runaces.com Listed by qilin Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
runaces.com was listed by the Qilin ransomware group on August 14, 2025, after internal files were exfiltrated in a ransomware attack affecting an undisclosed number of people. If you have an account or other relationship with the site, review any communications from runaces.com and consider changing passwords or enabling additional account protections.
On August 14, 2025, the organisation runaces.com was listed by the ransomware group known as qilin. Public reporting indicates that internal files were exfiltrated in a ransomware attack, though the number of people affected remains unknown and many operational details have not been disclosed.
The listing itself is a claim by the group. For anyone connected to Running Aces Casino and Racetrack, the incident raises practical questions about what information may have left the organisation’s systems and what steps can reduce personal risk.
What happened
According to the available record, runaces.com was listed by the qilin ransomware group on August 14, 2025. The report states that internal files were exfiltrated during a ransomware attack. No confirmed figures have been released for the volume of data taken, the precise date the intrusion began, or the technical method used to gain access. The number of individuals affected is listed as unknown.
The group’s own summary accompanying the listing includes the statement “Finished the game. Running Aces -you're playing a losing hand” and briefly recounts that the Running Aces Casino and Racetrack opened in Columbus, Minnesota, in April 2008, noting early financial difficulties. Beyond that claim and the description of internal-file exfiltration, public detail on the incident timeline and scale remains limited.
Who is qilin?
Qilin is a ransomware group that operates under a ransomware-as-a-service model. Public reporting over recent years has documented the group’s use of double-extortion tactics: encrypting systems while also stealing data and threatening to publish it on a dedicated leak site if a ransom is not paid. The group has been observed targeting organisations across multiple sectors, often after gaining initial access through compromised credentials, phishing, or unpatched remote services.
Like other ransomware operators, qilin typically posts victim names and sample data on its leak site to increase pressure. In this case the listing of runaces.com constitutes the group’s claim; independent confirmation of the full scope of the intrusion has not been provided in the public record. No additional statements attributed specifically to this victim beyond the listing language have been verified.
Who is runaces.com?
Runaces.com is the online presence of Running Aces Casino and Racetrack, a gaming and entertainment venue that opened in Columbus, Minnesota, in April 2008. Facilities of this type combine casino gaming floors, horse racing, dining, and related hospitality services. They routinely process customer accounts, loyalty programmes, payment transactions, employee records, and operational documents.
A breach at such an organisation is consequential because casinos and racetracks handle both financial data and personal identifiers for large numbers of patrons and staff. Even when the exact contents of stolen files remain unconfirmed, the nature of the business means that internal systems commonly store information that can be misused for fraud, identity theft, or further social-engineering attacks.
What data was at risk
The public record names the exposed material only as “internal files exfiltrated in a ransomware attack.” No further breakdown of file types, databases, or record counts has been disclosed. Organisations in the casino and racetrack sector typically maintain customer account details, payment-card information, loyalty-programme data, employee personnel files, vendor contracts, and operational records. Whether any of those categories were among the files taken in this incident has not been confirmed.
Because the precise contents remain unconfirmed, it is not possible to state with certainty which specific data elements left the organisation’s control. The only established fact is that internal files were reported as exfiltrated.
What's at stake
For individuals whose information may have been among the internal files, the practical risks include unsolicited contact that uses real personal details, attempts at financial fraud, and the long-term possibility that stolen data will be sold or reused in other scams. Even partial records can be combined with information from other breaches to create more convincing impersonation attempts.
For the organisation itself, the incident carries operational, regulatory, and reputational consequences. Recovery from ransomware often involves system restoration costs, potential notification obligations, and the need to strengthen access controls and monitoring. Customers and employees may lose confidence if they later discover their data was involved. Because the number of people affected is unknown and the exact data types are unconfirmed, the full extent of these risks cannot yet be quantified from public sources.
Were you affected?
If you have held an account, worked at, or otherwise shared personal information with Running Aces Casino and Racetrack, treat the possibility of exposure seriously until more definitive information appears. Practical first steps include:
- Monitor financial statements and credit reports for unfamiliar activity.
- Change passwords used with the organisation and enable multi-factor authentication wherever available.
- Be alert to phishing messages that reference the casino or racetrack by name.
- Consider placing a fraud alert or credit freeze if you believe sensitive identifiers may have been involved.
Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets. Such scans do not prove involvement in this specific incident, but they provide an independent way to see whether personal contact details have surfaced elsewhere.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Maine Course Hospitality Group Listed by qilin Ransomware GroupMango's Tropical Cafe Listed by qilin Ransomware GroupLaloma Listed by qilin Ransomware GroupIndian Spring Country Club Listed by qilin Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the runaces.com Listed by qilin Ransomware Group →
Publicly posted by qilin — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.