Free tools Windows power users keep installed
One-click scans. No signup required.
MGM Resorts and Caesars Entertainment were hit within days of each other in September 2023, but they did not suffer identical attacks. Caesars primarily disclosed the theft of loyalty-program data after social engineering involving an outsourced IT-support provider. MGM shut down systems after unauthorized access, causing a highly visible operational outage and an estimated $100 million impact on September adjusted-property EBITDAR.
Both incidents were widely linked to the English-speaking cybercriminal cluster known as Scattered Spider, also tracked under names including UNC3944 and Octo Tempest, and to the broader ALPHV/BlackCat ransomware ecosystem. That attribution is not the same as proof that one coordinated group carried out every part of both intrusions.
The short version
| Issue | MGM Resorts | Caesars Entertainment |
|---|---|---|
| First key date | Incident detected around September 10, 2023; public statement September 12 | Unauthorized actor identified as having obtained loyalty data by September 7; public filing September 14 |
| Initial access | Public disclosures initially provided limited detail about the unauthorized access | Social engineering of an outsourced IT-support vendor |
| Operational effect | Systems were shut down, disrupting casino, hotel, payment, reservation and digital operations | Casino, hotel, online-gaming and mobile-gaming operations continued without reported disruption |
| Information exposed | Names, contact details, dates of birth, driver’s-license numbers and, for a limited number, Social Security and passport numbers | Loyalty-program records containing driver’s-license numbers and/or Social Security numbers for a significant number of members |
| Payment-card information | MGM said it did not believe it was obtained | Caesars said it had no evidence it was acquired |
| Ransom reporting | No public confirmation of a ransom payment | Approximately $15 million reportedly paid against a $30 million demand; not confirmed in the initial SEC filing |
| Financial effect | Approximately $100 million in September adjusted-property EBITDAR impact, plus less than $10 million in one-time third-party expenses | Caesars said the incident did not disrupt operations and later characterized it as not material to operations or financial condition |
The central financial lesson is that a cyberattack can create two very different kinds of loss: immediate business interruption, as at MGM, or longer-tail privacy, fraud, litigation and regulatory exposure, as at Caesars.
Caesars came first
Caesars said its investigation determined that an unauthorized actor acquired a copy of its loyalty-program database on or about September 7, 2023. The company attributed the intrusion to social engineering against an outsourced IT-support vendor.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
Caesars disclosed the incident in a September 14 Form 8-K. The filing said physical properties, online gaming and mobile gaming continued without disruption. Caesars also said it notified law enforcement and state gaming regulators.
The stolen database included driver’s-license numbers and/or Social Security numbers for a significant number of loyalty-program members. Caesars said it had no evidence that passwords or PINs, bank-account information or payment-card data had been acquired. That wording matters: “no evidence acquired” does not prove that every category of payment information was technically inaccessible.
MGM’s systems go dark
MGM publicly announced a cybersecurity issue on September 12, 2023, after detecting the incident around September 10 according to contemporary reporting. Its initial statement said the company had taken certain systems offline as part of its response. MGM filed a related Form 8-K on September 13.
The shutdown contained the threat but made the incident visible to customers. Contemporary reporting described disruptions involving reservations, payment systems, ATMs, slot machines, digital services and other property operations. Systems were reported to be largely back online after roughly ten days, although restoration did not necessarily mean every system returned simultaneously.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesRank #2
MGM later estimated an approximately $100 million reduction in September adjusted-property EBITDAR for its Las Vegas Strip and regional operations. It also reported less than $10 million in one-time third-party expenses during the quarter. The figure is MGM’s own accounting estimate, not a universal measure of the attack’s total economic cost: legal work, customer remediation, insurance effects, regulatory matters and reputational damage may extend beyond it. See MGM’s financial-impact filing.
What data was exposed?
MGM
In its 2023 Form 10-K, MGM said affected information could include names, phone numbers, email addresses, postal addresses, gender, dates of birth and driver’s-license numbers. For a limited number of customers, Social Security and passport numbers were also involved. MGM said it did not believe customer passwords, bank-account numbers or payment-card information had been obtained. The affected information varied by person; not every customer was exposed to every category. Source: MGM’s 2023 Form 10-K.
Caesars
Caesars said the compromised loyalty database included driver’s-license numbers and/or Social Security numbers for a significant number of members. It reported no evidence that passwords or PINs, bank-account information or payment-card data had been acquired. Government-issued identification numbers and Social Security numbers can nevertheless create long-term identity-theft and fraud risks even when payment cards are not involved.
Who was Scattered Spider?
Scattered Spider is a widely used label for a cybercriminal cluster. Security reporting and government materials also associate the activity with names such as UNC3944 and Octo Tempest. Those labels can reflect overlapping activity, tracking conventions or related operators; they should not automatically be treated as interchangeable legal entities.
Rank #3
The FBI and CISA advisory AA23-320A describes tactics associated with Scattered Spider, including help-desk impersonation, credential theft, commercial remote-access tools, cloud-based data exfiltration, extortion and ransomware deployment. It is a general technical advisory, not a complete public post-incident report for MGM or Caesars.
ALPHV, also called BlackCat, is best described as a ransomware operation or ecosystem. Terms such as affiliate, partner, subgroup and operator are not interchangeable. The most defensible description is that the casino incidents were widely associated with Scattered Spider and the broader ALPHV/BlackCat ecosystem, while the precise roles and sequence remain less certain than many headlines suggest.
How the help-desk attack path works
The important technical weakness was not necessarily an exotic software vulnerability. A typical identity-driven sequence can look like this:
- An attacker identifies an employee or contractor who has access to identity, support or administrative systems.
- The attacker impersonates that person or persuades a help-desk worker to reset credentials, enroll a device or bypass an authentication step.
- Using apparently legitimate credentials and remote-access tools, the attacker searches for valuable systems and data.
- The attacker escalates privileges and moves laterally through the environment.
- The campaign ends in data theft and extortion, encryption, operational disruption, or a combination of these.
Phishing-resistant authentication, strict identity verification and controls on account recovery are therefore as important as endpoint defenses. A strong identity provider cannot compensate for a help-desk process that allows social pressure to override authentication safeguards.
Rank #4
Was it ransomware?
The careful answer is that both incidents were commonly described as ransomware-linked or cyber-extortion attacks, but the companies’ own disclosures were more cautious.
Caesars’ filing describes social engineering, unauthorized access and theft of its loyalty database. It does not say that Caesars’ systems were encrypted or taken offline. MGM described a cybersecurity issue, system shutdowns, operational disruption and customer-data theft, but its public filings did not explicitly confirm ransomware.
Modern criminal campaigns do not require encryption to cause harm. Attackers may steal data and threaten publication, encrypt systems, disrupt operations, or use several of these methods together. A ransom payment also does not prove that systems were encrypted, and paying does not undo the theft or guarantee that copies are deleted.
Media reports, including an Associated Press report, said Caesars paid approximately $15 million toward a $30 million demand. That should be treated as reported rather than as a company-confirmed fact from the initial SEC disclosure.
Best Value
Why the financial outcomes diverged
MGM’s decision to isolate and shut down systems likely reduced the risk of continued unauthorized activity, but it transferred the cost into immediate operational disruption. Lost gaming, hotel and food-and-beverage activity, manual workarounds, restoration, consulting and customer support all contributed to the financial impact.
Caesars preserved customer-facing continuity, but continuity was not the same as security. Its systems remained usable while sensitive loyalty records were reportedly obtained. That creates a different risk profile: potential identity theft, notification and remediation costs, lawsuits, regulator attention and reputational effects that may appear over a longer period.
For consumers and investors, “no operational disruption” should never be read as “no meaningful breach.” Conversely, MGM’s visible outage should not be interpreted as proof that every customer’s personal information was exposed.
What these incidents reveal about corporate security
- Help-desk recovery is a privileged operation. Password resets, device enrollment and multifactor-authentication changes should require robust, independent verification.
- Third-party access expands the attack surface. Outsourcing IT support can improve scale and expertise, but it creates an additional identity and access dependency.
- Phishing-resistant MFA is stronger than SMS or voice verification. FIDO2 security keys and other phishing-resistant methods reduce some identity attacks, although recovery procedures still need protection.
- Segmentation limits blast radius. Critical gaming, hotel, payment and identity systems should not all be reachable through one compromised account.
- Isolation has a price. Rapid shutdown can protect systems while causing immediate revenue loss. Business-continuity planning determines how painful that trade-off becomes.
- Incident communications affect trust. Early disclosure helps customers and investors, but companies must distinguish confirmed facts from evolving investigative findings.
What remains uncertain
The public record does not establish every detail of either intrusion. Important unresolved questions include the precise initial compromise paths, the exact malware or ransomware sequence, the division of labor among Scattered Spider and ALPHV-associated operators, the full scope of stolen data, the terms of any ransom negotiation, whether stolen data was deleted and the final legal and regulatory consequences.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Accordingly, the strongest claims come from the companies’ SEC filings: disclosure dates, known information categories, operational effects and MGM’s financial estimate. The FBI/CISA advisory is strongest for general threat-actor techniques. Ransom details and some attribution claims rely on reputable secondary reporting and should remain qualified.
What affected customers should take away
People who were notified by MGM or Caesars should treat the incident as an identity-risk event even if payment-card data was not implicated. Review breach notices carefully, place fraud alerts or credit freezes where appropriate, monitor credit reports and financial accounts, and be skeptical of follow-up calls or emails claiming to provide compensation, account recovery or loyalty-program assistance.
Attackers who obtain names, contact details and identity numbers can use them to make later impersonation attempts more convincing. Never provide one-time codes or change account-recovery details solely because someone claiming to be a casino, bank or support representative contacts you unexpectedly.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →




