MGM Resorts remains impaired, Caesars confirms earlier attack as cyberattack wave continues

Haley Hintze
Haley Hintze
Posted on: September 14, 2023 08:03 PDT

Computer-connected operations at MGM Resorts properties continue to be impacted by a cyberattack that has now extended into a fifth day, and Caesars Entertainment has confirmed via a filing with the Securities and Exchange Commission (SEC) that it was also recenty the victim of such an attack.

MGM Resorts properties are grappling with the situation as multiple law-enforcement agencies continue investigating the ransomware attack, which included the theft of stored data in addition to the access of sensitive systems. The computerized systems that were affected figure into virtually every aspect of MGM Resorts properties' daily operations, including hotel reservations and room keys, loyalty-program-linked slots and other forms of gaming, ATMs, parking-ramp access, and many, many other electronically-linked systems.

Scattered Spider group behind attack

Several prominent news outlets reported that a hacking group known as Scattered Spider claimed credit for the MGM attack. Scattered Spider and a related hacking group, UNC 3944, are also affiliated with other prominent global hacking groups. According to a Yahoo News update, the Scattered Spider group is believed to be comprised of hackers mostly of college age, 19 to 22, and the group's members are based mostly in the US and UK.

In online posts, the group claimed to have hacked into MGM via "social engineering," meaning to trick a systems-information worker at MGM or a third-party firm into resetting or otherwise revealing a password for a system-linked account that had been identified. One plausible example is for the hacking group to identify a worker at a related firm, gather as much personal and company information about that worker, and then pose as that worker in a call to the company's system-administration department, claiming a lost password and needing a reset.