• Overview
  • Map
  • Areas
  • Points of Interest
  • Characters
  • Races
  • Classes
  • Factions
  • Monsters
  • Items
  • Spells
  • Feats
  • Quests
  • One-Shots
  • Game Master
  1. Sin City
  2. Lore

04. Hacking, Surveillance, Alarms, and Digital Evidence

Digital Systems Overview

Modern crime in Sin City depends on phones, cameras, access systems, financial records, vehicle data, wireless networks, and online accounts.

Use D&D 5e ability checks as the foundation. Hacking should require time, access, equipment, knowledge, and a believable target.

A successful check should provide only the access the character actually earned.

Hacking Checks

Most hacking attempts use Intelligence, usually with proficiency from a relevant class, background, tool, or feature.

Possible approaches include:

  • Direct system access

  • Stolen credentials

  • Phishing

  • Social engineering

  • Malware

  • Hardware tampering

  • Network intrusion

  • Password recovery

  • Exploiting poor security

Suggested DCs:

  • DC 10: Weak password or unsecured device

  • DC 12: Ordinary personal or small-business system

  • DC 15: Professional security or restricted records

  • DC 18: Corporate, police, casino, or government network

  • DC 20+: Highly protected, isolated, or actively monitored system

Franz should adjust for preparation, equipment, physical access, security quality, and current alerts.

Access Levels

Digital access should be limited by what the character actually compromises.

Possible access levels include:

  • Public information

  • User account

  • Employee account

  • Administrator access

  • Security controls

  • Restricted archives

  • Isolated systems

Access to one account does not automatically grant control over the entire network.

Time and Preparation

Simple actions may take one action or a few minutes. Complex intrusions may require hours, repeated checks, or physical access.

Preparation may include:

  • Learning employee names

  • Studying system layouts

  • Obtaining passwords

  • Planting a device

  • Stealing an access card

  • Creating a false identity

  • Entering through a trusted network

  • Recruiting an insider

Good preparation may reduce the DC, grant advantage, shorten the attempt, or prevent detection.

Failed Hacking Attempts

Failure should create a consequence appropriate to the system.

Possible consequences include:

  • Access denied

  • Account lockout

  • Security alert

  • Logged activity

  • Traced device

  • Corrupted data

  • Lost time

  • Increased Heat

  • Security response

  • False or incomplete information

Failure does not always mean immediate arrest. It may instead leave evidence that becomes important later.

Phones and Personal Devices

Phones may contain:

  • Messages

  • Contacts

  • Photos

  • Location history

  • Banking information

  • Authentication codes

  • Browsing history

  • Recorded calls

  • Application data

Access may require a passcode, biometric unlock, account credentials, forensic tools, or cooperation from the owner.

Destroying the phone does not automatically erase cloud backups, carrier records, or messages stored on other devices.

Cameras and Surveillance

Surveillance may include:

  • Public cameras

  • Casino systems

  • Police cameras

  • Traffic cameras

  • Doorbell cameras

  • Corporate security

  • Private residences

  • Vehicle cameras

  • Hidden recording devices

Camera coverage should depend on location. Wealthy, government, casino, and corporate districts usually have stronger surveillance than neglected streets.

Cameras may identify clothing, vehicles, movement, weapons, associates, or direction of travel without always providing a clear face.

Surveillance Blind Spots

Characters may avoid or reduce surveillance through:

  • Masks

  • Changed clothing

  • Alternate routes

  • Poorly covered entrances

  • Crowds

  • Weather

  • Lighting

  • Camera tampering

  • Insider assistance

  • Temporary power loss

Avoiding one camera does not guarantee avoiding every witness or recording system.

Alarms

Alarm systems may protect:

  • Doors

  • Windows

  • Safes

  • Server rooms

  • Vehicles

  • Restricted floors

  • Warehouses

  • Homes

  • Casinos

  • Government facilities

Alarms may trigger:

  • Audible sirens

  • Silent notifications

  • Locked doors

  • Camera focus

  • Security dispatch

  • Police notification

  • Data preservation

  • Remote shutdown

Franz should establish whether an alarm is visible, hidden, monitored, or local.

Disabling Alarms

Disabling an alarm may require:

  • Technical knowledge

  • Physical access

  • Credentials

  • Tools

  • Cutting power

  • Network intrusion

  • Replacing a sensor

  • Looping a camera feed

  • Insider cooperation

Cutting power may activate backup batteries, emergency lighting, or automatic alerts.

Electronic Locks and Access Cards

Electronic security may use:

  • Keycards

  • PIN codes

  • Biometrics

  • Mobile credentials

  • Time-based access

  • Security desks

  • Two-person authorization

A stolen card may still require a PIN, matching identity, or active employment status.

Access records may later reveal who entered, when, and through which door.

Social Engineering

Social engineering uses deception rather than direct technical intrusion.

Examples include:

  • Impersonating staff

  • Requesting a password reset

  • Sending a false invoice

  • Claiming an emergency

  • Creating a fake support call

  • Following an employee through a secure door

  • Persuading someone to open a file

These attempts may use Charisma skills, Intelligence checks, forged documents, or a combination.

A successful deception may provide credentials or access without defeating the system itself.

Digital Evidence

Digital evidence may include:

  • Messages

  • Emails

  • Access logs

  • Camera footage

  • Location records

  • Financial transactions

  • Search history

  • Deleted files

  • Cloud backups

  • Vehicle telemetry

  • Call records

  • Network logs

Digital evidence can connect people, places, devices, money, and timelines.

It should rarely solve an entire case by itself without interpretation or supporting evidence.

Deleted and Altered Data

Deleted information may still survive in:

  • Backups

  • Cloud storage

  • Archived systems

  • Recipient devices

  • Temporary files

  • Provider records

  • Forensic recovery

Altering records may leave inconsistencies, timestamps, missing entries, or unusual access logs.

Destroying one device does not erase every copy.

Encryption

Encryption protects information from casual access.

Breaking strong encryption may require:

  • Stolen credentials

  • The unlocked device

  • An insider

  • Specialized equipment

  • A software vulnerability

  • Extended time

  • Legal authority

  • Coercion

A single successful Intelligence check should not instantly defeat every encrypted system.

Tracing and Attribution

Investigators may identify a hacker through:

  • Login records

  • Device identifiers

  • Network addresses

  • Camera footage

  • Payment records

  • Reused tools

  • Writing patterns

  • Informants

  • Physical devices

  • Access timing

Using public networks, stolen devices, or indirect connections may complicate attribution without making it impossible.

Police and Corporate Cybersecurity

Police, casinos, government agencies, and Cortech Industries may maintain:

  • Security teams

  • Intrusion detection

  • Activity logs

  • Network isolation

  • Backups

  • Incident-response plans

  • Employee monitoring

  • Access audits

Powerful organizations may investigate quietly before confronting a suspected intruder.

They may watch compromised accounts, feed false information, or trace future activity.

Surveillance by Criminal Factions

Criminal factions may use:

  • Lookouts

  • Stolen cameras

  • Phone tracking

  • Bribed employees

  • Vehicle trackers

  • Informants

  • Social-media monitoring

  • Compromised accounts

Their systems may be less advanced than corporate networks but more difficult to predict because they rely on people and informal methods.

Digital Heat

Digital Heat represents how strongly suspicious online activity is connected to a person, device, account, or crew.

Digital Heat may increase through:

  • Repeated intrusions

  • Failed login attempts

  • Reused devices

  • Recognizable methods

  • Compromised accounts

  • Public leaks

  • Attacks on powerful organizations

  • Leaving planted hardware behind

Possible consequences include account monitoring, device tracing, false information, police interest, corporate retaliation, or faction pressure.

Reducing Digital Heat

Digital Heat may be reduced through:

  • Abandoning compromised devices

  • Changing accounts

  • Using clean equipment

  • Allowing time to pass

  • Removing planted hardware

  • Redirecting suspicion

  • Falsifying logs

  • Bribing insiders

  • Destroying evidence

  • Changing methods

These actions may reduce risk but should not automatically erase evidence already copied or reported.

Hacking During Combat

Simple digital actions during combat may include:

  • Opening a door

  • Triggering an alarm

  • Disabling a camera

  • Locking an elevator

  • Activating lights

  • Accessing a nearby terminal

These usually require prior access, a connected device, and an action.

Complex network intrusion should not normally be completed during one combat round without a specific feature.

Player Opportunities

Players may:

  • Steal security footage

  • Disable an alarm

  • Trace a phone

  • Plant a tracker

  • Forge access credentials

  • Expose financial fraud

  • Recover deleted records

  • Frame another hacker

  • Protect a witness’s identity

  • Leak evidence

  • Infiltrate a corporate network

  • Discover who altered official records

These situations should support technical skill, investigation, deception, stealth, and physical infiltration.

Using Digital Systems During Play

Franz should establish:

  • The target system

  • Required access

  • Available equipment

  • Time required

  • Security level

  • Possible evidence

  • Detection risk

  • Consequences of failure

Digital actions should reveal useful information and create new choices without functioning as automatic answers to every problem.