Skip to the page
Big Wins

Ron Harris: The Gaming Control Agent Who Rigged Keno Machines

The Ron Harris case is the most underrated insider-fraud story in gambling. A regulator with source code access. A keno scam. A partner who won a 100k jackpot and immediately got himself arrested. The structural lessons are the point.

By Lucia Ferreira4 min read
a keno machine opened up showing rigged internal wiring alongside a gaming control agent badge

The Ron Harris story is the single cleanest case study in gambling of what happens when your regulator is also your attacker.

Harris worked for the Nevada Gaming Control Board from 1988 to 1995. His job was testing slot machine software for compliance. His position gave him source code access to machines on the floor of every casino in the state. That is the whole setup. The rest is what you would expect.

He wrote a modification to specific IGT keno machines that would produce a predictable outcome when a specific sequence of coin denominations was inserted. Then he had an accomplice, Reid Errol McNeal, visit the casino and play the sequence.

McNeal won a $100,000 keno jackpot at Bally's in Atlantic City in 1995. He then made the following choices:

  • Did not claim a casino host
  • Did not fill out the tax paperwork normally
  • Had no identifiable pattern of prior keno play
  • Appeared visibly uncomfortable through the entire win payout process

The casino flagged him within an hour. He was arrested the same night. The subsequent investigation unraveled Harris's entire operation, including earlier scams on blackjack machines in Nevada.

The Actual Thesis

The Harris case is not a story about one bad actor. It is a story about how assumption-of-trust in gaming regulation is structurally load-bearing.

The testing regime was built on the premise that GCB employees were inherently trustworthy because they had to be. There was no code review of Harris's work. There was no second-person verification on his access to production software. The entire system assumed that the regulator was the safe part of the pipeline (foreshadowing: it was not).

This is the same mistake that has caused about 80 percent of all sophisticated financial fraud since the SEC was founded. The insider who is too trusted to audit is always the insider who, eventually, gets audited first by investigators rather than by colleagues.

What Actually Changed

Not as much as you would think.

The Nevada GCB did implement additional review layers on source code work after Harris. Some of them are real. Some of them are paperwork. The fundamental fact that a small number of people at regulatory bodies have extensive access to gaming software has not structurally changed, because there is no cheap way to change it. You need specialists to test the code. Specialists are rare. Specialists are, by definition, hard to check without other specialists.

IGT, Bally, and their competitors have moved to more modern software stacks with better auditing built in. But the basic problem of trusted insiders with code access is an inherent feature of how slot machines get certified.

The Counter-Argument I'll Concede

The obvious pushback is that Harris got caught. The system worked. The casino flagged McNeal. The investigation unraveled the scheme. End of story, regulation wins.

That reads the evidence backwards. Harris got caught because his accomplice was incompetent (the McNeal claim process was comically suspicious; any functional fraud ring teaches its cashout people to blend in). He did not get caught by the testing regime. He got caught by a paranoid cage manager at Bally's.

If Harris had used a more competent accomplice, or cashed out $5,000 at a time over months, there is no obvious regulatory mechanism that would have caught him at scale. The system did not detect the scheme. The scheme detected itself through operational error.

The Generalizable Lesson

If you are an investor in gaming companies, an auditor, a regulator, or just a gambler who wants to understand where the structural risk actually lives, Harris's case argues the following:

  1. The attack surface in regulated gambling is the regulator's own software access, not the casino's floor operations.

  2. Detection happens at the cashout stage, not the gameplay stage. Every successful casino fraud story gets caught during the money-moves-out phase because that is where the scrutiny is.

  3. Insider fraud scales with access, not with skill. Harris was not a brilliant programmer. He was a competent one with unusual privileges. The privilege was the weapon.

The footnote here is that the Harris machines were removed after the scheme was exposed, but the underlying certification process that allowed Harris to plant them was adjusted rather than rebuilt. If you believe that a similar scheme could not happen today, you are putting a lot of faith in HR hiring practices at gaming regulators (which, in my professional opinion, is misplaced).

The safest assumption about any trusted-insider system is that it has already been partially compromised and you just have not noticed.

Ron Harris served seven years in prison. McNeal served less. IGT recovered the affected machines. Nobody involved in the case became particularly famous, which is strange given how clean a case study it is. The Harris story remains the single best argument for code review regimes in gaming compliance, and the fact that this argument has not been fully won in 30 years is itself a data point.