EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/ransomware-attack/mgm-resorts-hack-2023
128/430

File EL-0303CriticalResolvedRansomware Attack / Double Extortion Ransomware

MGM Resorts Hack

Also filed as MGM Resorts Cyberattack · ALPHV Attack on MGM

The MGM Resorts Hack was a major ransomware attack that compromised MGM Resorts International's operational technology and corporate networks. The attackers, attributed to the Scattered Spider group, utilized ALPHV ransomware, a variant known for its aggressive double extortion tactics. The breach significantly disrupted key services, including hotel operations and gaming systems, leading to temporary closures and substantial financial losses.

  • #mgm-resorts
  • #ransomware
  • #alphv
  • #scattered-spider
  • #cyberattack
  • #double-extortion
Notoriety8/10
Event
11 Sept 2023
Disclosed
12 Sept 2023
Target
MGM Resorts International
Actor
Scattered Spider
Scale
Unknown (estimated to be large, encompassing operational and customer data)
Status
Resolved

01Summary

The incident began around September 11, 2023, when MGM Resorts detected unusual network activity indicative of a sophisticated ransomware intrusion. The attackers, operating under the moniker Scattered Spider, gained initial access and systematically moved laterally through the corporate network. They deployed the ALPHV ransomware, which encrypted critical data and systems across multiple properties. The attackers employed a double extortion model, threatening not only to encrypt the data but also to leak sensitive corporate and customer information if a ransom was not paid. The attack forced MGM to temporarily suspend non-essential services and significantly impacted guest experiences and revenue streams. The incident highlighted the vulnerability of large, complex, interconnected physical and digital infrastructure to modern ransomware threats.

02Background

MGM Resorts operates a vast, interconnected portfolio of luxury hotels and casinos, making its operational technology (OT) and IT systems highly interdependent. Historically, the industry has been a prime target for cybercriminals due to the high value of customer data and the critical nature of continuous operations. This incident capitalized on the complexity and scale of MGM's digital footprint.

03Key revelations

  1. 01The attackers successfully compromised core operational systems, leading to temporary closures of major gaming and hotel facilities.
  2. 02The use of the ALPHV ransomware variant confirmed the attackers' focus on high-impact, disruptive extortion.
  3. 03The incident demonstrated the vulnerability of large, interconnected physical infrastructure (casinos) to modern, sophisticated ransomware groups.

04Technical analysis

The attack vector was believed to involve exploiting a vulnerability or using compromised credentials to gain initial access. Once inside, the threat actors utilized sophisticated lateral movement techniques, likely involving exploiting internal network trust relationships or weak segmentation. The ALPHV ransomware was deployed, which is known for its speed and ability to target diverse file types, including backups and operational databases. The attackers also exfiltrated data before encryption, confirming the double extortion model.

Attack vector
Compromised credentials or exploited vulnerability (specific vector not publicly confirmed)
Attack method
Ransomware deployment and data exfiltration (Double Extortion)
Initial access
Compromised credentials or external-facing service exploitation
Lateral movement
Internal network traversal and privilege escalation
Persistence
Creation of backdoors or scheduled tasks (assumed)
Exfiltration
Data staging and transfer to external command and control (C2) infrastructure
Tool / malware
ALPHV
Malware family
ALPHV
Malware type
Ransomware

MITRE ATT&CK techniques

  • T1566.001
  • T1071.001
  • T1021.001

05Threat actor

Scattered Spider is a highly sophisticated, financially motivated ransomware group known for its ability to compromise large organizations through initial access brokers and exploiting human vulnerabilities. They are associated with the ALPHV ransomware strain and specialize in double extortion, ensuring maximum pressure on victims to pay the ransom.

Aliases

  • ALPHV

MITRE groups

  • T1566.001
  • T1071.001
  • T1021.001

Attribution sources

  • Mandiant
  • CISA
  • Security Industry Reports

06Victims and impact

Additional victims

  • MGM Grand Hotel & Casino
  • Garden of Dreams Casino

Countries affected

  • United States

07Data exposed

Data types

  • Customer PII
  • Financial Records
  • Operational Data
  • Internal Communications

08Financial damage

The damage estimate is complex, involving lost revenue, remediation costs, and reputational damage, but no single figure was publicly confirmed.

09Timeline

  1. 2023-09-11Initial detection of unauthorized network activity and ransomware deployment.
  2. 2023-09-12MGM Resorts publicly discloses the cyberattack and service disruptions.
  3. 2023-09-15Partial restoration of critical services begins.

10Reaction and fallout

Public reaction

The public reaction was characterized by immediate concern over service disruptions, particularly for guests relying on MGM's amenities. Media coverage focused heavily on the scale of the attack and the potential loss of personal data.

Political impact

The incident prompted increased scrutiny from state and federal regulators regarding the cybersecurity resilience of critical physical infrastructure, particularly in the gaming and hospitality sectors.

11Legal

MGM Resorts initiated internal and external forensic investigations. While no immediate criminal charges were filed against the company, the incident triggered mandatory regulatory reviews of their security posture.

Civil lawsuits

  • Potential class-action lawsuits from affected customers regarding data breaches and service disruption.

12Aftermath

Policy changes

  • Increased industry focus on network segmentation between IT and OT systems in critical infrastructure.

Regulatory changes

  • Potential tightening of state-level cybersecurity mandates for large gaming and hospitality enterprises.

Security improvements

  • Mandatory implementation of Zero Trust Architecture (ZTA) principles across corporate networks.
  • Enhanced network monitoring and behavioral analytics to detect lateral movement.

13Significance and legacy

Significance

This attack is significant because it demonstrated the direct and immediate threat ransomware poses to physical, revenue-generating infrastructure. It moved the threat from purely digital data theft to operational paralysis, forcing major corporations to confront the reality that their physical assets are only as secure as their weakest network link.

Legacy

The MGM hack contributed to a broader industry shift in cybersecurity spending, emphasizing resilience and recovery planning over mere prevention. It reinforced the necessity of robust segmentation between corporate IT and operational OT systems.

14Disclosure and media

Authentication
Industry threat intelligence reports and forensic analysis

Media partners

  • Reuters
  • The New York Times
  • TechCrunch

Publishing organisations

  • Mandiant
  • CISA

15Related files

Related events

  • Colonial Pipeline Ransomware Attack (2021)

Inspired by

  • ransomware-as-a-service models (general)

16Field notes

  1. 01The attack forced the temporary closure of several high-profile gaming and hotel amenities, impacting thousands of guests.
  2. 02The use of Scattered Spider/ALPHV highlighted the increasing trend of criminal groups targeting large, complex, and highly interconnected corporate environments.

17Resolution

MGM Resorts eventually restored services through a combination of forensic recovery, system rebuilding, and potentially paying a ransom (details unconfirmed). The company emphasized a commitment to long-term security upgrades.

18Sources

Official documents

  • MGM Resorts Public Statements (Sept 2023)

References

  1. [1]Mandiant Threat Intelligence Reports
  2. [2]Major Financial News Outlets Coverage
Fact sheetEL-0303

Dates

Event
11 Sept 2023
Started
11 Sept 2023
Ended
15 Sept 2023
Duration
5 days
Discovered
11 Sept 2023
Disclosed
12 Sept 2023
Ongoing
No

Target

Organisation
MGM Resorts International
Type
Corporation
Sector
Hospitality/Gaming
Country
United States

Actor

Name
Scattered Spider
Type
Ransomware Gang
Motivation
Financial gain through data encryption and extortion
Attribution
Medium
Status
Active
Arrested
No
Convicted
No

Data

Volume
Unknown (estimated to be large, encompassing operational and customer data)
Sensitivity
Confidential
Published
No

Money

Crypto
Bitcoin (BTC)

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.