MGM Casino Group fell victim to "Oceans 11" Style Ransom Ware / Hack. UPDATE: CAESARS hacked too!!

D24OHA

Rising Star
BGOL Investor

Thus affected the mgm.com domain, the main casino and others in their group.


Just some of the good parts from the article

Scattered Spider’s members are thought to be in their late teens and early 20s, based in Europe and possibly the US, and fluent in English — which makes their vishing attempts much more convincing than, say, a call from someone with a Russian accent and only a working knowledge of English. In this case, it appears that the hackers found an employee’s information on LinkedIn and impersonated them in a call to MGM’s IT help desk to obtain credentials to access and infect the systems.infect the systems.

Someone claiming to be a representative of the group told the Financial Times that it stole and encrypted MGM’s data and is demanding a payment in crypto to release it. This was the backup plan; the group initially planned to hack the company’s slot machines but weren’t able to, the representative claimed.


If that all has you thinking that we’re in the middle of a remake of Ocean’s 13, you should also know that it may not be accurate. ALPHV/BlackCat is denying parts of these reports, especially the slot machine hacking attempt. The group posted a message on Thursday night claiming responsibility for the attack but denying that it was perpetrated by teenagers in the US and Europe or that anyone tried to tamper with slot machines. It also criticized what it said was inaccurate reporting on the hack and said it hadn’t officially spoken to anyone about the hack, and “most likely” wouldn’t in the future. The message said that data was stolen from MGM, which has thus far refused to engage with the hackers or pay any kind of ransom.

It seems that MGM wasn’t the only casino chain hit by a recent cyberattack. Caesars Entertainment paid millions of dollars to hackers who breached its systems around the same time as MGM and was able to continue operations as normal. Caesars admitted to the breach in a filing with the Securities and Exchange Commission on Thursday, where it said an “outsourced IT support vendor” was the victim of a “social engineering attack” that resulted in sensitive data about members of its customer loyalty program being stolen. Though the method is very similar to those reportedly used by Scattered Spider and the attack happened at nearly the same time as MGM’s, the alleged representative of the group told the Financial Times that it wasn’t behind it.
 

D24OHA

Rising Star
BGOL Investor
Caesars was also hit by a similar attack but Caesars paid the bounty and suffered no interruption in online / hotel service....





Information about Caesars....






They paid about $15 million to get their access back.



If you were on either site or their physical properties l, apart of their membership programs...etc



Get your credit checked and / or buy identity protection!!
 

34real

Rising Star
BGOL Investor
Good stealing back some of the money they stole from people that come there to win.

You gotta pay one way or another and they don't need a gun or a ski mask.....nobody moves,nobody gets hurt.
 

bkqns718

Rising Star
BGOL Investor
The MGM hack they were able to impersonate an MGM OT employee with easily available information....

The Caesars hack they impersonated an IT contractor and did the same.....

It's looking like major systems upgrades are in order......which would equal $$$$ for those already in the business.
If you are in the field learn how to design a Zero Trust solution with all the third 3rd party crap/cloud vendors out there..........$$$$$$$$$$
 

easy_b

Easy_b is in the place to be.
BGOL Investor
Yeah but its Russia......

These mfkrs getting way too comfortable hacking us
This is why I’m glad the United States nuclear bombs are still on an analog sequence because you know what would have happened if they would have made that completely digital.
 
Top