What happened
MGM Resorts disclosed a cybersecurity issue on 12 September 2023 that took hotel reservation systems, digital room keys, slot machines and its website offline across US properties for about ten days. In its Q3 2023 filing MGM reported roughly $100 million of negative impact to Las Vegas Strip adjusted property EBITDAR, plus under $10 million in one-time costs, and said personal data of customers who transacted before March 2019 was stolen, including names, contact details, dates of birth and driver's licence numbers, and Social Security and passport numbers for a subset. Scattered Spider, working with ALPHV/BlackCat, claimed responsibility.
How the deception worked
MGM has never published the entry point, but the widely reported account, consistent with the CISA advisory and Okta's contemporaneous warning, is that the crew identified an MGM employee from a public professional profile, gathered enough personal and organisational detail to pass as them, and phoned the IT help desk to obtain a credential and MFA reset in a call reported to have lasted about ten minutes. With a legitimate identity re-issued to them, the actors escalated inside the identity provider and, after exfiltration, deployed ransomware against virtualisation infrastructure.
AI involvement · No AI reported
No AI or voice cloning was reported; the reported method was a live human call using details gathered from public professional profiles.
The control that would have caught it· our reading, not a claim from the sources
High-privilege credential and MFA resets should never be grantable on a single inbound phone call; out-of-band verification with a known manager or video identity check would have cost the caller the whole operation.
Sources (4)
- Ransomware attack on MGM Resorts costs $110 MillionSecurity Affairs·securityaffairs.comOpen ↗
- MGM Resorts confirms hackers stole customers' personal data during cyberattackTechCrunch·techcrunch.comOpen ↗
- Scattered Spider (AA23-320A)CISA / FBI·cisa.govOpen ↗
- A full timeline of the MGM Resorts cyber attackCyber Security Hub·cshub.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.