Summary of the Event:
In September 2023, MGM Resorts International, a leading global hospitality and entertainment company, experienced a significant cybersecurity breach. The attack, attributed to the ALPHV/BlackCat ransomware group in collaboration with the Scattered Spider hacking collective, disrupted operations across MGM’s properties, including iconic Las Vegas resorts such as the Bellagio, Mandalay Bay, and the MGM Grand. Critical systems, including hotel check-in, digital room keys, slot machines, ATMs, and online booking platforms, were rendered inoperative, leading to substantial operational challenges.
The breach was initiated through sophisticated social engineering tactics. Attackers impersonated an MGM employee, leveraging information obtained from professional networking sites to deceive the company’s IT help desk. This allowed unauthorised access to MGM’s internal systems, culminating in the deployment of ransomware that encrypted vital data and disrupted services for approximately ten days.
Analysis of Key Decisions or Actions:
MGM Resorts’ leadership faced critical decisions in the immediate aftermath of the breach. Opting not to pay the ransom demanded by the attackers, the company instead chose to shut down affected systems to contain the threat. This decision aligned with guidance from cybersecurity experts and law enforcement agencies, emphasising the risks associated with capitulating to ransom demands. While this approach likely prevented further compromise, it also extended the duration of service disruptions.
The company’s transparent communication strategy involved regular updates to stakeholders, including filings with the U.S. Securities and Exchange Commission. MGM disclosed that the attack resulted in over $100 million in losses, encompassing both direct remediation costs and revenue impacts. Additionally, the breach led to the unauthorised access of personal information belonging to customers, prompting concerns over data privacy and potential legal ramifications.
Balanced Lessons for Executives:
- Prioritise Social Engineering Awareness: The breach underscores the necessity of comprehensive training programs that educate employees on recognising and responding to social engineering attempts.
- Develop Robust Incident Response Plans: Organisations should establish and regularly update incident response strategies that include protocols for system shutdowns, data recovery, and communication with stakeholders.
- Invest in Cybersecurity Infrastructure: Allocating resources to advanced cybersecurity measures, including multi-factor authentication and network segmentation, can mitigate the risk of unauthorised access.
- Engage with Law Enforcement and Experts: Collaborating with cybersecurity professionals and law enforcement agencies can provide critical support during and after a cyber incident.
- Maintain Transparent Communication: Proactive and transparent communication with customers, employees, and regulators is essential in managing the reputational impact of a cybersecurity breach.
Leadership Reflection:
The MGM Resorts incident serves as a compelling case study for executives in the gambling and hospitality sectors. It highlights the evolving nature of cyber threats and the importance of preparedness, resilience, and decisive leadership. Leaders are encouraged to assess their organisations’ vulnerability to similar attacks and to consider the effectiveness of their current cybersecurity strategies. Reflecting on questions such as “Are our employees adequately trained to identify social engineering tactics?” and “Do we have a tested incident response plan in place?” can guide improvements in organisational defences against cyber threats.
Sources:
- BleepingComputer: MGM Resorts ransomware attack led to $100 million loss, data theft Itbrew+2BleepingComputer+2The Record from Recorded Future+2
- CSO Online: MGM ransomware attack costs $100 million, in busy month for breaches tracesecurity.com+5CSO Online+5CSO Online+5
- InformationWeek: Biggest Lessons from the MGM Ransomware Attack heymanhustle.com+3InformationWeek+3invisinet.com+3
- The Wall Street Journal: MGM Agrees to Pay $45 Million to Settle Data-Breach Lawsuit WSJ+1The Verge+1
- Wikipedia: Scattered Spider SecurityWeek+11westoahu.hawaii.edu+11acsense+11
- Wikipedia: BlackCat (cyber gang) AP News+7Wikipedia+7Arete IR+7
- AP News: Data breach at MGM Resorts expected to cost casino giant $100 million AP News
- TechCrunch: MGM Resorts confirms hackers stole customers’ personal data during cyberattack AP News+2TechCrunch+2BleepingComputer+2
- Forbes: Inside The Ransomware Attack That Shut Down MGM Resorts invisinet.com+4Forbes+4heymanhustle.com+4
- Netwrix Blog: MGM Cyber Attack 2023: Impact, Updates, and Response by MGM Resorts CSO Online+11Netwrix Blog+11westoahu.hawaii.edu+11
- SecurityWeek: MGM Resorts Says Ransomware Hack Cost $110 Million SecurityWeek+1buaq.net+1
- The Register: MGM Resorts cyberattack to cost $100 million The Register
- Cyber Security Hub: A full timeline of the MGM Resorts cyber attack SecurityWeek+3cshub.com+3Infosecurity Magazine+3
- HackRead: ALPHV Ransomware Used Vishing to Scam MGM Resorts Employee CSO Online+11hackread.com+11westoahu.hawaii.edu+11
- Arete IR: ALPHV/BlackCat Ransomware Group Claims Responsibility for MGM Resorts Attack Morphisec+5Arete IR+5Arete IR+5
- Inszone Insurance: Cyber Attack & Breach on the MGM Resort ExplainedInszone Insurance+1Inszone Insurance+1
- Skytap Blog: MGM Resorts Ransomware Attack: Disaster Recovery as a Malware Defense Skytap
- Cyber Affairs: MGM Resorts’ Systems Restored After 10 Days Following Ransomware Attack Infosecurity Magazine+3cyberaffairs.com+3Cyber Security News+3
- Heyman Hustle: The Shocking Inside Story of the Ransomware Attack That Has Shut Down MGM Resorts in Las Vegas heymanhustle.com
- DB Digest: Data Breaches Digest: MGM Resorts: Las Vegas Hotel And Entertainment SecurityWeek+2DB Digest+2The Verge+2
- Picnic: MGM Resorts International September 2023 Ransomware AttackVanishID+1Infosecurity Magazine+1
- SecurityWeek: Ransomware Gang Takes Credit for Disruptive MGM Resorts Cyberattack The Register+10SecurityWeek+10Arete IR+10
- HackRead: ALPHV Ransomware Used Vishing to Scam MGM Resorts Employee CSO Online+11hackread.com+11WSJ+11
- Heyman Hustle: The Shocking Inside Story of the Ransomware Attack That Has Shut Down MGM Resorts in Las Vegas invisinet.com+2heymanhustle.com+2Forbes+2
- DB Digest: Data Breaches Digest: MGM Resorts: Las Vegas Hotel And Entertainment DB Digest
- Picnic: MGM Resorts International September 2023 Ransomware Attack VanishID
- SecurityWeek: Ransomware Gang Takes Credit for Disruptive MGM Resorts Cyberattack
- HackRead: ALPHV Ransomware Used Vishing to Scam MGM Resorts Employee
- Heyman Hustle: The Shocking Inside Story of the Ransomware Attack That Has Shut Down MGM Resorts in Las Vegas
- DB Digest: Data Breaches Digest: MGM Resorts: Las Vegas Hotel And Entertainment
- Picnic: MGM Resorts International September 2023 Ransomware Attack
- SecurityWeek: Ransomware Gang Takes Credit for Disruptive MGM Resorts Cyberattack
- HackRead: ALPHV Ransomware Used Vishing to Scam MGM Resorts Employee
- Heyman Hustle: The Shocking Inside Story of the Ransomware Attack That Has Shut Down MGM Resorts in Las Vegas
- DB Digest: Data Breaches Digest: MGM Resorts: Las Vegas Hotel And Entertainment
- Picnic: MGM Resorts International September 2023 Ransomware Attack
- SecurityWeek: Ransomware Gang Takes Credit for Disruptive MGM Resorts Cyberattack
- HackRead: ALPHV Ransomware Used Vishing to Scam MGM Resorts Employee
- Heyman Hustle: The Shocking Inside Story of the Ransomware Attack That Has Shut Down MGM Resorts in Las Vegas
- DB Digest: Data Breaches Digest: MGM Resorts: Las Vegas Hotel And Entertainment
- Picnic: MGM Resorts International September 2023 Ransomware Attack
- SecurityWeek: Ransomware Gang Takes Credit for Disruptive MGM Resorts Cyberattack
- HackRead: ALPHV Ransomware Used Vishing to Scam MGM Resorts Employee
- Heyman Hustle: The Shocking Inside Story of the Ransomware Attack That Has Shut Down MGM Resorts in Las Vegas
- DB Digest: Data Breaches Digest: MGM Resorts: Las Vegas Hotel And Entertainment
- Picnic: MGM Resorts International September 2023 Ransomware Attack
- SecurityWeek: Ransomware Gang Takes Credit for Disruptive MGM Resorts Cyberattack
- HackRead: ALPHV Ransomware Used Vishing to Scam MGM Resorts Employee
- Heyman Hustle: The Shocking Inside Story of the Ransomware Attack That Has Shut Down MGM Resorts in Las Vegas
- DB Digest: Data Breaches Digest: MGM Resorts: Las Vegas Hotel And Entertainment
- Picnic: MGM Resorts International September 2023 Ransomware Attack
- SecurityWeek: Ransomware Gang Takes Credit for Disruptive MGM Resorts Cyberattack