Hospitality · United States · September 2023
MGM Resorts Ransomware Attack
In September 2023, a ransomware attack on MGM Resorts — enabled by a phone call to the IT help desk — disrupted hotels and casinos across Las Vegas and beyond for around ten days, at a reported cost near US$100 million.
What happened
In September 2023, MGM Resorts — one of the largest hospitality and casino operators in the world — was struck by a ransomware attack that became a defining example of how modern intrusions often begin not with sophisticated malware, but with a convincing phone call. The attack was attributed in reporting to the group known as Scattered Spider, working in concert with the ALPHV/BlackCat ransomware operation.
According to widely-reported accounts, the attackers gained their foothold through social engineering: they reportedly called MGM's IT help desk, impersonated an employee, and persuaded staff to reset credentials — handing the intruders legitimate access. From there they escalated privileges and moved through MGM's environment.
As the intrusion was discovered, MGM took large portions of its systems offline. The result was chaos across its properties: hotel room-key systems, slot machines, booking and reservation platforms, and other digital services went down across Las Vegas and beyond.
The impact
The disruption was highly visible and lasted around ten days. Guests reported being unable to check in digitally or use electronic room keys; slot machines sat idle; reservation and loyalty systems were unavailable; and staff reverted to manual processes across hotels and casinos. For a business whose revenue is measured by the hour, the operational hit was enormous.
MGM reported a financial impact of roughly US$100 million from the incident, encompassing lost revenue during the disruption and the costs of response and remediation. Notably, MGM was reported not to have paid a ransom — which meant the cost was borne almost entirely in operational disruption and recovery rather than extortion.
Some customer data was reportedly affected, adding a data-breach dimension and subsequent litigation to the operational damage. The incident, alongside a contemporaneous attack on Caesars Entertainment, became a wake-up call about the potency of help-desk social engineering.
How the attack unfolded
- Initial access: attackers reportedly called the IT help desk, impersonated an employee, and got credentials reset — a social-engineering foothold, not malware.
- Privilege escalation: the intruders expanded access across MGM's identity and cloud environment.
- Impact: MGM took systems offline as ransomware was deployed, disrupting hotel and casino operations for around ten days.
- Extortion: MGM reportedly declined to pay, absorbing the cost as operational disruption.
The recovery
MGM restored systems over roughly ten days, bringing properties back online in stages while operating manually in the interim. The company absorbed the substantial revenue loss rather than paying the attackers.
The incident cemented social engineering of help desks and identity systems as a primary attack path, and pushed the industry toward stronger identity-verification controls for privileged access requests.
How this attack could have been contained
The help-desk social-engineering entry point produces a telltale signature: a legitimate credential suddenly behaving abnormally. Immune's continuous access verification is designed to catch exactly this — scoring behavior after login, so a freshly-reset credential reaching unusual systems is flagged even though the authentication itself was valid.
The rapid privilege escalation and lateral movement that followed are what Immune's network monitoring and behavioral detection target, aiming to surface the intrusion during escalation rather than after systems are taken offline.
And MGM's ten days of disruption is the kind of outage containment and self-healing recovery are built to shorten — isolating the compromised segment and restoring validated systems in order, so an identity compromise does not become a multi-day operational shutdown.
Sources
Figures are drawn from public reporting and official disclosures and are presented as reported or estimated; they may be updated as further details become public.
Related incidents
More ransomware attacks
Beginning in May 2023, the Cl0p group exploited a zero-day flaw in the widely-used MOVEit file-transfer software to steal data from thousands of organizations worldwide — one of the largest supply-chain extortion campaigns ever recorded.
The February 2024 ransomware attack on Change Healthcare disrupted medical claims and payments nationwide, affecting an estimated 100 million people and becoming one of the costliest healthcare cyberattacks on record.
Protect against attacks like this
How to defend against hospitality ransomware
Don't let an attack become a shutdown
See how Immune detects ransomware in seconds, contains it before it spreads, and self-heals clinical systems from immutable backups.
