MGM Resorts International confirmed that a cyberattack that began on September 11, 2023, caused widespread disruption across its properties, including 12 casino venues on the Las Vegas Strip. The company shut down affected systems to protect customer data, which took down its website, mobile app, online reservations, ATMs, slot machines, and credit card machines. Guests reported being unable to use key cards to enter rooms, and employees were locked out of corporate email systems for days. A hacking group known as Scattered Spider, affiliated with the Russian ransomware-as-a-service group Black Cat (also called ALPHV), claimed responsibility for the attack.

The group reportedly gained access by using social engineering tactics against a help desk employee, allowing them to bypass multi-factor authentication controls. Once inside, the hackers encrypted more than 100 hypervisors and stole sensitive information. The attack exposed the personal data of customers who used MGM services before March 2019. That information included contact details, driver’s license numbers, Social Security numbers, passport numbers, and passwords.
The company said the hackers did not access customer payment information. MGM President and CEO Bill Hornbuckle said in a letter to customers that the company responded swiftly, shut down systems to reduce risk, and coordinated with federal law enforcement and external cybersecurity experts. He later announced that domestic operations had stabilized and most systems were restored, saying, “We also believe that this attack is contained. ”
The company reported a $100 million loss in earnings before interest, taxes, depreciation, amortization, and rent for its Las Vegas Strip resorts and regional operations.
It also expected to incur charges of less than $10 million for legal fees and technology consulting. Hotel occupancy in September fell to 88 percent, down from 93 percent the previous year. According to reports from 404 Media, the hackers used social engineering to deceive an employee into providing credentials, which allowed them to bypass security controls from identity management company Okta. The same hacking group was also linked to attacks on companies including Reddit, Riot Games, and Coinbase.
MGM refused to pay the ransom, following advice from the FBI, which warns that paying does not guarantee the return of stolen data and encourages further criminal activity. Caesars Entertainment, which was also hacked by the same group, reportedly chose a different path and paid $15 million, about half of the initial $30 million demand, according to the Wall Street Journal. Both companies later faced federal lawsuits over the incidents. MGM did not disclose how the attackers breached its systems or how many customers were affected, but it offered free credit monitoring and identity theft protection to impacted customers.
The company also said its cybersecurity insurance would cover the financial impact of the operational disruption. In a filing with the Securities and Exchange Commission, MGM said the breach would negatively affect its third-quarter financial results, particularly in Las Vegas, but expected minimal impact in the fourth quarter and overall annual results. Security experts commented on the broader implications of the attack. An Cutler, a cybersecurity evangelist at Keeper Security, said the ramifications of an attack of that size are far-reaching and long-lasting.
Bud Broomhead, CEO at Viakoo, said no company is too big to hack, but the critical issue is whether a business is too resilient to hack. Omri Weinberg, co-founder and CRO at DoControl, noted that no company can ever be fully protected, as hackers continue to find new and more sophisticated methods. The attack on MGM was not isolated. Clorox also reported a cybersecurity incident that caused significant operational disruptions, shortages of products, and delayed order processing.
The company projected a net sales decline of 23 to 28 percent for the first quarter of 2024. The MGM breach highlighted how vulnerable large corporations remain to skilled cybercriminals. The company’s decision to refuse the ransom demand aligned with law enforcement advice but came with substantial financial and operational consequences.
Caesars’ decision to pay was aimed at quickly mitigating the immediate threat, though it may encourage future ransom demands.