SOCLYDE logo
Current languageEN
Cybersecurity newsHIT d.d.IntrusionPhishing

Hit nova gorica: intrusion closes casinos and leaves personal-data questions open

HIT d.d. Nova Gorica detected an intrusion on August 25, 2026. Here is what is known about the casino shutdown, the recovery and phishing risks for guests.

By Soclyde Team

Empty casino-hotel entrance after a business interruption

In summary

  • HIT d.d. Nova Gorica detected an intrusion on August 25, 2026; its casinos temporarily closed and the company later restored operations.
  • On September 12, HIT confirmed unauthorized access to some data while saying that the exact impact on personal data was still being assessed.
  • A message containing your name or address is not proof that it is genuine: verify through official channels and never share a password or code.

Explore next

Soclyde resources

Article contents

On August 25, 2026, HIT d.d. Nova Gorica detected a cybersecurity incident that led to unauthorized access to its information systems. The Slovenian group operates casinos, hotels and entertainment businesses; its casinos temporarily stopped operating while a forensic investigation began.

On September 12, HIT said that unauthorized access to some data had occurred and that the possibility of access to personal data was still being assessed. The public information reviewed does not establish the affected categories or the attacker’s identity. For guests, the immediate concern is therefore the possibility of convincing messages impersonating HIT.

What HIT confirmed on August 25

HIT’s initial notice places detection of the incident during the night of Monday to Tuesday, August 25. Internal teams, external experts and relevant authorities were involved, while a digital forensic investigation was tasked with determining the incident’s scope and content.

The operational consequence was immediate: the group’s casinos were not operating, while hotels continued on a limited basis. Delo listed the closed properties, including Perla and Park in Nova Gorica, as well as Mond, Korona and Casino Fontana. That list describes the situation announced that day, not a permanent scope.

From closure to gradual recovery

HIT announced on August 28 that its systems again supported the opening of the casinos. In its September 12 update, the company said that business operations had been restored, while warning that delays or limitations could still occur during the recovery process.

That sequence matters: reopening a property does not mean the forensic analysis is complete. HIT says it prioritized the security and integrity of its systems, involved law-enforcement authorities and strengthened technical and organizational safeguards.

What is known — and still uncertain — about the data

In its September 12 notice, HIT states that unauthorized access to certain data occurred. The company says some personal data may have been accessible to an unauthorized third party, but also makes clear that investigation and analysis are ongoing.

It would therefore be premature to assign a precise data list, number of people or attack method to this incident. HIT does, however, identify a plausible risk of fraud, impersonation and phishing. A message can contain a real first name, last name or address and still not have been sent by the company.

Practical steps for HIT guests

Verify every notification through the official hit.si website or the official website of the relevant property, entering the address yourself. Do not use links, phone numbers or addresses supplied in an unexpected message. HIT says it will never ask by SMS, email or phone for a password, one-time code, approval of a transaction you did not initiate or a login through an unknown link.

If you reused a password on an account connected to HIT, change it on every affected service and enable multi-factor authentication. Do not reply to suspicious messages, pay because of a message alone or discard evidence you may need when reporting an attempt.

The Soclyde connection

Soclyde does not protect HIT’s systems and cannot establish which data were accessible. Its value is upstream and during remediation: generate a different secret for every service, avoid reuse after an alert and keep credentials in an encrypted vault under local control.

For a team managing several booking, administration or guest-relations accounts, this separation reduces scattered copies and makes rotation more practical. It complements HIT’s controls and verification advice; it replaces neither the company’s investigation nor multi-factor authentication.

Key takeaway

The intrusion detected by HIT on August 25 first caused a visible casino shutdown, followed by a gradual recovery. As of September 12, the company confirmed unauthorized access to certain data without having finalized the analysis of potentially accessible personal data.

For guests, the right response is to watch for messages exploiting this news, verify outside the received channel and replace reused secrets. For a next step, read our guide to local-first password managers and contact Soclyde to discuss a suitable setup.

Frequently asked questions

What HIT customer data was exposed?

HIT says that unauthorized access to certain data occurred, but that the scope assessment is ongoing. The notice reviewed here does not provide a final list of data categories.

How can I verify a message that appears to come from HIT?

Do not use the link or phone number in the message. Open hit.si or the official website of the relevant property yourself, then use the contact details published there.

Should I change my password after this incident?

Yes, if you reused a password connected to a HIT account, email address or booking service. Choose a unique secret, enable multi-factor authentication where available and be wary of urgent requests.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading