Don’t do SECURITY. Do business SECURELY.
Threat intel

Cyber attack disrupts MGM Resorts casinos and hotels

A cyber attack on MGM Resorts shut down systems across its US casinos and hotels, costing the company around $100m.

MGM Resorts said a cyber security issue had affected some of its systems, disrupting casinos and hotels across the US. The ALPHV/BlackCat ransomware group claimed the attack, with reports linking it to the Scattered Spider hacking group.

What happened

  • Guests reported problems with digital room keys, slot machines, and card payments, and some check-ins were handled by hand.
  • Attackers reportedly gained access through social engineering of the IT help desk.
  • MGM said the attack had an impact of around $100m on its quarterly results and that customer personal data was taken.
  • Caesars Entertainment disclosed a separate attack around the same time, and was reported to have paid a ransom.

Why it mattered

The attack showed how social engineering against help desks could lead to a major operational outage, and brought Scattered Spider to global attention. Researchers and media later reported links between Scattered Spider and attacks on other large companies, including UK retailers in 2025.

Lessons for organisations

Organisations should strengthen identity checks at their service desk before resetting passwords or MFA, and train staff to recognise phone-based social engineering. Phishing-resistant MFA and privileged access management reduce the damage if an account is taken over.

Source: BleepingComputer

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe

More insights