All vulnerabilities
CRITICALOpSecransomware

OPSEC-MGM-CAESARS-2023

Hospitality · MGM Resorts and Caesars Entertainment

Summary

In September 2023, the Scattered Spider group (an ALPHV/BlackCat ransomware affiliate) used vishing and help-desk social engineering to breach MGM Resorts and Caesars Entertainment. Attackers impersonated employees to IT help desks to obtain credentials and MFA resets, then moved laterally and deployed ransomware. Caesars had its loyalty-program database stolen, including driver's license and Social Security numbers, and reportedly paid roughly $15 million of a $30 million demand. MGM refused to pay, suffered an approximately $100 million hit to quarterly EBITDAR, had over 100 ESXi hypervisors encrypted, and exposed personal data of customers who transacted before March 2019.

References

Related vulnerabilities

All OpSec →