Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Titans in crisis: unraveling the MGM and Caesars ransomware timeline

MGM and Caesars were hit within days in September 2023, but the incidents differed sharply: MGM suffered a major operational outage, while Caesars disclosed loyalty-data theft without reported disruption.
From TheFinanceBase Team7 min to read

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

MGM Resorts and Caesars Entertainment were hit within days of each other in September 2023, but they did not suffer identical attacks. Caesars primarily disclosed the theft of loyalty-program data after social engineering involving an outsourced IT-support provider. MGM shut down systems after unauthorized access, causing a highly visible operational outage and an estimated $100 million impact on September adjusted-property EBITDAR.

Both incidents were widely linked to the English-speaking cybercriminal cluster known as Scattered Spider, also tracked under names including UNC3944 and Octo Tempest, and to the broader ALPHV/BlackCat ransomware ecosystem. That attribution is not the same as proof that one coordinated group carried out every part of both intrusions.

The short version

Issue MGM Resorts Caesars Entertainment
First key date Incident detected around September 10, 2023; public statement September 12 Unauthorized actor identified as having obtained loyalty data by September 7; public filing September 14
Initial access Public disclosures initially provided limited detail about the unauthorized access Social engineering of an outsourced IT-support vendor
Operational effect Systems were shut down, disrupting casino, hotel, payment, reservation and digital operations Casino, hotel, online-gaming and mobile-gaming operations continued without reported disruption
Information exposed Names, contact details, dates of birth, driver’s-license numbers and, for a limited number, Social Security and passport numbers Loyalty-program records containing driver’s-license numbers and/or Social Security numbers for a significant number of members
Payment-card information MGM said it did not believe it was obtained Caesars said it had no evidence it was acquired
Ransom reporting No public confirmation of a ransom payment Approximately $15 million reportedly paid against a $30 million demand; not confirmed in the initial SEC filing
Financial effect Approximately $100 million in September adjusted-property EBITDAR impact, plus less than $10 million in one-time third-party expenses Caesars said the incident did not disrupt operations and later characterized it as not material to operations or financial condition

The central financial lesson is that a cyberattack can create two very different kinds of loss: immediate business interruption, as at MGM, or longer-tail privacy, fraud, litigation and regulatory exposure, as at Caesars.

Caesars came first

Caesars said its investigation determined that an unauthorized actor acquired a copy of its loyalty-program database on or about September 7, 2023. The company attributed the intrusion to social engineering against an outsourced IT-support vendor.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Caesars disclosed the incident in a September 14 Form 8-K. The filing said physical properties, online gaming and mobile gaming continued without disruption. Caesars also said it notified law enforcement and state gaming regulators.

The stolen database included driver’s-license numbers and/or Social Security numbers for a significant number of loyalty-program members. Caesars said it had no evidence that passwords or PINs, bank-account information or payment-card data had been acquired. That wording matters: “no evidence acquired” does not prove that every category of payment information was technically inaccessible.

MGM’s systems go dark

MGM publicly announced a cybersecurity issue on September 12, 2023, after detecting the incident around September 10 according to contemporary reporting. Its initial statement said the company had taken certain systems offline as part of its response. MGM filed a related Form 8-K on September 13.

The shutdown contained the threat but made the incident visible to customers. Contemporary reporting described disruptions involving reservations, payment systems, ATMs, slot machines, digital services and other property operations. Systems were reported to be largely back online after roughly ten days, although restoration did not necessarily mean every system returned simultaneously.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

MGM later estimated an approximately $100 million reduction in September adjusted-property EBITDAR for its Las Vegas Strip and regional operations. It also reported less than $10 million in one-time third-party expenses during the quarter. The figure is MGM’s own accounting estimate, not a universal measure of the attack’s total economic cost: legal work, customer remediation, insurance effects, regulatory matters and reputational damage may extend beyond it. See MGM’s financial-impact filing.

What data was exposed?

MGM

In its 2023 Form 10-K, MGM said affected information could include names, phone numbers, email addresses, postal addresses, gender, dates of birth and driver’s-license numbers. For a limited number of customers, Social Security and passport numbers were also involved. MGM said it did not believe customer passwords, bank-account numbers or payment-card information had been obtained. The affected information varied by person; not every customer was exposed to every category. Source: MGM’s 2023 Form 10-K.

Caesars

Caesars said the compromised loyalty database included driver’s-license numbers and/or Social Security numbers for a significant number of members. It reported no evidence that passwords or PINs, bank-account information or payment-card data had been acquired. Government-issued identification numbers and Social Security numbers can nevertheless create long-term identity-theft and fraud risks even when payment cards are not involved.

Who was Scattered Spider?

Scattered Spider is a widely used label for a cybercriminal cluster. Security reporting and government materials also associate the activity with names such as UNC3944 and Octo Tempest. Those labels can reflect overlapping activity, tracking conventions or related operators; they should not automatically be treated as interchangeable legal entities.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The FBI and CISA advisory AA23-320A describes tactics associated with Scattered Spider, including help-desk impersonation, credential theft, commercial remote-access tools, cloud-based data exfiltration, extortion and ransomware deployment. It is a general technical advisory, not a complete public post-incident report for MGM or Caesars.

ALPHV, also called BlackCat, is best described as a ransomware operation or ecosystem. Terms such as affiliate, partner, subgroup and operator are not interchangeable. The most defensible description is that the casino incidents were widely associated with Scattered Spider and the broader ALPHV/BlackCat ecosystem, while the precise roles and sequence remain less certain than many headlines suggest.

How the help-desk attack path works

The important technical weakness was not necessarily an exotic software vulnerability. A typical identity-driven sequence can look like this:

  1. An attacker identifies an employee or contractor who has access to identity, support or administrative systems.
  2. The attacker impersonates that person or persuades a help-desk worker to reset credentials, enroll a device or bypass an authentication step.
  3. Using apparently legitimate credentials and remote-access tools, the attacker searches for valuable systems and data.
  4. The attacker escalates privileges and moves laterally through the environment.
  5. The campaign ends in data theft and extortion, encryption, operational disruption, or a combination of these.

Phishing-resistant authentication, strict identity verification and controls on account recovery are therefore as important as endpoint defenses. A strong identity provider cannot compensate for a help-desk process that allows social pressure to override authentication safeguards.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Was it ransomware?

The careful answer is that both incidents were commonly described as ransomware-linked or cyber-extortion attacks, but the companies’ own disclosures were more cautious.

Caesars’ filing describes social engineering, unauthorized access and theft of its loyalty database. It does not say that Caesars’ systems were encrypted or taken offline. MGM described a cybersecurity issue, system shutdowns, operational disruption and customer-data theft, but its public filings did not explicitly confirm ransomware.

Modern criminal campaigns do not require encryption to cause harm. Attackers may steal data and threaten publication, encrypt systems, disrupt operations, or use several of these methods together. A ransom payment also does not prove that systems were encrypted, and paying does not undo the theft or guarantee that copies are deleted.

Media reports, including an Associated Press report, said Caesars paid approximately $15 million toward a $30 million demand. That should be treated as reported rather than as a company-confirmed fact from the initial SEC disclosure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why the financial outcomes diverged

MGM’s decision to isolate and shut down systems likely reduced the risk of continued unauthorized activity, but it transferred the cost into immediate operational disruption. Lost gaming, hotel and food-and-beverage activity, manual workarounds, restoration, consulting and customer support all contributed to the financial impact.

Caesars preserved customer-facing continuity, but continuity was not the same as security. Its systems remained usable while sensitive loyalty records were reportedly obtained. That creates a different risk profile: potential identity theft, notification and remediation costs, lawsuits, regulator attention and reputational effects that may appear over a longer period.

For consumers and investors, “no operational disruption” should never be read as “no meaningful breach.” Conversely, MGM’s visible outage should not be interpreted as proof that every customer’s personal information was exposed.

What these incidents reveal about corporate security

  • Help-desk recovery is a privileged operation. Password resets, device enrollment and multifactor-authentication changes should require robust, independent verification.
  • Third-party access expands the attack surface. Outsourcing IT support can improve scale and expertise, but it creates an additional identity and access dependency.
  • Phishing-resistant MFA is stronger than SMS or voice verification. FIDO2 security keys and other phishing-resistant methods reduce some identity attacks, although recovery procedures still need protection.
  • Segmentation limits blast radius. Critical gaming, hotel, payment and identity systems should not all be reachable through one compromised account.
  • Isolation has a price. Rapid shutdown can protect systems while causing immediate revenue loss. Business-continuity planning determines how painful that trade-off becomes.
  • Incident communications affect trust. Early disclosure helps customers and investors, but companies must distinguish confirmed facts from evolving investigative findings.

What remains uncertain

The public record does not establish every detail of either intrusion. Important unresolved questions include the precise initial compromise paths, the exact malware or ransomware sequence, the division of labor among Scattered Spider and ALPHV-associated operators, the full scope of stolen data, the terms of any ransom negotiation, whether stolen data was deleted and the final legal and regulatory consequences.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Accordingly, the strongest claims come from the companies’ SEC filings: disclosure dates, known information categories, operational effects and MGM’s financial estimate. The FBI/CISA advisory is strongest for general threat-actor techniques. Ransom details and some attribution claims rely on reputable secondary reporting and should remain qualified.

What affected customers should take away

People who were notified by MGM or Caesars should treat the incident as an identity-risk event even if payment-card data was not implicated. Review breach notices carefully, place fraud alerts or credit freezes where appropriate, monitor credit reports and financial accounts, and be skeptical of follow-up calls or emails claiming to provide compensation, account recovery or loyalty-program assistance.

Attackers who obtain names, contact details and identity numbers can use them to make later impersonation attempts more convincing. Never provide one-time codes or change account-recovery details solely because someone claiming to be a casino, bank or support representative contacts you unexpectedly.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.