No Results Found.
The page you requested could not be found. Try refining your search, or use the navigation above to locate the post.
Jake McGreevy
•
October 18, 2023
You may have seen it in the news, but another major company has been a victim of a nasty ransomware attack that disrupted services and customers for over ten days. This time, the victim was MGM Resorts in Las Vegas.
What separates this major incident from others is that the hackers pulled the malicious attack off using one of the oldest tricks in the book: social engineering. So, what happened, and what can we learn from this?

From what is made public, the attack started with some simple Open-Source Intelligence (OSINT) against MGM and their resorts, searching for potential privileged employees on websites such as LinkedIn. Then, the attackers spoofed the employee and called the IT Help Desk at MGM to reset the user’s credentials and multi-factor authentication (MFA). Once in control of the elevated account, the attackers assigned more elevated privileges to other accounts and removed MFA to obtain persistence and facilitate lateral movement.
Initially, the plan for the attackers was to attack MGM’s slot machines and milk the devices, but when that failed, the attackers planted ransomware and encrypted the company’s systems. After the attack was initiated, many MGM-owned hotels were brought to a standstill as the attack affected corporate email, restaurant reservation and hotel booking systems, and digital room keys.
Several weeks later, MGM provided an update on the attack’s impact and advised the attackers could access personal information, including names, contact information, gender, DOB, and even social security numbers from “some customers” before March 2019.
Surprisingly, MGM chose not to pay the ransom demanded by the attackers as it did not guarantee a return of their systems and data, and the company estimated the attack cost roughly $110 million. It was later known that days before MGM’s attack, casino operator Caesars was also hit with the same attack but ended up paying out a $15 million payout to the same group responsible.
Reach out to ProCircular to learn about how we can help your organization strengthen its security posture and avoid similar future attacks.

https://www.cnn.com/2023/09/14/business/caesars-mgm-casino-cyberattack/index.html
Talk with ProCircular about incident response, tabletop exercises, security assessment, and practical ways to reduce risk.