In September 2023, Scattered Spider used a 10-minute vishing call to impersonate an MGM employee and convince IT support to hand over credentials. That single social engineering move gave the attackers admin access to MGM's Okta and Azure environments, triggering a 10-day ALPHV ransomware attack that disrupted slot machines, hotel keys, and booking systems across Las Vegas. MGM lost an estimated $100 million and faces multiple class-action lawsuits.
If you've ever been to a Las Vegas casino, you know they’re literally money-making machines, with people wagering on a variety of games nonstop. Modern casinos exemplify digitally transformed businesses, with customers interacting through multiple digital channels, from gaming systems to mobile apps and loyalty programs.
The cyberattack on the Las Vegas MGM clearly demonstrated how a digital disruption can quickly have significant consequences for a company's revenue, customer satisfaction, and public image.
On September 11, 2023, MGM Resorts released a statement on X that a "cybersecurity incident" was impacting some of its systems. The incident was expected to result in a $100 million loss in the third quarter of 2023. The attack was carried out by two separate groups known as Scattered Spider and ALPHV.
Faced with significant disruption to its operations and the potential for further damage, the company had to make difficult decisions, including whether to pay millions in ransom to the attackers, as its rival Caesars Entertainment did.
Initial discovery and response
It doesn't take long to realize you’re in the midst of a ransomware attack. Attackers are believed to have first breached the network on September 8th. The following day, MGM's security teams detected unusual activity and traffic on the company's systems. The attack rapidly escalated over the next few days as operations were publicly disrupted.
MGM Resorts acted quickly, including shutting down some systems to protect its data and infrastructure, which caused further disruptions. Recognizing the severity of the situation, MGM promptly engaged third-party agencies and leading cybersecurity experts to help contain and mitigate the attack. They also engaged law enforcement, launching an immediate investigation into the breach.
How the cyber attack on MGM unfolded
The attack unfolded in two distinct phases, each exploiting a different weakness: the first targeted people, the second targeted systems.
Social engineering tactics used by hackers
To gain access to the MGM network, Scattered Spider launched a social engineering attack via vishing that went something like this:
- Scattered Spider members searched LinkedIn for MGM employees, gathering information about their roles and identities.
- Using the information they gathered, the attackers chose an MGM employee to impersonate.
- The attackers contacted MGM's IT help desk, posing as the employee and successfully convincing the help desk to provide them with login credentials.
- Using the obtained credentials, Scattered Spider gained administrator privileges in MGM's Okta and Azure tenant environments.
- The attackers used their high-level access to move laterally within the MGM systems.
It was at this time that Scattered Spider engaged ALPHV to deploy their ransomware-as-a-service (RaaS) software. They encrypted approximately 100 ESXi hypervisors within MGM's network.
These servers hosted thousands of virtual machines that supported critical hospitality systems, including gaming machines, online reservation systems, digital room keys, and websites.
ALPHV also claims to have exfiltrated 6 TB of customer information during this period, which they used as a threat to pressure MGM into paying and preventing the publication of the stolen data.
Netwrix Privilege Secure replaces standing admin accounts with just-in-time privileged sessions that revoke automatically. Download a free trial
Impact on MGM systems and operations
The effects of the cyberattack on MGM Resorts were immediately evident with widespread disruptions across their organization:
- Gambling operations were halted when slot machines went offline and displayed error messages.
- Hotel guests reported that their digital room keys had stopped working.
- Online booking and reservation systems were closed.
- Mobile services were discontinued as the MGM app became completely inaccessible.
- Email systems were affected.
- Restaurant reservations were stopped.
Timeline of events and duration of the attack
The total duration of the attack was approximately 10 days. The attack timeline was as follows:
- September 7, 2023: Scattered Spider launches a social engineering attack against Caesar's Entertainment's IT support provider.
- September 10, 2023: MGM Resorts begins experiencing system outages.
- September 11, 2023: MGM publicly discloses the incident and launches an investigation after contacting law enforcement.
- September 12–13, 2023: Customers report various issues impacting their experience.
- September 14, 2023: Scattered Spider claims to have stolen 6 terabytes of data from MGM Resorts, and MGM begins restoring its systems.
- September 20, 2023: MGM confirms full-service restoration across all its systems.
The financial and reputational damage
Estimated financial losses due to the MGM cyber attack
The costs of a ransomware attack can be quite exorbitant. These costs include containment expenses, lost productivity, potential lawsuits, business interruption, and the potential payment of a ransom.
Unlike Caesars Entertainment, which suffered a ransomware attack around the same time and chose to pay the ransom, MGM stated it never considered paying. Their decision to abstain from payment was in line with the recommendations of cybersecurity experts, government agencies, and law enforcement, who advised against such actions due to the risks involved. MGM lost an estimated $84 million in lost revenue.
They also spent $10 million in one-time expenses for technology consulting, legal fees, and third-party consultants. The company also incurred costs associated with providing complimentary services and restoring loyalty program points to affected customers.
Reputational impact on MGM and customer trust
MGM Resorts faced a barrage of negative attention on social media as users expressed their frustrations. It remains to be seen whether this will lead to reduced customer loyalty and trust. MGM's recovery was aided by the timely arrival of the high-profile Formula One race shortly after the incident, which helped shift attention and potentially mitigate some reputational damage.
Data breach and information compromise
Types of customer information exposed
The data exfiltrated during the attack consisted of information on MGM customers, primarily those who had transacted with the company before March 2019. This included personal information such as names, contact information, dates of birth, and driver's license numbers.
A smaller subset of customers may have had their Social Security numbers, passports, or military identification numbers exposed. Personal data related to hotel reservations and loyalty program details were also compromised. Although unconfirmed, employee data may also have been exposed in the attack.
Measures taken by MGM to protect customers
Having a well-defined incident response plan is essential for effectively managing and mitigating the impact of a cyberattack. Here are some of the measures MGM took immediately after the attack:
- Created a specific website and portal with information about the breach.
- Released public statements and updates through various channels to ensure transparency.
- Provided free credit monitoring services.
- Offered identity theft protection to affected customers and employees.
- Implemented a dedicated call center to address customer concerns and questions.
Legal consequences and customer lawsuits
Class action lawsuits against MGM
Multiple lawsuits have been filed against MGM. The lawsuits allege that, as a global leader in the casino and hotel industry, MGM failed to implement adequate cybersecurity measures to protect consumer data.
They allege that the plaintiff stored sensitive customer information without proper encryption and that Okta had previously warned the company of potential security risks, suggesting that MGM failed to heed these warnings. The lawsuits seek various forms of relief, including:
- Monetary damages
- Reimbursement for potential identity theft protection
- Coverage of expenses related to the protection of personal information
- Punitive damages for alleged negligence
Compliance and regulatory oversight issues
MGM properly disclosed the cyberattack and its potential financial impact in SEC filings, as required for publicly traded companies. The FTC launched an investigation into MGM's data security practices following the attack; however, MGM sued the FTC, arguing that the investigation exceeded the agency's authority.
The company also claims a conflict of interest, as FTC Chairwoman Lina Khan was personally affected by the cyberattack while staying at an MGM property. Multiple state regulators have launched investigations into the MGM cyberattack incident. While no specific entities have been named, the Nevada Gaming Control Board is likely involved in the investigation.
Netwrix Threat Manager maps credential theft, lateral movement, and privilege escalation across on-premises Active Directory and Entra ID. Get a demo.
Lessons learned and future measures for cybersecurity
Improvements to MGM's cybersecurity strategy
To strengthen its cybersecurity posture, the company conducted a thorough assessment of its existing cybersecurity systems and processes. Subsequently, they implemented additional security measures, including:
- Improved access control and authentication processes
- Improved network segmentation
- Enhanced intrusion detection and prevention systems
- Strengthened data encryption practices
Notably, MGM's public disclosures center on technical controls, not the help-desk identity-verification step that Scattered Spider actually defeated. Encryption and network segmentation don't stop a convincing phone call; that takes callback verification, stronger identity proofing before a credential reset, and ongoing social-engineering training for IT support staff.
Additionally, MGM announced plans to invest up to $40 million in IT improvements over the next year.
The importance of incident response plans
MGM's swift actions clearly show it had a well-structured incident response plan. Their prompt response included:
- Engaging cybersecurity experts and law enforcement agencies
- Mobilizing IT professionals to contain the breach
- Attempting to prevent further spread of ransomware
- Timely and transparent communication with affected customers
MGM quickly recognized the attack's severity and made the critical decision to shut down essential digital systems to contain it. While this initially disrupted operations, it prevented further data exfiltration and limited the ransomware's potential spread. This proactive approach demonstrated the importance of having a predefined protocol for rapid system isolation during a cybersecurity incident.
Wider implications for the hospitality industry
The cyberattack on MGM Resorts exposed the industry's reliance on interconnected digital systems. As digital technologies become increasingly integrated to manage reservations, loyalty programs, and payment systems, the industry is becoming a prime target for cybercriminals.
The attack demonstrated how quickly multiple services can be disrupted. To address the increased risk, the industry must implement comprehensive security measures, continuously test its defenses, and make necessary adjustments.
How Netwrix can help
Netwrix offers a suite of security solutions that can protect your organization from attacks like the one at MGM.
Netwrix Privilege Secure replaces standing admin accounts with just-in-time privileged sessions that revoke automatically. Instead of static accounts that are vulnerable when not in use, Netwrix provisions temporary access with the right permissions to perform the required task. Once the task is completed, the account is deleted. It also monitors all administrative activity in real time across multiple IT systems.
Netwrix Auditor records before-and-after values for access and change events across hybrid Microsoft environments. By consolidating all anomalous activity alerts triggered by an individual into a comprehensive view, security teams can quickly identify potentially malicious insiders or compromised accounts.
Netwrix Data Classification Software discovers and tags PII, PHI, and PCI data across hybrid stores. It can automatically quarantine critical or sensitive data stored in unsecured locations or accessible by large, open groups.
Request a demo to see how Netwrix can help you eliminate standing privileges, detect lateral movement, and classify sensitive data before attackers reach it.
Frequently asked questions about the MGM cyber attack
Share on
Learn More
About the author
Dirk Schrader
VP of Security Research
Dirk Schrader is a Resident CISO (EMEA) and VP of Security Research at Netwrix. A 25-year veteran in IT security with certifications as CISSP (ISC²) and CISM (ISACA), he works to advance cyber resilience as a modern approach to tackling cyber threats. Dirk has worked on cybersecurity projects around the globe, starting in technical and support roles at the beginning of his career and then moving into sales, marketing and product management positions at both large multinational corporations and small startups. He has published numerous articles about the need to address change and vulnerability management to achieve cyber resilience.
Learn more on this subject
What is DLL hijacking, and why your new AI plugin might be the easiest way in
Automating Entra ID tenant destruction with AI
UEBA (User and Entity Behavior Analytics): complete guide to detection, use cases, and implementation
Risk Analysis Example: How to Evaluate Risks
The CIA Triangle and Its Real-World Application