MGM Resorts shut down IT systems across its casinos after a cyberattack
- Organization
- MGM Resorts International
- Exploit
- Ransomware
- Industry
- Hospitality and Gaming
MGM Resorts International said on September 11, 2023 that it had identified a cybersecurity issue affecting some of its systems and had shut parts of its network down in response. The disruption began the previous evening and spread across properties nationwide, including Las Vegas Strip resorts such as the Bellagio, Aria and Mandalay Bay.
Guests and staff reported that the company's main website and online reservation system were unavailable, that the MGM Rewards app would not load, and that in-casino equipment including ATMs, slot machines and card payment terminals had stopped working. Digital room keys failed, leaving front desks issuing physical keys and writing receipts by hand. MGM directed customers to telephone for reservations and rewards inquiries.
The company said it had taken prompt action to protect its systems and data and had begun an investigation, but released few details. Security specialists quoted by Infosecurity Magazine said the symptoms were consistent with ransomware. MGM did not name an attacker at the time.
By September 14 the outage had run into a fourth day. The Scattered Spider group, which researchers associate with the ALPHV ransomware operation, claimed responsibility and told TechCrunch it had reached MGM's systems by impersonating an employee in a call to the company's help desk. MGM waived cancellation fees for guests arriving through September 17.
Sources
- BleepingComputer, MGM Resorts shuts down IT systems after cyberattack
- Infosecurity Magazine, MGM Resorts Hit By Cyber-Attack, Systems Down
- TechCrunch, Hackers claim MGM cyberattack as outage drags into fourth day
- Las Vegas Review-Journal, MGM Resorts nationwide work to recover from cybersecurity issue