• Home
  • News
  • Coins2Day 500
  • Tech
  • Finance
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
Tech

Over the past few weeks, MGM and Caesars were both hacked by one of the most ‘aggressive threat actors’ targeting the U.S.

By
William Turton
William Turton
,
Christopher Palmeri
Christopher Palmeri
,
Katrina Manson
Katrina Manson
and
Bloomberg
Bloomberg
Down Arrow Button Icon
By
William Turton
William Turton
,
Christopher Palmeri
Christopher Palmeri
,
Katrina Manson
Katrina Manson
and
Bloomberg
Bloomberg
Down Arrow Button Icon
September 13, 2023, 6:58 PM ET
The Park MGM hotel and casino in Las Vegas.
The Park MGM hotel and casino in Las Vegas.Bridget Bennett/Bloomberg via Getty Images

MGM Resorts International was hacked by the same group of attackers that breached Caesars Entertainment weeks earlier, according to four people familiar with the matter.

Recommended Video

The hackers demanded a ransom from MGM, according to two of the people. It wasn’t immediately clear how much ransom was requested or if the hackers deployed ransomware to lock up the company’s files.

Caesars didn’t respond to messages seeking comment, but the company is expected to disclose the cyberattack imminently in a regulatory filing. 

MGM declined to respond to questions about the attack. In a statement on Tuesday, MGM said the investigation is ongoing. The company said it was continuing to implement measures to secure its business operations.

MGM was still working to resolve the turmoil caused by the hackers, known as Scattered Spider, four days into the cyberattack that has disrupted the company’s websites, reservation system and some slot machines at its casinos across the country, according to two of the people.

Caesars was also hacked by the same group in a cyberattack a few weeks earlier, and ended up paying tens of million of dollars to the hackers, according to the people, who asked not to be identified because the information is private. The hackers first breached an outside IT vendor before gaining access to the company’s network, two of the people said.

Scattered Spider, which is also known as UNC3944, is composed of hackers who are based in the US and UK, some as young as 19 years old, according to a cybersecurity researcher familiar with the group. The group has targeted telecommunications and business process outsourcing companies to pull off SIM swaps of phone numbers that can then be used in phishing attacks to steal data from victim systems and extort a ransom.

Charles Carmakal, chief technical officer for Mandiant Inc., part of Google Cloud, described the hackers as “one of the most prevalent and aggressive threat actors impacting organizations in the United States today.” Mandiant first came across the group in May 2022.

He said many of the members of the group are young native English speakers who are “incredibly effective social engineers.” They have started deploying ransomware encryptors and sometimes expose victims on infrastructure used by another hacking group, ALPHV. 

The FBI said in April 2022 the group had leased its ransomware to others that has resulted in compromises of at least 60 entities worldwide.

In the MGM hack, Scattered Spider may have worked with ALPHV, according to two people familiar with the group’s operations.

Hackers use several different techniques to extort victims for money.

For instance, ransomware is a type of malware that locks up a victim’s computer files. The hackers then promise to provide a decryption key if an extortion fee is paid.

More recently, hacking groups have shifted away from ransomware and instead focused on stealing sensitive data from victims. They then threaten to release the information online unless they are paid.

Coins2Day Brainstorm AI returns to San Francisco Dec. 8–9 to convene the smartest people we know—technologists, entrepreneurs, Coins2Day Global 500 executives, investors, policymakers, and the brilliant minds in between—to explore and interrogate the most pressing questions about AI at another pivotal moment. Register here.
About the Authors
By William Turton
See full bioRight Arrow Button Icon
By Christopher Palmeri
See full bioRight Arrow Button Icon
By Katrina Manson
See full bioRight Arrow Button Icon
By Bloomberg
See full bioRight Arrow Button Icon
Rankings
  • 100 Best Companies
  • Coins2Day 500
  • Global 500
  • Coins2Day 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Coins2Day Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Coins2Day Brand Studio
  • Coins2Day Analytics
  • Coins2Day Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Coins2Day
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Coins2Day Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Coins2Day Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.