishing emails to look for insufficient updates and improper protection processes.
3. Real-time detection
If you’re only relying on traditional endpoint protection tools (e.g., firewalls and antivirus software), security attacks and data breaches may go undetected for weeks or months. These are reactive security measures developed to counter known security threats.
Two technologies now define the current standard for proactive threat detection:
- Security information and event management (SIEM) collects and aggregates log data from across your environment, networks, endpoints, applications, identity systems and cloud platforms and correlates that data in real time to surface suspicious patterns. Unlike a firewall that only sees what crosses its perimeter, a SIEM sees across your entire operation simultaneously. For a tribal organization running a casino, a health center, a broadband network and a government services portal, that breadth of visibility is critical. A SIEM might flag that the same user account logged in from two geographic locations within minutes, that a privileged account accessed an unusual volume of enrollment records overnight, or that outbound traffic is communicating with a known malicious IP address.
- Managed detection and response (MDR) pairs that technology with human security analysts operating around the clock. MDR platforms use extended detection and response (XDR) capabilities to correlate signals across endpoints, networks, cloud environments and identity systems. Trained analysts investigate alerts, separate genuine threats from false positives and take containment action when needed. AI-driven behavioral analysis has become central to this discipline, enabling faster detection of multi-stage attacks that automated rules alone would miss.
Used together, SIEM and MDR close the visibility and response gaps left by legacy tools. For tribes that cannot hire a full security staff, outsourcing MDR to a specialized provider delivers 24/7 coverage without the operational overhead. While the SIEM ensures analysts have the full environment data they need to act quickly and decisively.
4. Patches and updates
Hackers know how to exploit vulnerabilities in systems, applications and processes. Patches and updates fix code defects and close these vulnerabilities. Make sure a member of your IT team is monitoring software and frequently pushing updates and patches.
5. Cybersecurity insurance
When assessing your insurance needs, make sure to consider obtaining cybersecurity insurance. Appropriate coverage helps prevent your tribe from being left in a vulnerable security posture with much to lose.
6. Backup and recovery
Ransomware attacks are increasingly looking for backup files to encrypt so they can prevent access to any data until the ransom is paid. Your tribes should have a data backup recovery process in place that includes air-gapped, immutable data protection. These are offline copies of data, which makes them secure, recoverable and unable to be altered or changed. By keeping an archive of immutable backups, you can recover from a ransomware attack much easier and faster — without having to pay the ransom.
7. Cybersecurity training
Employees remain a primary target in cyberattacks, and the attacks they face are becoming more sophisticated. AI-generated phishing emails are now grammatically flawless, personalized and increasingly indistinguishable from legitimate communications. Deepfake audio and video are being used in vishing (voice phishing) attacks, in which criminals impersonate executives or vendors to obtain authorization for fraudulent wire transfers or credential resets.
A modern security awareness program needs to include:
- Simulated phishing campaigns: Regularly send realistic test phishing emails to employees and use failures as teaching moments rather than punitive ones.
- Role-based training: Tailor training to specific departments. Finance staff need training on wire fraud and business email compromise. HR staff need training on W-2 and direct deposit scams. IT staff need training specific to their elevated access privileges.
- Insider threat awareness: Not all threats are external; employees need to understand access control principles and report unusual activity.
- Frequent updates: Training content must evolve as threats evolve. New employees must be trained before they have access to tribal systems, not weeks after onboarding.
Cybersecurity for tribes FAQs
Here are answers to some frequent asked questions about cybersecurity for tribes:
Why are tribal governments targeted by cyberattacks?
Tribal governments are high-value targets because they combine the financial assets of a business with the sensitive data holdings of a government entity. Tribal casinos and resorts generate significant revenue and process large volumes of credit card transactions, gaming loyalty data and financial records that are attractive to financially motivated attackers. At the same time, tribes hold personally identifiable information (PII) on their members and protected health information (PHI) through tribal health centers.
Tribes also operate critical infrastructure, including broadband networks, water utilities and emergency services that hackers may target to cause disruption.
The scale of that attack surface, often managed with lean IT and security resources, makes tribal governments a frequent and deliberate target.
How often should tribes conduct cybersecurity assessments?
At a minimum, tribes should conduct a comprehensive cybersecurity risk assessment annually, but the threat environment has evolved to the point where annual reviews alone are not sufficient. Penetration tests should be performed at least once a year, with targeted retesting any time a significant system change, new technology deployment or major business expansion occurs. Ongoing attack surface management and continuous vulnerability scanning should run between formal assessments to catch newly discovered exposures before attackers do.
Tribes that operate casinos, health centers or broadband networks, each of which carries its own regulatory and compliance obligations, may need assessments on a more frequent cycle to remain in good standing with applicable requirements.
Think of cybersecurity assessment not as a calendar event but as a continuous process with periodic formal checkpoints.
What is the biggest cybersecurity risk for tribal organizations today?
The single greatest cybersecurity risk facing tribal organizations today is human error. Specifically, the success rate of phishing and social engineering attacks as an initial entry point into tribal systems.
Attackers no longer need to find a technical vulnerability when a convincing email, text message or AI-generated voice call can trick an employee into handing over credentials or directly authorizing a fraudulent transaction. Once inside, attackers move laterally across connected systems, often going undetected for weeks.
The growing use of generative AI by threat actors has made phishing messages harder to identify, removing the spelling errors and awkward phrasing that employees were historically trained to spot. Addressing this risk requires a combination of phishing-resistant MFA, continuous security awareness training and robust detection capabilities that can identify suspicious behavior even after credentials have been compromised.
How can tribes prepare for ransomware attacks?
Preparing for ransomware requires a layered strategy that addresses prevention, detection and recovery.
On the prevention side, tribes should enforce phishing-resistant MFA on all accounts, maintain a disciplined patch management program and limit user access privileges so that a compromised account cannot move freely across systems.
For detection, managed detection and response (MDR) combined with a SIEM gives security teams the visibility to identify ransomware staging activity, such as large-scale file enumeration or backup deletion, before encryption begins.
Recovery preparedness centers on maintaining tested, air-gapped and immutable backups, so that data can be restored without paying a ransom. Equally important is a documented incident response plan that has been rehearsed through tabletop exercises, ensuring tribal leadership, IT staff, legal counsel and communications teams each know their role the moment an attack is confirmed.
Read more
- AI for tribes: Managing risk and maximizing impact
- How GASB 103 and GASB 104 will impact tribal governments
- Your tribal organization just implemented a new ERP. How do you maximize the success of your investment?
Cybersecurity experience is important, and tribes should consider outsourcing certain projects like penetration testing and 24/7 detection and response. Wipfli provides a full range of industry-tailored cybersecurity services to help you proactively address mounting threats with the right technology. As the past has shown us, no single cyber solution is foolproof, but mitigating risk by employing the above steps goes a long way toward advancing a tribe’s security posture. Improve your tribe’s cybersecurity.
