Modern crime in Sin City depends on phones, cameras, access systems, financial records, vehicle data, wireless networks, and online accounts.
Use D&D 5e ability checks as the foundation. Hacking should require time, access, equipment, knowledge, and a believable target.
A successful check should provide only the access the character actually earned.
Most hacking attempts use Intelligence, usually with proficiency from a relevant class, background, tool, or feature.
Possible approaches include:
Direct system access
Stolen credentials
Phishing
Social engineering
Malware
Hardware tampering
Network intrusion
Password recovery
Exploiting poor security
Suggested DCs:
DC 10: Weak password or unsecured device
DC 12: Ordinary personal or small-business system
DC 15: Professional security or restricted records
DC 18: Corporate, police, casino, or government network
DC 20+: Highly protected, isolated, or actively monitored system
Franz should adjust for preparation, equipment, physical access, security quality, and current alerts.
Digital access should be limited by what the character actually compromises.
Possible access levels include:
Public information
User account
Employee account
Administrator access
Security controls
Restricted archives
Isolated systems
Access to one account does not automatically grant control over the entire network.
Simple actions may take one action or a few minutes. Complex intrusions may require hours, repeated checks, or physical access.
Preparation may include:
Learning employee names
Studying system layouts
Obtaining passwords
Planting a device
Stealing an access card
Creating a false identity
Entering through a trusted network
Recruiting an insider
Good preparation may reduce the DC, grant advantage, shorten the attempt, or prevent detection.
Failure should create a consequence appropriate to the system.
Possible consequences include:
Access denied
Account lockout
Security alert
Logged activity
Traced device
Corrupted data
Lost time
Increased Heat
Security response
False or incomplete information
Failure does not always mean immediate arrest. It may instead leave evidence that becomes important later.
Phones may contain:
Messages
Contacts
Photos
Location history
Banking information
Authentication codes
Browsing history
Recorded calls
Application data
Access may require a passcode, biometric unlock, account credentials, forensic tools, or cooperation from the owner.
Destroying the phone does not automatically erase cloud backups, carrier records, or messages stored on other devices.
Surveillance may include:
Public cameras
Casino systems
Police cameras
Traffic cameras
Doorbell cameras
Corporate security
Private residences
Vehicle cameras
Hidden recording devices
Camera coverage should depend on location. Wealthy, government, casino, and corporate districts usually have stronger surveillance than neglected streets.
Cameras may identify clothing, vehicles, movement, weapons, associates, or direction of travel without always providing a clear face.
Characters may avoid or reduce surveillance through:
Masks
Changed clothing
Alternate routes
Poorly covered entrances
Crowds
Weather
Lighting
Camera tampering
Insider assistance
Temporary power loss
Avoiding one camera does not guarantee avoiding every witness or recording system.
Alarm systems may protect:
Doors
Windows
Safes
Server rooms
Vehicles
Restricted floors
Warehouses
Homes
Casinos
Government facilities
Alarms may trigger:
Audible sirens
Silent notifications
Locked doors
Camera focus
Security dispatch
Police notification
Data preservation
Remote shutdown
Franz should establish whether an alarm is visible, hidden, monitored, or local.
Disabling an alarm may require:
Technical knowledge
Physical access
Credentials
Tools
Cutting power
Network intrusion
Replacing a sensor
Looping a camera feed
Insider cooperation
Cutting power may activate backup batteries, emergency lighting, or automatic alerts.
Electronic security may use:
Keycards
PIN codes
Biometrics
Mobile credentials
Time-based access
Security desks
Two-person authorization
A stolen card may still require a PIN, matching identity, or active employment status.
Access records may later reveal who entered, when, and through which door.
Social engineering uses deception rather than direct technical intrusion.
Examples include:
Impersonating staff
Requesting a password reset
Sending a false invoice
Claiming an emergency
Creating a fake support call
Following an employee through a secure door
Persuading someone to open a file
These attempts may use Charisma skills, Intelligence checks, forged documents, or a combination.
A successful deception may provide credentials or access without defeating the system itself.
Digital evidence may include:
Messages
Emails
Access logs
Camera footage
Location records
Financial transactions
Search history
Deleted files
Cloud backups
Vehicle telemetry
Call records
Network logs
Digital evidence can connect people, places, devices, money, and timelines.
It should rarely solve an entire case by itself without interpretation or supporting evidence.
Deleted information may still survive in:
Backups
Cloud storage
Archived systems
Recipient devices
Temporary files
Provider records
Forensic recovery
Altering records may leave inconsistencies, timestamps, missing entries, or unusual access logs.
Destroying one device does not erase every copy.
Encryption protects information from casual access.
Breaking strong encryption may require:
Stolen credentials
The unlocked device
An insider
Specialized equipment
A software vulnerability
Extended time
Legal authority
Coercion
A single successful Intelligence check should not instantly defeat every encrypted system.
Investigators may identify a hacker through:
Login records
Device identifiers
Network addresses
Camera footage
Payment records
Reused tools
Writing patterns
Informants
Physical devices
Access timing
Using public networks, stolen devices, or indirect connections may complicate attribution without making it impossible.
Police, casinos, government agencies, and Cortech Industries may maintain:
Security teams
Intrusion detection
Activity logs
Network isolation
Backups
Incident-response plans
Employee monitoring
Access audits
Powerful organizations may investigate quietly before confronting a suspected intruder.
They may watch compromised accounts, feed false information, or trace future activity.
Criminal factions may use:
Lookouts
Stolen cameras
Phone tracking
Bribed employees
Vehicle trackers
Informants
Social-media monitoring
Compromised accounts
Their systems may be less advanced than corporate networks but more difficult to predict because they rely on people and informal methods.
Digital Heat represents how strongly suspicious online activity is connected to a person, device, account, or crew.
Digital Heat may increase through:
Repeated intrusions
Failed login attempts
Reused devices
Recognizable methods
Compromised accounts
Public leaks
Attacks on powerful organizations
Leaving planted hardware behind
Possible consequences include account monitoring, device tracing, false information, police interest, corporate retaliation, or faction pressure.
Digital Heat may be reduced through:
Abandoning compromised devices
Changing accounts
Using clean equipment
Allowing time to pass
Removing planted hardware
Redirecting suspicion
Falsifying logs
Bribing insiders
Destroying evidence
Changing methods
These actions may reduce risk but should not automatically erase evidence already copied or reported.
Simple digital actions during combat may include:
Opening a door
Triggering an alarm
Disabling a camera
Locking an elevator
Activating lights
Accessing a nearby terminal
These usually require prior access, a connected device, and an action.
Complex network intrusion should not normally be completed during one combat round without a specific feature.
Players may:
Steal security footage
Disable an alarm
Trace a phone
Plant a tracker
Forge access credentials
Expose financial fraud
Recover deleted records
Frame another hacker
Protect a witness’s identity
Leak evidence
Infiltrate a corporate network
Discover who altered official records
These situations should support technical skill, investigation, deception, stealth, and physical infiltration.
Franz should establish:
The target system
Required access
Available equipment
Time required
Security level
Possible evidence
Detection risk
Consequences of failure
Digital actions should reveal useful information and create new choices without functioning as automatic answers to every problem.