Skip to content
Cybersecurity & Tech Innovation

MGM Resorts’ ransomware attack and the cost of not paying

1. Case Summary

MGM Resorts International disclosed on 12 September 2023 that it had identified a cybersecurity issue affecting systems across its US properties, and the intrusion is attributed to an affiliate of the ALPHV, or BlackCat, ransomware group, working with the social engineering collective known as Scattered Spider. According to public reporting, an attacker impersonated an MGM employee identified through LinkedIn and called the company’s IT helpdesk, obtaining credentials in around ten minutes, which is not much time at all for a company of MGM’s size to be exposed by. MGM then shut down significant portions of its network to contain the intrusion, a decision that disrupted slot machines, digital room keys, reservation systems, ATMs and its website and booking apps for several days.

MGM refused to pay a ransom, and in its subsequent Form 8-K filing with the US Securities and Exchange Commission, the company estimated the incident’s negative impact at approximately $100 million to adjusted property EBITDAR across its Las Vegas Strip and regional operations, plus less than $10 million in one-time costs for technology consulting, legal fees and third-party advisors. September occupancy fell to 88 per cent against 93 per cent the previous year, with a full rebound not expected until November, and for customers who had transacted with MGM before March 2019, attackers obtained personal information including names, contact details, dates of birth and driver’s licence numbers, with a subset of Social Security and passport numbers also exposed, though passwords, bank details and payment card data were not accessed.

Caesars Entertainment suffered a related but separate attack weeks earlier, also linked to Scattered Spider, using social engineering against a third-party IT vendor rather than MGM’s own helpdesk. Caesars reportedly paid a ransom, with the Wall Street Journal reporting an initial demand of $30 million, and it avoided the extended shutdown MGM went through, though its Rewards database, including loyalty members’ driver’s licence and Social Security numbers, was still compromised regardless.

2. Global Context

Caesars is the most direct comparison here, since both attacks happened within weeks of each other, involved the same threat actor, and hit the same industry and largely the same jurisdiction, Nevada, and yet the two companies made opposite decisions on the central question a ransomware incident forces onto a board: pay, or refuse. Caesars paid and kept its properties largely running, while MGM refused and absorbed around $100 million in lost earnings plus days of guest-facing disruption during a peak period, and neither route spared customers entirely, since Caesars’ loyalty database was compromised regardless of payment.

A useful comparison from outside gambling is Equifax, the US credit reporting company, which discovered in July 2017 that attackers had exploited an unpatched software vulnerability to access the data of around 147 million consumers, including Social Security numbers and driver’s licence details. Equifax did not disclose the breach publicly for roughly six weeks, and in July 2019 it agreed to pay up to $700 million to settle with the Federal Trade Commission, the Consumer Financial Protection Bureau and 48 US states. Where MGM’s failure was a helpdesk check defeated by a phone call, Equifax’s was a known vulnerability left open for months, and both cases show the same thing in the end, which is that the technical cause of a breach matters less to regulators and customers than how quickly and honestly the company then discloses and responds.

3. Analysis

The tension here is that doing what security orthodoxy recommends cost MGM more, in the short term, than doing what it does not. Law enforcement guidance is consistently not to pay ransoms, since payment funds further criminal activity and offers no guarantee attackers will delete stolen data, and MGM followed that guidance and lost roughly $100 million and days of operations, while Caesars did not and largely kept trading. Neither outcome is straightforwardly vindicated by what happened next, which is precisely the discomfort a board has to sit with once this decision stops being hypothetical.

The dimensions show why this is not simply a technology question. Strategically, MGM’s slot machines, room keys, payment systems and booking platforms sat on a network integrated enough that one compromised credential could cascade into an enterprise-wide shutdown, which makes network architecture a board-level risk decision rather than an IT department one. Ethically, MGM’s refusal to fund a criminal enterprise is defensible in principle, but it does not erase the practical harm to guests locked out of rooms or unable to use hotel services during one of Las Vegas’s busiest periods, a cost the decision imposed on customers who had no say in it. Operationally, the weak point was not a sophisticated exploit but a basic identity verification step at a helpdesk, exactly the kind of control that is inexpensive to fix and expensive to leave unfixed. And on the human dimension, guests experienced this as a service failure regardless of the security logic behind it, which is a reminder that decisions made in a crisis room have consequences that show up, immediately and visibly, on a casino floor.

Caesars’ choice, made weeks earlier and available to MGM as a reference point, is worth thinking through properly. Had MGM paid, it might have avoided the $100 million earnings hit and the days of disruption, as Caesars largely did, but it would not have avoided the exposure of guest data, since Caesars’ loyalty database was compromised regardless of payment, and it would have made a payment to a criminal actor whose promises about deleting stolen data cannot be verified or enforced by anyone. Neither path eliminates harm, and each simply chooses which form of harm the company and its customers end up absorbing.

The decision boards actually face is not, in the abstract, whether to pay, but whether the technology architecture forces that binary choice onto the business in the first place, and that is where the real pressure runs. Security budgets have to be weighed against the roughly $100 million MGM’s incident cost, a figure that likely dwarfs what proper network segmentation and helpdesk verification would have required, and legal, communications and security functions have to operate on the same clock, since US securities rules require timely disclosure of material cybersecurity incidents even while an incident is still active.

4. Governance Lessons

One, whether to pay a ransom should be a documented, board-approved policy decided before an incident, not negotiated for the first time under crisis pressure.

Two, converged operational technology- room keys, slot machines, payment systems- sitting on one poorly segmented network turns a single social engineering success into an enterprise-wide outage, so segmentation is a governance priority, not purely a technical one.

Three, helpdesk identity verification is a human process control, and exactly the kind of control that is cheap to strengthen and catastrophic to leave weak.

Four, refusing to pay does not eliminate customer harm; it just changes its form, from data exposure risk to service disruption, so boards should prepare communications and remediation for both outcomes, not only the one they hope avoids liability.

Five, disclosure obligations and crisis response now run on the same timeline, which means legal, communications and security teams need one rehearsed joint protocol, not three that meet for the first time during the incident itself.

5. Boardroom Questions

1. Do we have a documented, board-approved position on ransom payment, tested against a realistic scenario rather than left as an untested policy statement?

2. How segmented is our operational technology, guest-facing systems, payment systems, and physical access control from our corporate network, and when was that segmentation last independently tested?

3. If our helpdesk or an equivalent front-line function were targeted by social engineering tomorrow, what specific verification step would stop the attacker, and do we know it is actually being followed, not just documented?

Sources

1. MGM Resorts International, Form 8-K, US Securities and Exchange Commission, 5 October 2023, https://www.sec.gov/Archives/edgar/data/789570/000119312523251667/d461062d8k.htm

2. CDC Gaming Reports, ‘SEC filing by MGM: Cyberattack will cost $100 million in adjusted earnings’, 2023, https://cdcgaming.com/sec-filing-by-mgm-cyberattack-will-cost-100-million-in-adjusted-earnings/

3. Forbes, ‘2 Casino Ransomware Attacks: Caesars Paid, MGM Did Not’, 14 September 2023, https://www.forbes.com/sites/suzannerowankelleher/2023/09/14/2-casino-ransomware-attacks-caesars-mgm/

4. Federal Trade Commission, ‘Equifax to Pay $575 Million as Part of Settlement with FTC, CFPB, and States Related to 2017 Data Breach’, 22 July 2019, https://www.ftc.gov/news-events/news/press-releases/2019/07/equifax-pay-575-million-part-settlement-ftc-cfpb-states-related-2017-data-breach