MGM Resorts International
On the evening of September 10, 2023 an operator placed a call to MGM's IT help desk. Within roughly ten minutes they had convinced help-desk staff to reset the password and MFA of an MGM employee they had identified on LinkedIn.
From that single account they pivoted through MGM's Okta identity platform into Microsoft 365 and Azure, located VMware vCenter administrator credentials, and deployed ALPHV/BlackCat ransomware against roughly 100 ESXi hypervisors. Encrypting hypervisors is a force multiplier: every virtual machine on the host goes dark at once. This is why slot machines, hotel digital keys, booking systems, restaurant POS, and the MGM Rewards app all went offline simultaneously.
The outage lasted more than 36 hours for core systems. Slot floors at the Bellagio, Aria, MGM Grand, Mandalay Bay, and other MGM properties went dark. Hotel guests waited in line while front-desk staff wrote room keys by hand. MGM's October 5, 2023 SEC 8-K filing disclosed approximately $100 million in operational impact, plus roughly $10 million in one-time remediation costs.
Customer data of approximately 10 million prior guests was reported stolen: names, dates of birth, contact info, and for a subset, driver's license and passport numbers. MGM publicly refused to pay the ransom.
The attack chain did not require a zero-day, an exploit, or any technical vulnerability in MGM's software. It required a phone, a LinkedIn account, and an IT help desk willing to reset a password for a confident caller. That is the entire playbook.
MGM Resorts International SEC Form 8-K (Oct 5, 2023); Mandiant + Okta incident briefings; KrebsOnSecurity coverage; Bloomberg; Reuters. Public statements from MGM and reporting on Scattered Spider tradecraft.
Same playbook, different victim.
Caesars
Compromised through a vendor's help desk. Loyalty-program data exfiltrated. Caesars went the other way and reportedly paid. The stolen data was already gone either way.
Findlay Direct
Henderson-headquartered dealership chain breached directly. 30+ dealerships across 5 states. Customer + employee PII exposed. Class-action lawsuits in Clark County.
Findlay via CDK
Two weeks after the direct breach, Findlay's software vendor CDK Global was ransomed. ~15,000 dealers nationwide reverted to pen and paper for ~2 weeks.
Want me to take a look?
Email me and we will set up a free consultation. Tell me what you run and what you are worried about, and I will tell you whether there is anything worth doing.
yeriahz@sscsnv.com