Immune — Self Heal, an iStudio Technologies product

Hospitality · United States · September 2023

MGM Resorts Ransomware Attack

In September 2023, a ransomware attack on MGM Resorts — enabled by a phone call to the IT help desk — disrupted hotels and casinos across Las Vegas and beyond for around ten days, at a reported cost near US$100 million.

What happened

In September 2023, MGM Resorts — one of the largest hospitality and casino operators in the world — was struck by a ransomware attack that became a defining example of how modern intrusions often begin not with sophisticated malware, but with a convincing phone call. The attack was attributed in reporting to the group known as Scattered Spider, working in concert with the ALPHV/BlackCat ransomware operation.

According to widely-reported accounts, the attackers gained their foothold through social engineering: they reportedly called MGM's IT help desk, impersonated an employee, and persuaded staff to reset credentials — handing the intruders legitimate access. From there they escalated privileges and moved through MGM's environment.

As the intrusion was discovered, MGM took large portions of its systems offline. The result was chaos across its properties: hotel room-key systems, slot machines, booking and reservation platforms, and other digital services went down across Las Vegas and beyond.

The impact

The disruption was highly visible and lasted around ten days. Guests reported being unable to check in digitally or use electronic room keys; slot machines sat idle; reservation and loyalty systems were unavailable; and staff reverted to manual processes across hotels and casinos. For a business whose revenue is measured by the hour, the operational hit was enormous.

MGM reported a financial impact of roughly US$100 million from the incident, encompassing lost revenue during the disruption and the costs of response and remediation. Notably, MGM was reported not to have paid a ransom — which meant the cost was borne almost entirely in operational disruption and recovery rather than extortion.

Some customer data was reportedly affected, adding a data-breach dimension and subsequent litigation to the operational damage. The incident, alongside a contemporaneous attack on Caesars Entertainment, became a wake-up call about the potency of help-desk social engineering.

How the attack unfolded

  • Initial access: attackers reportedly called the IT help desk, impersonated an employee, and got credentials reset — a social-engineering foothold, not malware.
  • Privilege escalation: the intruders expanded access across MGM's identity and cloud environment.
  • Impact: MGM took systems offline as ransomware was deployed, disrupting hotel and casino operations for around ten days.
  • Extortion: MGM reportedly declined to pay, absorbing the cost as operational disruption.

The recovery

MGM restored systems over roughly ten days, bringing properties back online in stages while operating manually in the interim. The company absorbed the substantial revenue loss rather than paying the attackers.

The incident cemented social engineering of help desks and identity systems as a primary attack path, and pushed the industry toward stronger identity-verification controls for privileged access requests.

How this attack could have been contained

The help-desk social-engineering entry point produces a telltale signature: a legitimate credential suddenly behaving abnormally. Immune's continuous access verification is designed to catch exactly this — scoring behavior after login, so a freshly-reset credential reaching unusual systems is flagged even though the authentication itself was valid.

The rapid privilege escalation and lateral movement that followed are what Immune's network monitoring and behavioral detection target, aiming to surface the intrusion during escalation rather than after systems are taken offline.

And MGM's ten days of disruption is the kind of outage containment and self-healing recovery are built to shorten — isolating the compromised segment and restoring validated systems in order, so an identity compromise does not become a multi-day operational shutdown.

Sources

Figures are drawn from public reporting and official disclosures and are presented as reported or estimated; they may be updated as further details become public.

Protect against attacks like this

How to defend against hospitality ransomware

Don't let an attack become a shutdown

See how Immune detects ransomware in seconds, contains it before it spreads, and self-heals clinical systems from immutable backups.

Talk to us

See Immune protect your organization

Tell us about your environment and our team will show you exactly how Immune detects, contains, and self-heals through a ransomware attack — including the connected devices your current tools can't reach. We respond within one business day.

  • A working demo on a realistic scenario
  • Agentless coverage for medical and connected devices
  • On-premises and data-sovereignty deployment options
  • A frank look at where Immune fits alongside your stack

Request your demo

Tell us a little about your organization and we'll be in touch.

By submitting, you agree to be contacted about Immune. We respect your privacy and never share your details. See our privacy policy.