Recommended Free Tools
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
MGM Resorts’ September 2023 cyberattack caused a severe, multi-day disruption—not a clearly established 36-hour outage. MGM shut down some systems to contain the incident; the Associated Press reported that the broader computer shutdown lasted about 10 days, with systems back up by September 20. The disruption affected hotel and casino operations, and MGM later said the incident exposed some customer information and reduced third-quarter adjusted property EBITDAR by about $100 million.
What happened at MGM Resorts?
MGM detected a cybersecurity incident in September 2023 and shut down certain systems as a containment measure. The company’s September 12 statement called it a “cybersecurity issue,” said an investigation was under way and that law enforcement had been notified. Its SEC filing described effects on certain U.S. systems. That qualification matters: the disclosures do not establish that every MGM property worldwide was affected in the same way.
Taking systems offline can be a defensive choice: limiting access may help contain an intrusion, but it can also interrupt ordinary business. At a large resort, hotel check-in, room access, reservations, payments, loyalty services and casino operations rely on digital services. If interconnected systems are unavailable, staff may have to fall back on manual workarounds while the company investigates and safely restores service.
How long did the disruption last?
The full incident was not simply a 36-hour outage. Contemporary accounts and company disclosures place detection and shutdown around September 10–11, followed by a public announcement on September 11–12. The Associated Press reported that MGM’s broader computer shutdown lasted about 10 days and that systems were back up on September 20. MGM CEO Bill Hornbuckle later described the first four or five days as a period when the company was effectively “in the dark.” These descriptions refer to different stages: the worst operational disruption was concentrated in the early days, while the broader shutdown lasted longer. They do not show that every service recovered at once.
#1 Best Overall
| Date | What was reported |
|---|---|
| September 10–11, 2023 | MGM detected the incident and began shutting down certain systems, according to contemporary reporting and subsequent company disclosures. MGM statement |
| September 11–12, 2023 | MGM publicly disclosed a cybersecurity issue affecting certain U.S. systems. SEC filing |
| September 2023 | Hotel, casino, reservation, payment, loyalty and website functions experienced disruption. Axios |
| September 20, 2023 | The Associated Press reported that MGM’s computer systems were back up after a roughly 10-day shutdown. AP |
| September 29–October 5, 2023 | MGM determined that an unauthorized third party had obtained some customer information on September 11, then disclosed categories of information that could have been involved. MGM update |
| October 5–6, 2023 | MGM disclosed an estimated $100 million third-quarter adjusted-property-EBITDAR impact and less than $10 million in one-time expenses. SEC filing |
What did guests and casino customers experience?
Reports described impaired or unavailable slot machines, digital room keys, hotel check-in and other resort functions. Guests also encountered problems with reservations, payment processing, ATMs, websites and loyalty-program services. Delays, queues and uncertainty about reservations or charges were practical consequences of systems that staff could not use normally. The Associated Press reported that the shutdown affected systems used for reservations and credit-card processing, while Axios’ contemporary account documented guest-facing problems.
This was an availability problem as well as a security investigation: customers could be unable to use services even where their own account information was not shown to be involved. A containment shutdown can therefore produce an outage without implying that attackers directly disabled every affected device or property.
Was it a cyberattack, a data breach or ransomware?
Those labels describe different aspects of the incident. MGM initially used the broad term “cybersecurity issue.” Unauthorized access to systems is an intrusion; the later disclosure that some customer information had been obtained makes data exposure a separate part of the story. Public reporting connected the incident to ransomware activity, but MGM’s public disclosures did not provide a complete technical account that settles every detail of how the attack unfolded.
Scattered Spider, also known as UNC3944 in some reporting, and the ALPHV/BlackCat ransomware operation were associated with the incident in news coverage and claims. That is not the same as a formal public law-enforcement finding establishing the identity and role of every attacker. The Associated Press covered alleged group links in its report on MGM and Caesars; TechCrunch reported on a claim of responsibility. Treat those accounts as reporting and claims, not as proof of a definitive attribution.
Rank #3
How did attackers reportedly get in?
Social engineering—deceiving staff or support processes into granting access—has been reported as a possible route. A 2025 consolidated complaint alleges that hackers impersonated an IT administrator and obtained credentials. A complaint states allegations, not findings established by a court; the filing does not by itself prove the exact initial-access method. The allegation appears in the 2025 consolidated complaint.
The broader security lesson is that identity checks and help-desk procedures can become critical entry points. If an attacker obtains a valid identity or credentials, the risk can extend beyond one employee’s workstation in an organization whose services depend on connected enterprise systems. The public record cited here does not provide a complete MGM network diagram or establish precisely how the intrusion spread.
Rank #4
Restoring service after a serious incident is also more involved than simply turning systems back on. In general, organizations need to investigate affected systems, check their integrity, rebuild or remediate where needed, and validate systems before reconnecting them. This explains why containment and recovery can disrupt operations even after the initial access has been stopped; it is general recovery context, not a claim about MGM’s specific internal procedures.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →What customer information did MGM say was involved?
On October 5, MGM said an unauthorized third party had obtained some customer information on September 11. Its update said the information could include names, contact details, gender, dates of birth and driver’s-license numbers. For a limited number of customers, Social Security and/or passport numbers were also involved. MGM did not say that every customer or every category applied to every affected person.
Best Value
MGM said it did not believe passwords, bank-account numbers or payment-card information were affected. That is the company’s stated assessment, not an independent guarantee that every risk to customers was eliminated. Contact details and identity information can still be used in targeted phishing or other fraud attempts. MGM’s account of the categories and its assessment is in its October 5 update.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What did the incident cost MGM?
MGM estimated a roughly $100 million negative impact to adjusted property EBITDAR for its Las Vegas Strip resorts and regional operations in September 2023. EBITDAR is an operating-performance measure; this figure is not the same as $100 million in cash paid out, a ransom payment, or the complete cost of the incident. MGM separately estimated less than $10 million in one-time third-quarter expenses, including technology consulting, legal fees and other advisers. The figures appear in the company’s SEC Form 8-K; the Associated Press also reported the financial impact.
These disclosed amounts do not capture every possible longer-term consequence, such as subsequent legal costs, insurance recoveries, remediation work or reputational effects. MGM’s later 2023 Form 10-K continued to discuss related claims, investigations, remediation, restoration and cybersecurity-insurance recovery as matters involving risk or uncertainty.
Did MGM pay a ransom, and was this the same incident as Caesars?
The available official MGM disclosures cited here do not establish a ransom payment. Contemporary reporting said MGM refused the attackers’ demand; separate reporting said Caesars, another casino operator targeted around the same time, paid a negotiated ransom. Those accounts are attributed reporting, not a complete official account of either company’s negotiations. The incidents were separate corporate events, even though coverage linked them to overlapping threat actors. The Associated Press comparison discusses both companies.
What happened after systems came back?
Service restoration did not end the privacy, legal or security consequences. MGM said it notified affected individuals and offered identity-protection or credit-monitoring services to those affected. Its SEC filings continued to describe remediation and related claims and investigations. Lawsuits and settlement-related proceedings also followed. The U.S. litigation site says its matters concern both MGM’s 2019 and September 2023 incidents, so its descriptions should not be read as proof that every listed data category applied to every person in the 2023 event. See the U.S. litigation FAQ for its description of the proceedings. A separate Canadian settlement site concerns Canadian proceedings. Settlement administration and court schedules can change, so check the relevant official site for current status rather than relying on older coverage.
Quick Recap
What should affected customers do?
- Use MGM’s direct notices and official account channels to determine whether you were identified as affected and whether a protection offer applies to you.
- Be alert for messages that imitate MGM, a hotel, a loyalty program or an identity-monitoring provider. Do not follow unexpected links or share verification codes in response to unsolicited contact.
- Review financial and loyalty accounts for unfamiliar activity, even though MGM said it did not believe bank-account or payment-card information was affected.
- Change reused passwords on relevant accounts and enable multifactor authentication where available.
- Consider reviewing credit reports and using available credit protections if your notice indicates that sensitive identity information such as a Social Security or driver’s-license number was involved.
- Verify any settlement or credit-monitoring message through the official MGM or court-authorized site rather than an unsolicited email or text.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

